One area we’ve examined is the status of security policies within organization (Figure 15). We’ve
been interested in whether organizations have formal policies to describe what should be happening (and not happening) in terms of security. Curiously, the number of respondents saying their
organizations had a formal security policy in place dropped to 60.4 percent from last year’s 68.8.
The difference was made up in “no policy” and in “other,” which makes it possible that there is perhaps some slight shift in the makeup of the respondent pool. It may also be that the bar for what
counts as “formal” may have shifted slightly upward. What is meant by “other” is something that
may be worth examining in subsequent editions of the survey. In any case, the primary takeaway
is that the vast majority of organizations have something in the way of a security policy in place.