An organization’s information security policies should be developed primarily based on:
Information security policies should be based primarily on a risk management process so that controls, requirements, and priorities address the organization’s specific threats, vulnerabilities, impacts, and risk appetite.
Community Discussion