Summary
In conclusion, having a solid set of security policies lays the groundwork for your security program. Your security policies should be reviewed annually and approved. A subset of your policies should be reviewed by all employees and signed off. This ensures that all employees are informed of what is expected of them and how the security practices of the company work.
In the next chapter, we will be covering security and risk management, which is the process of balancing cyber risks, the controls to thwart attacks, and a budget. As a CISO, it is a balancing act to decide on what to prioritize and what risks are acceptable.