The Role of Information Security Policy

1182 Words5 Pages
The Role of Information Security Policy Karen A. Smith CMGT400 FEBRUARY 13, 2013 Reuben Wanjala The Role of Information Security Policy The increased use of electronic data indicates a growing need for privacy and protection of vital databases. Businesses rely on the Internet and web services for information and communication therefore there is need for an effective information security policy. Confidentiality, integrity, and availability are three important principles of information systems security. An effective information security policy helps to mitigate liability, reduce costs, manage regulations, assure proper audit, and control procedures for securing critical infrastructure and data. Policies and standards are integral to maintaining information systems security. Polices define the law and standards describes how to implement the policies. The policy should include the mission and objectives of the business as well as ensure the goals are met safely and securely. An effective information security policy defines the objectives of the business and outlines the strategy to achieve its goal. These policies and standards should inform employees, senior management to entry level, their required responsibilities for protecting the information system of the organization. Failure to implement an effective system may lead to financial loss, release of confidential data, and reputation. Businesses are required to comply with regulatory requirements and fiduciary responsibilities. It is the business’ responsibility to ensure the safety of its information security policy. As stated by the Rutgers Office of Information Technology, “The protection and management of non-public personal information (NPPI) must comply with a variety of state

More about The Role of Information Security Policy

Open Document