Knowledgebase

Writing a Practical Security Policy Print

  • cybersecurity, cyber, security, password, billing, guide, howto, solution
  • 0

Rules people will follow.

WHAT TO COVER

Passwords and the second step Device requirements What may be installed How data is handled and shared Access on joining and leaving Verification for payments and access changes Who to tell when something goes wrong

KEEP IT SHORT

One or two pages. Longer is not read.

WHAT MAKES A POLICY WORK

Being achievable Being supported by the tools people need Being followed by you

THE TOOLS POINT

Requiring unique passwords without providing a password manager produces non-compliance, not security.

WHAT TO AVOID

Rules nobody can follow Controls that make work impossible Anything you bypass yourself

THAT LAST ONE

Staff follow behaviour, not documents.

WHAT TO INCLUDE EXPLICITLY

That reporting a mistake is welcomed and never punished.

WHAT TO REVIEW

Annually, and when systems change.

WHAT TO CHECK

Whether it is actually followed.

Ask the people expected to follow it.


Was this answer helpful?
Back

Are you happy with your experience? Leave us a review on Trustpilot.


Trustpilot