We love to say that policy is the foundation of our information security programs, and go on and on about how important it is. But when it comes time to create policy, all the good intentions go out the window and the game of CYA and liability transfer starts up. The output from the policy creation process has less to do with improving security for the organization and more with politics. Risk acceptance has become something no one will admit too, yet we all do. We will break down what is wrong with current policies and how to correct it. If you are ready to stop playing the biscuit game of Infosec and want to make real improvements, this is the talk for you.
Link to this comment:
All Comments (0)