A critical organization policy is the security(or information security[InfoSec]) policy. Management needs to establish fundamental security objectives tied to business objectives and identify assets that need protection from identified risks. A good policy is contingent on a proper and thorough risk assessment.