A formal document that defines an organization's approach to information security, including acceptable use, access control, incident response, and data handling procedures. Security policies establish the security baseline for all employees.
Related Terms
ISO 27001
complianceAn international standard for information security management systems (ISMS). ISO 27001 provides a systematic approach t...
Risk Assessment
complianceThe systematic process of identifying, analyzing, and evaluating security risks to an organization's assets. Risk assess...
Security Awareness
generalThe knowledge and attitude employees possess regarding the protection of organizational assets from cyber threats. Secur...