Generally Accepted System Security Principles

P-17 Policy Centered Security Principle

Copyright(c), 1995 - Management Analytics and Others - All Rights Reserved


Policies, standards, and procedures should be established to serve as a basis for management planning, control, and evaluation of information security activities.


Communicating senior management policy directives to all affected individuals defines the relationship between information security and other departments. The policy document conveys management's intent regarding information security concerns and describes the organizational structure and associated responsibilities of personnel who will be charged with implementing the policy.