Which of the following is NOT a valid statement to include in an organisation's security policy?
An organization's security policy should be a reflection of its own security stance and principles, not tailored to third parties. While it may be informed by third-party requirements, the policy itself should not be amended to suit all third-party contractors. This is because the security policy is meant to establish a clear set of rules and expectations for the organization's members to maintain the confidentiality, integrity, and availability of its data. It should be defined, approved by management, and communicated to employees and relevant external parties. Amending the policy to suit all third-party contractors could lead to a dilution of the security standards and potentially compromise the organization's security posture.
Ona
3 days agoSheron
8 days agoJamal
13 days agoElke
19 days agoVanna
24 days agoEugene
29 days agoArlean
1 month agoTien
1 month agoNidia
1 month ago