Section 27.260 Policy and Handbooks Flashcards
Objective 5.6 Given a scenario, you must be able to implement security awareness practices
Policies and Handbooks
Policy
A system of principles and rules guiding decisions, ensuring compliance
with legal and ethical standards
Policies and Handbooks
Handbook
A comprehensive guide providing detailed information on procedures, guidelines, and best practices
Policies and Handbooks
■ Policies and handbooks are living guidelines that shape behavior and decision-making in organisations
■ These documents vary between organisations based on industry, needs, and use
cases
■ Importance of not just reading but understanding the policies and handbooks
Scope of Policies and Handbooks
■ Cover various aspects in an organisation, e.g data protection, remote work,
technology use, conflicts of interest
■ Different handbooks for different aspects, e.g., Employee Handbook, Training
Handbook, Compliance Handbook
Data Destruction Policy Example
■ Some policies may define rules for data disposal, e.g., shredding
■ Color-coded paper for document classification
■ Shredding of sensitive documents to prevent data breaches
Remote Work and Data Protection
■ Organisations may have strict guidelines regarding remote work
■ Policies cover physical files and digital files that leave the office
■ Restrictions on what can be taken home or worked on remotely
Policy Guidance for Daily Responsibilities
■ Provide guidance on handling various situations, e.g., data breaches, reporting
suspicious activity
■ Ensures employees know how to respond to specific scenarios
Policy and Handbook Updates
■ Policies and handbooks should be reviewed at least annually
■ Updates to reflect changing cybersecurity landscape
■ Employee awareness of policy updates and significant changes is crucial
Human Judgment and Culture of Security
■ Policies and handbooks may not cover every scenario
■ Employees should understand the “why” behind the policies to make judgment
calls
■ Creating a culture of security involves reporting gaps and fostering a secure
environment
Importance of Employee Involvement
■ Encourage employees to bring up concerns and questions
■ Open communication with management and leadership teams
■ Collective responsibility in promoting a secure organization culture