Security is a primary business objective and requires the attention of all management and staff. This book outlines security fundamentals and identifies the responsibilities that are essential to the control of risk when handling business and customer information. The Information Security Policy and supporting standards and procedures are based upon the industry standard ISO 27002:05 and provide the foundation on which an organization develops and maintains a consistent and secure environment for the operation of its business processes.
The purpose of this book is to help your organization define the baseline security controls and standards for the protection of distributed information system resources. Detailed operational and control procedures are covered within the book, but must be customized and maintained by each business unit as necessitated by the operating environment.