Guest
Information security policies
I have a question regarding Acceptable Use Policy vs all of the smaller documents (DYOD, Teleworking, cryptographic controls, password policy).
Assign topic to the user
Expert
Rhand Leal
Aug 03, 2018
Do I understand correctly that for a smaller company (~30) it is sufficient to have one detailed document in form of the Acceptable Use Policy and then it is not necessary anymore to fill out all the smaller ones as mentioned above? Or do you need both? I feel like they are somewhat redundant.
Thank you very much. Looking forward to your answer to move on quickly.
Answer: You understanding is correct. If a single Use Acceptance Policy can fulfil your needs you do not need to develop other policies.
These article will provide you further explanation about policies development:
- 8 criteria to decide which ISO 27001 policies and procedures to write 8 criteria to decide which ISO 27001 policies and procedures to write https://advisera.com/27001academy/blog/2014/07/28/8-criteria-to-decide-which-iso-27001-policies-and-procedures-to-write/
- One Information Security Policy, or several policies? https://advisera.com/27001academy/blog/2013/06/18/one-information-security-policy-or-several-policies/
Comment as guest or Sign in
Aug 03, 2018
Aug 03, 2018
Aug 03, 2018