Protecting information assets starts with clear direction. An information security program sets out what must be protected, how much protection it needs and who is responsible. It also gives auditors something to test against: without an approved policy or standard, an auditor can only offer opinions, but with one, she can measure the organization against what it agreed to do. This topic is about the hierarchy of documents, the frameworks that shape them, and the roles that make them work.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.