Security Policy: Difference between revisions
Jump to navigation
Jump to search
m →General |
m →Policy |
||
Line 52: | Line 52: | ||
:1. Is appropriate to the purpose of the organization; | :1. Is appropriate to the purpose of the organization; | ||
:2. Includes information security objectives (see [[Security_Policy#information_security_objectives_and_planning_to_achieve_them| | :2. Includes information security objectives (see [[Security_Policy#information_security_objectives_and_planning_to_achieve_them|3.2]]) or provides the framework for setting information security objectives; | ||
:3. Includes a commitment to satisfy applicable requirements related to information security; and | :3. Includes a commitment to satisfy applicable requirements related to information security; and | ||
:4. Includes a commitment to continual improvement of the information security management system. | :4. Includes a commitment to continual improvement of the information security management system. |