Information Security Policy

What is information security policy?Information securityof questions to which company's employees have to
policy is a set of suggestions (laws) which companyanswer and after that, special information security
has to write to make their information system safeawareness companies process these answers and
and immune against malicious attacks!Usally this kind ofwrite your own (company) information security policy.
policy is written to different level employees, but theAnother way to create this policy is to use a special
common element in all these policies is - target!software which automaticaly processes the answers,
Policy can include conjuct set of rules about all themesevaluate the risks and give out a policy. This way is
which related with information security and computereasier and thats also take less time.The policy has to
usage or seperated rules about various theme, forbe written in a form that is relevant, accessible and
example, e-mail, network or physical security.understandable to the intended readers!
Why a company needs information security policy?Company gets a policy. What next?!
Many information systems have not been designed toNow a company's manager has to nominate one
be secure, but without these systems bussines life isperson who will be responsible for policy writen rules
hard to imagine. Increasingly, companies and theirobservation. This person has to introduce all
information systems and networks are faced withemployees to these rules and also published and make
security threats from a wide range of source, includingthis policy available. Now this person needs to check
computer-assisted fraud, espionage, sabotage,and control how these rules are implemented in life.
vandalism, fire or flood. Sources of damage such asThis person has to be very close to manager and
computer viruses, computer hacking and denail ofregulary inform if there is some problems.
service attacks have become more common, moreProblems!
ambitious and increasingly sophisticated. And to doUsually problems start whith impementing policy's rules
company's information system safe is not enough onlyin life. People have to change their daily work
with modern technolgies and software, but alsoobservance and try to work notice these rules. It's
everyone in this company need to a part of securityalways hard, but there are many ways how to
system.stimulate or even press to do this. This process more
Security policy modelling process point to system'seasly makes special e-learning courses which provide
weakest area and give advices how to prevent them.information security awareness companies, for
How is a policy created?example, Infosecuritylab. And also managers can
There are different ways how to create a securitydevelop some kind of bonuss system to employies
policy, but the main idea is the same. There are a setwhich notice these rules or warnning these who ignore!