Risk Areas
10.3 Absence or existence of a weak IT security policy in an organisation may
exclude the following basic principles of information security:
• Responsibility and accountability must be explicit
• Awareness of risks and security initiatives must be disseminated
• Security must be addressed taking into consideration both technological and
non technological issues
• Security must be coordinated and integrated
• Security must be reassessed periodically
• Ethics must be promoted by respecting the rights and interests of others
• Security must be cost effective
• Security procedures must provide for monitoring and timely response
Audit Procedure
10.4 There should be specific statements in an IT security policy indicating
minimum standards and compliance requirements for specific areas like (a) assets
classification, (b) data security, (c) personal security, (d) physical, logical and
environmental security, (e) communications security, (f) legal, regulatory and
contractual requirements, (g) business continuity planning, (h) security awareness and
training, (i) security breach detection and reporting requirements, (j) violation
enforcement provisions, etc.