Find Resources & Connect with members on topics that interest you.

AI - Acquire and Implement

PO - Plan and Organize

DS - Deliver and Support

Please sign in to see your topics.

You must be logged in to join this group.

Information Security Policies/Procedures

Welcome to the Information Security Policies/Procedures topic!

Collaborate, contribute, consume and create knowledge around various information security policies and procedures including BYOD, password complexity, and other topics.

ISACA members can participate by clicking on the “Join this Community” button. You must be signed into the site. Set your alerts to be notified of new discussion activity within this community. Not an ISACA member? Join now!

This Topic Has:
1155 Members
2 Online
11390 Visits

Community Leader

Knowledge Center Manager

Knowledge Center Manager

Title: Become a Topic Leader!

Badge: Energizer


NEW! Activity Badges

Badges help others understand your level of community activity and your reputation as a contributor within the Knowledge Center. Learn More.

Discussions: 56 total

Must be a Topic member to contribute
View All »
It's a tricky one, and from my previous post in this community you may guess has been a fascination of mine for coming on 2 decades now.   Writing policies is fine, there are many resources to help - and once you have a good set of them most auditors wil...
Daniel477 | 2/22/2017 1:42:18 AM | COMMENTS(5)
I would like to know which argument we could give for NOT having formal policies in the context of small and medium entreprises. I would like to come with other arguments than the lack of resources, or skills, which are weak arguments, in my opinion. As a...
frelem | 2/3/2017 3:57:18 PM | COMMENTS(5)
Hi  Is there any organisation or resource (such as NIST, etc) which publishes best practice security policy documents which can be used as a starting point for companies looking to review their security policies?  Thanks in advance
Sharad407 | 2/2/2017 8:27:18 AM | COMMENTS(4)
Can anyone recommend industry recognized certifications for writing IT Security Policies? I'm looking for something that will improve my skillset while highlighting my existing skills and experience. Thanks! Adora
Adora370 | 12/20/2016 8:14:35 AM | COMMENTS(7)
Hi All, Recently I heard a real story from a friend who works in a bank. He is working in a department which handle highly confidential document. As an internal control, I understand his department head requires everyone must keep their mobile phone into ...
K.C. Lam, Dicky | 12/1/2016 7:54:23 AM | COMMENTS(1)
Hello everybody, I need to draft Acceptable Usage Policy for having employee use their personal mobile device for work. We are rolling out two-factor authentication, our preferred approach is employees use mobile device push notification or a soft token b...
Srinivas689 | 9/23/2016 8:45:40 AM | COMMENTS(0)

Documents & Publications: 38 total

Must be a Topic member to contribute
View All »
Posted by ISACA 638 days ago
Posted by ISACA 779 days ago
Posted by ISACA 942 days ago
Posted by ISACA 942 days ago
Posted by ISACA 942 days ago

Events & Online Learning: 8 total

16 Mar 2015
ISACA International Event
Orlando, FL, USA
15 Jun 2015
ISACA International Event
Ciudad de México, Mexico
21 Sep 2015
ISACA International Event
Miami, FL, USA
1 Aug 2016
ISACA International Event
Chicago, IL, USA
31 Jul 2017
ISACA International Event
Chicago, IL, USA

Journal Articles: 29 total

Volume 1, 2017
by David Eduardo Acosta R., CISA, CRISC, CISM, BS 25999 LA, CCNA Security, CEH, CHFI Trainer, CISSP Instructor, PCI QSA, OPST
Based on the information an organization manages, the security policy should set out the requirements and controls for the protection of the various assets according to their criticality
Volume 5, 2015
by Seymour Bosworth, Michel E. Kabay and Eric Whyne | Reviewed by Dino Ippoliti, CISA, CISM
Many students and young professionals want to know which topics they should master in the information security field.
Volume 4, 2015
by Laura Taylor | Reviewed by Ibe Etea, CISA, CRISC, CA, CFE, CIA, CRMA
FISMA Compliance Handbook is a valuable reference guide to compliance requirements in the US.
Volume 2, 2015
One of biggest budget busters for an information security program is technology solutions that are not a good match for the organization.
Volume 2, 2015
by Mauricio Rocha Lyra, Ph.D., COBIT Foundation, CTFL, ISO 20000, ITIL, MCSO, OCUP, PMP, RUP and Jose Carlos Ferrer Simoes
The transformations experienced by organizations due to technological advances has made information, arguably, an enterprise’s most valuable asset.
Volume 6, 2014
by Jeimy J. Cano M., Ph.D, CFE
International trends reflect a paradigmatic change in current business models caused by the markets’ asymmetry and dynamics where instability is the constant and change is the norm.

Wikis: 2 total

Blog Posts: 4 total

Must be a Topic member to view blog posts
Senior Manager           ultimate responsibility Information security Officer          functional responsibility Security Analyst           Strategic, develops policies and guidelines Owner         - Responsible for asset         - Determine level of clas...
Posted By : Muhammad554 | 0 comments
Infosec community celebrates new versions of ISO 27001:2013 and ISO 27002:2013. Worth to look at: and everyone should read the story of genesis of  ISO 270...
Posted By : Vilius | 1 comments
13 Nov 2014
Posted By : masarker | 4 comments
On March 1st,  I was invited to speak at the CampIT conference on Enterprise Risk/Security Management at Rosemont Convention Center. Before me there were two speakers. The first presenter spent an hour presenting the story from the trenches of technolog...
Posted By : appolloconsulting | 2 comments