Where are your policies, and are they being used?
One of your first tasks in building out an information security program is to review the company’s information security policies. You need to ask the following questions:
- Where are the security policies?
- Are the policies being followed?
- When were they last updated and reviewed?
- Is there a documented sign-off for employees?
Your security policies set a baseline of security, including actions that the entire company must follow. They show due diligence and provide consistency across your organization. Policies are meant to be high-level so that they can be applied across departments and the entire organization. It’s imperative the organization is aware of the policies and that they are followed. There needs to be an annual review of the key security policies that all employees sign off on after reviewing the policies. Alternatively, an “employee handbook” summarizing the policy can...