Home >> Solutions >> Information Security Policies
Information Security Policies

Global Security Network develops Information Security Policies that meet the overall business objectives of customer organizations, are adapted to their specific needs and form the basis of a comprehensive information security culture in the organization.

Why do we need Information Security Policies?

Information Security Policies are the cornerstone of information security effectiveness! Without Information Security Policies, organizations have little or no foundation upon which to built appropriate controls to protect its information.

In the absence of Information Security Policies, information security is likely to be inconsistent. Therefore security holes will be left unplugged and ready to be exploited by internal and external threats, which make it necessary to have well developed security policies.

Information Security Policies Development

GSN develops Information Security Policies that lay a solid foundation for the development and implementation of adequate information security practices in the organization.
The policies are based on the extensive experience and expertise of our ISO 27001 certified security specialists and are in accordance with the principles of ISO 27002 / ISO 17799 (Code of Practice for Information Security) which are a part of the ISO 27001 international standard for information security.

Scope of the Policies

Information Security Policies developed by GSN cover the following domains, each domain addressing multiple areas of information security:

  • High level Information Security Policy
  • Information Security Organization
  • Information Classification
  • Human Resources Issues related to Security
  • Physical and Environmental Security
  • Communications and Operations Security
  • Controlling Access to Systems and Information
  • Security Issues related to software acquisition, development and maintenance
  • Information Security Incident Management
  • Business Continuity Management
  • Compliance with legal/regulatory requirements