An information security policy must be:
An information security policy is effective only when it is distributed and communicated, enforceable, maintained through regular updates, and written in language its intended audience can understand.
Community Discussion