The Role of Information Security Policy

1118 Words5 Pages
The Role of Information Security Policy CMGT/400 September 12, 2014 The Role of Information Security Policy Absolute protection of computer systems and networks is not possible. Hardware and software alone can’t solve the problems of information security. We know that information technology systems are built by and around humans. This human element is information technology’s most significant challenge. We can design and plan our information system for many different threats and attack scenarios but it is nearly impossible to know all the different ways people can deliberately or accidentally cause harm. Despite all these threats from people themselves, people are also the best tool to defend against threats caused by other people. Organizations have high level board statements called policies and they are about rules and guidelines to follow to achieve certain goals. It is an attempt by an organization to control the behavior of their employees. There are many different sets of standards and policies in any given organization. We are going to talk about information security policies and standards. Standards are mandatory elements regarding the implementation of a policy. They are accepted specifications that provide specific details on how a policy is to be enforced. In regards to information security, there are many common sets of policies in place. These policies include acceptable use policies, due care, separation of duties, password management, change management, classification of information. Other important policy-related issues include privacy, service level agreements, human resources policies, codes of ethics, and policies governing incident response (Conklin, White, & Williams, 2012). Earlier, we talked about how human factor is the most critical aspect in information security. Criminals are always searching for newer and clever ways

More about The Role of Information Security Policy

Open Document