Describe the role of a policy framework


Discussion Post: Operating Security

An information technology (IT) security policy framework is the foundation of an organization's information security program. Organizations use these documents to build processes, determine acceptable technologies, and lay the foundation for enforcement. The security policy framework documents and their implementation express management's view of the importance of information security.

a) Describe the role of a policy framework in an information security program

b) Describe the different types of policies used to document a security program

c) What business factor(s) do YOU think should be considered when building an organizational IT security policy framework? Explain

d) What is the difference between risk tolerance vs risk appetite?

The response must include a reference list. Using one-inch margins, double-space, Times New Roman 12 pnt font and APA style of writing and citations.

Solution Preview :

Prepared by a verified Expert
Management Information Sys: Describe the role of a policy framework
Reference No:- TGS03094006

Now Priced at $15 (50% Discount)

Recommended (94%)

Rated (4.6/5)