Let's start with a brief description of a policy. A policy is a set of principles that are intended to guide actions of an organization. For example, a computer security policy for a bank could be written that sets restrictions on employee Internet access in an effort to reduce the likelihood of an outside cyber-attack.Policies are generally formulated either reactively or proactively. A reactively derived policy is created as a consequence of a failed or flawed process that caused or could have caused harm to the organization. Let's use a real-world scenario as an example of a reactive policy. For example, a small restaurant recently experienced a cyber-attack from a remote location by an individual using a mobile device. Upon learning of the details of the attack, the restaurant created a policy that restricts wireless access only to authorized individuals, in an attempt to limit access to the network. Rather than forecasting a cyber-attack and implementing a proactive policy, the restaurant waited until an actual attack occurred.