Info Security - Questions that Should be Asked Frequently

When last was our information security policyillegal copy of our website?Who is responsible for the
reviewed?Do we have an information security officerenforcement of policies in our organization?Can we
in each department?Are people punished for breachingbeat our chest and say that our customers are not
our information security policy?Do we have a chiefthe weakest link in the information security plan of our
information security officer?Does our website presentorganization e.g. can we confidently ask 10 customers
the list of our contractors and business suppliers?Canthe Url address of the company? Would they get it
our security guards identify information assets? E.g. Doright?Have we recently disengaged any of our staff
our security Guards know what a hard disk is or looksthat assisted to develop an in-house application?Have
like?Are our E-mails digitally signed?Can we verify thewe disabled all default passwords and usernames of
authenticity of the caller e.g. A caller to a bank, pleasevendor applications?Do we have an information
transfer from my account 200,000 to this accountclassification policy in place?Have we disabled
number ...... ?Do we have an information disclosureusernames and passwords of all disengaged staff or
policy in place.Is our secretary aware of thestudents that came for industrial training (it)?Do we
information she should not give out?Do we have animmediately install operating system patch
information disposal policy in place? i.e. what type ofupdates?Are we regularly aware of new released
information is thrown into the dustbin?Can ourpatches by software vendors?
customers differentiate between our website and an