Information Security 14- Policy Formation and Enforcement
Information Security 14- Policy Formation and Enforcement
ArfanShahzad.com
Course Outline
ArfanShahzad.com
Policy
ArfanShahzad.com
Policy cont…
• Like laws, policies define what is right, what is wrong, what the
penalties are for violating policy, and what the appeal process is.
ArfanShahzad.com
Policy cont…
Standards, Practices, Procedures and Guidelines
• Standards, on the other hand, are more detailed statements of what
must be done to comply with policy.
ArfanShahzad.com
Policy cont…
Standards, Practices, Procedures and Guidelines
• Finally, practices, procedures, and guidelines effectively explain how
to comply with policy.
ArfanShahzad.com
Policy cont…
Standards, Practices, Procedures and Guidelines
ArfanShahzad.com
Policy Formation
ArfanShahzad.com
Policy Formation cont…
ArfanShahzad.com
Policy Enforcement
• Policy enforcement is the process of ensuring that organizational policies,
rules, and regulations are adhered to by individuals, employees, and
stakeholders within an organization.
ArfanShahzad.com
Policy Enforcement cont…
ArfanShahzad.com