How can I develop a security policy for my organisation?
First, identify a group of personnel who should be involved in developing the security policy. Second, make all necessary plans for activities, resources required and schedules. Third, determine the core security requirements, and establish the organisation’s security policy accordingly. A draft security policy should then be reviewed and agreed by various stakeholders. The process of drafting might require several iterations before a security policy can be established. As technologies, business environments and security requirements change over time, the security policy should be reviewed periodically (e.g. once every two years) in order to keep abreast of changes.