From the course: CompTIA Security+ (SY0-701) Cert Prep

Unlock the full course today

Join today to access over 24,000 courses taught by industry experts.

Security policies

Security policies

- [Instructor] Policies form the foundation of any information security program, and having strong information security policies is a critical component of your efforts to protect information. Information security policies and procedures play several important roles in an organization. No matter what specific issue a policy or procedure covers, it should meet several key criteria. It should provide the foundational authority for data security efforts, adding legitimacy to your work and providing a hammer if it's needed to ensure compliance. They also offer clear expectations to everyone involved in information security by explaining what data must be protected and the controls that should be used to protect that data. They provide guidance on the appropriate paths to follow when requesting access to data for business purposes, and they offer an exception process for formally requesting policy exceptions when it's necessary to meet business requirements. Let's take a look at a few of…

Contents