|
Newsletter
|
Main Page
Why Security Policy? Information is not only data stored using computer media or paper documents. It also includes phone communications, and employee expertise. Information flow within a business is a foundation of its competitive edge and financial liquidity. Maintaining the competitive edge is also increasingly often related to implementing information services, which act as a way to improve information flow. However, it is important that these services be implemented in such a fashion, that the intended profits do not become losses. That is why information security policy is of such importance. However, this is no easy task. Information security policy must be implemented in such a fashion, that it enables business continuity, minimizes risk, and maximizes business efficiency. However, the more complex IT systems and networks become (i.e. the more connections between public and private networks), the more difficult they are to control. Improper development of information resources leads in consequence to data scattering and decrease in security.
In
order to protect their business assets, businesses develop information
security policies as sets of regulations and procedures, which are
intended to help maintain information confidentiality, integrity and
availability. This manner is clearly appropriate. However, it becomes
much worse, as it is brought to life.
In order to develop an effective information security policy, it is not enough to follow the national standards, which only outline a schema of such a policy. Therefore, it is not enough to:
Such an important document should never be treated as a project, which upon being developed may simply be put away on a shelf. It should also never be developed by a single person, but a team supported by independent consultants, who are able to view the structure of an organization in a comprehensive and independent manner. Developing and implementing the information security policy should be an activity that is carefully planned and analyzed in detail, and it should involve all employees, suppliers, customers and stakeholders.
As
already mentioned, the information security policy is not just a single
project. It involves a number of continuous activities, which should be
audited in a regular fashion, verifying the development direction of
the implemented policy. Meeting your needs in this area, the ISecMan Organization invites you to participate in a set of trainings. Our trainings help you gain practical expertise in managing information security (developing and implementing information security policies, contingency plans and emergency procedures). They are designed mainly for upper management, personal data managers and IT staff who design and manage systems storing and processing protected information. All this, so you may gain comprehensive knowledge, which is required to effectively plan and implement business policies related to information security. |



