Home > Intel Communities > Open Port IT Community > IT@Intel > Blog > 2009 > January > 23
Currently Being Moderated
0

Don't assume people will read the security policy!

 

Just because the policy is posted, does not mean everyone will read it.

 

Listen to the Audiocast:Information Security policy must be marketed to employees

 

Policy, like any other communication, must be marketed.  It is the role of the security professional to show the end-users the value and how it helps them.   Make it personal.

 

References: SANS.org blog: How to Suck at Information Security



Add a comment Leave a comment on this blog post.

There are no comments on this post