Showing posts with label policy enforcement. Show all posts
Showing posts with label policy enforcement. Show all posts
Thursday, October 1, 2015
One in Three Companies Lacks Policies for Information Security, Data Encryption, and Classification
If your company is one of those that lacks policies, don't despair. Check out the following books and articles to how-to develop polices and policy templates.
BOOKS
Information Security Policy Development for Compliance: ISO/IEC 27001, NIST SP 800-53, HIPAA Standard, PCI DSS V2.0, and AUP V5.0
Building an Effective Information Security Policy Architecture
Information Security Policies and Procedures: A Practitioner's Reference, Second Edition
Click here for other books on policies, procedures, and standards:
ARTICLES
The Security Policy Life Cycle: Functions and Responsibilities
6 Steps to Security Policy Excellence
Information Security Policies, Procedures, and Standards: Establishing an Essential Code of Conduct
Monday, June 2, 2014
CISOs Reveal Top Firms Failing on Security Awareness Training
Is this a failure of will, or of process, or of failing to enforcement policies and procedures? There's something to be said about a draconian approach to enforcement. Touchy-feely really doesn't work.
With resources like these books available, there's no reason for this failure.
Managing an Information Security and Privacy Awareness and Training Program, Second Edition
Asset Protection through Security Awareness
Here's a partial list of available articles:
Why Information Security Training and Awareness Are Important
The ABCs of a Persuasive Security Awareness Program
Implementing an Information Security Awareness Program
Subscribe to:
Posts (Atom)