From the course: CompTIA CySA+ (CS0-002) Cert Prep: 7 Compliance and Assessment

Unlock the full course today

Join today to access over 22,600 courses taught by industry experts or purchase this course individually.

Security policies

Security policies

From the course: CompTIA CySA+ (CS0-002) Cert Prep: 7 Compliance and Assessment

Start my 1-month free trial

Security policies

- [Instructor] Policies form the foundation of any cybersecurity program, and having strong data security policies is a critical component of your efforts to protect information. Data security policies and procedures plays several important roles in an organization. No matter what specific issue a policy or procedure covers, it should meet several key criteria. First, the policy should provide the foundational authority for data security efforts, adding legitimacy to your work and providing a hammer, if needed, to ensure compliance. Policy should also describe data ownership, making clear statements that any information generated by the organization, belongs to the organization by default. Policy should also offer clear expectations to everyone involved in data security by explaining what data must be protected, and the controls that should be used to protect that data. Policy should also provide guidance on the…

Contents