16.06.2009
-- Step by step instructions for untrained staff to perform routine security tasks in ways that ensure that the associated preventive, detective, and/or response mechanisms work as planned.
-- Advice on the easiest way to comply with security policy, usually written for non-technical users who have multiple options for secure information-handling processes.
What an Information Security Policy Includes
This leaves the question: what is the minimum information required to be included in an Information Security Policy It must be at least enough to communicate management aims and direction with respect to security. It should include:
1. Scope -- should address all information, systems, facilities, programs, data, networks and all users of technology in the organization, without exception