What Should You Write in Your Information Security Policy?

What Should You Write in Your Information Security Policy?

Writing an information security policy has to address the mushrooming size of the physical Internet, the ever-increasing volume of data being squeezed through it, and the wider range of information security risks that come with both. When you say “computer security”, what comes to mind most often are external threats: hackers, malware, viruses, botnets. But when you look at computer and IT trends, the technologies your own people use every day, mobile devices, cloud apps, social networking and generative AI assistants, pose at least as great a threat to the integrity of your company.

So what should you write in your information security policy? The ten steps below are the ones that pay back fastest, and most of them are inexpensive and easy to implement.

10 Best Ways to IT Security Policy

Your employees are at least as great a threat to your information security policy as are the people on the outside trying to break in. What can you do to secure your information, your network, and your computers from IT security threats? There are a number of steps you can take to boost business cyber-security and protect your business.

1. Manage Your Technology Life Cycle

Old computer technology is less secure than new technology. Newer hardware and operating systems ship with protections the old ones cannot be retrofitted with, so one of the best things you can do when you create an Information Security Policy is to keep the estate current.

In fact, you should develop a technology life cycle plan for all of your computer hardware and software assets. Consider replacing computers after four years, and budget roughly 25% each year for new technology to replace the old. Write the vendor support end date next to every asset in the inventory, because a device that stops receiving security updates becomes a liability on a known calendar date, not a surprise.

2. Establish a Password Security Policy

This one is really simple: make sure your computers, servers, wi-fi connections and cloud accounts all have password protection. Adding open devices and connections to your network is just inviting trouble, but there are a few ways your business can improve cybersecurity beyond simply closing them.

Close those connections now, using unique credentials for each user. Favour long passphrases over short complex strings, screen new passwords against known breached-password lists, and give staff a password manager so unique credentials are realistic rather than aspirational. NIST Special Publication 800-63B advises that verifiers should not require memorized secrets to be changed arbitrarily, for example on a fixed monthly or quarterly schedule, and should instead force a change when there is evidence of compromise. You can read the requirement in the NIST digital identity guidelines. Your IT Security Policies should say exactly that, then add the controls that actually stop account takeover: multi-factor authentication on email, remote access and administrative accounts, lockout of an account after “n” failed login attempts, and immediate disablement of past employee accounts.

3. Back Up Your Data Frequently

Everyone I talk to says they have a back-up plan and, of course, they perform backups, but are their servers backed up frequently enough? And what about individual PCs, do they have data or apps that aren’t on the servers? Are they backed up, ever? Should they be?

IT administrator checking an external backup drive at a server rack in a small business utility room

Are backups taken off-site? Have you tried to restore your backups onto a machine that is NOT the one they came from? Are you using cloud-based apps but wonder if your cloud-based data are backed up appropriately? Bizmanualz OnPolicy procedure management software eliminates the need for backups at the user level for your policy and procedure documents.

And have you tested your backup process lately? Trust me, when you’re trying to recover your system from an attack or a fatal system error is not when you want to find out your backup process doesn’t work. Ransomware makes this sharper, because current strains hunt for reachable backups and encrypt or delete them first. CISA advises organizations to maintain offline, encrypted backups of critical data and to regularly test the availability and integrity of those backups in a disaster recovery scenario, as set out in the CISA #StopRansomware Guide. Your IT Security Policies should specify regular backups, at least one copy kept offline or immutable, and a restore test on a named cadence with a named owner.

4. Use Malware and Virus Protection

It happens, people inadvertently download something they shouldn’t, because social engineering techniques are that effective. The next thing you know, that computer, even your whole network, is compromised. You should have a Computer Malware Procedure that says who isolates the machine, who investigates, and who decides it is safe to return to the network.

When you develop an information security policy, consider centralizing your anti-virus and anti-spyware management instead of having each user responsible for their own devices. Enable frequent scanning and frequent, automatic updates. To secure your information, monitor your subscriptions, because you can’t afford to let them lapse. Modern endpoint protection also watches behaviour rather than only file signatures, which is what catches the scripted and fileless attacks that never write a recognizable file to disk.

5. Secure Your Mobile Devices

Your company may be facing increasing liability exposure from employees housing data on laptops, phones and tablets. If your employees have access to sensitive information, you need to develop a Mobile Device Management Plan that addresses digital rights management, data loss prevention, data security, and the other IT policies and procedures templates that support it. Consider device security and data protection that includes disk encryption, screen lock enforcement, and the ability to wipe a device in case it is lost or misused.

And if you don’t want employees using their personal devices to handle company information, what’s your policy on that and how do you enforce it? The same question now applies to consumer cloud storage and to public AI assistants, so name the approved tools in the policy and say plainly what company data may never be pasted into an unapproved one.

6. Communicate Your Information Security Policies

Imagine you’ve created a new password policy, invested in anti-virus software, and developed a Mobile Device Management Plan but you haven’t told anyone. How useful will those measures be in helping secure your information?

Employees in a meeting room during a short security awareness training session at a whiteboard

You must communicate your IT security policies and train your employees how to implement computer security methods. You can’t just tell everyone in an email that “here’s our IT Security Policy” and leave it at that. You have to show everybody how important it is, how it’s done, and how it helps secure your information.

You have to ensure that all employees understand the password policy, how endpoint protection keeps your computer safe, what “acceptable use” is, and the importance of protecting their mobile devices. Track who has acknowledged the current version, because an untracked policy is indistinguishable from an unread one when a regulator or an insurer asks.

7. Restrict Access to Your Data

IT Security Policies found in Microsoft Windows, Linux, and other operating systems have their own kind of user access controls. Using them means you have to identify what each user login requires for data, network, or peripheral access, for example read only, read/write, or execute. If you allow too much freedom of access, you increase the risk of misuse, data loss and similar problems, but if you make restrictions too tight, you’ll get far too many user complaints. There’s a very fine line between too much and too little, that line often isn’t easy to find, and it moves around a lot.

Two habits keep the line in roughly the right place. Grant access by role rather than by person, so a job change updates permissions automatically, and review the access list on a schedule, paying particular attention to administrator rights and to shared cloud folders that quietly became company-wide.

8. Implement a Contingency Plan

A computer, IT, or data center disaster recovery plan is an important element of securing your computer data. There are more than hackers and trusting (or untrustworthy) employees, there are acts of nature that threaten your business’s continuity, too.

You never know when fire, flood, tornado, civil disruption, robbery, or other catastrophic events will occur, but if one of them does strike, how long will it take you to get your business back online? Without a disaster plan in place, it will take too long.

Your IT Security Policies should include hardware and software replacement, data recovery, and key configuration, restoration, or installation details. It should include appropriate software license numbers, insurance numbers, and key contractor or supplier numbers. It should cover testing, validation, and performance criteria. Write down the recovery time you are actually aiming for per system, and keep a printed copy of the plan and the contact list, because a plan that lives only on the encrypted file server is not available on the day you need it. Furthermore, you need to thoroughly test your recovery plan before you need it.

9. Block Would-Be Intruders from Your Network

First, you can’t do this perfectly, but you can at least make it more difficult by installing a business-class firewall and updating it regularly. Close all the firewall ports you’re not using. Retire legacy wireless encryption and run WPA3 where your access points and clients support it, falling back to WPA2 only where they do not, and keep a separate guest network off your business network entirely. Always make sure you’re up on the latest threat prevention methods.

IT Security Policies should be set to restrict access to DNS zone transfers, which attackers can use to read your DNS records and obtain your server details. Add an Intrusion Protection System (IPS) that monitors network and system events for malicious activity. Remote access deserves the same attention as the perimeter, so require multi-factor authentication on VPN and on any remote desktop service, and never expose remote desktop directly to the Internet.

10. Close Holes in Your IT Security Policy

As we often say in the quality field, “You don’t know what you don’t know.” This is true for IT security, as well. To find the holes in your computer security system, perform some type of regular IT security audit and network inspection. Check your firewall and server logs for signs of threat.

See that you’ve implemented measures to address the first nine points above. Secure your information technology by securing your computer networks. Enable automatic updates across operating systems, browsers, and the third-party applications that attackers actually target, and use a patch management or vulnerability scanning tool to prove the updates landed rather than assuming they did. Be sure your anti-virus and other malware prevention systems are being automatically and regularly updated.

I also recommend hiring an independent computer security expert to audit your information security system and conduct system tests, such as penetration testing and leak testing, from time to time. A short annual engagement usually finds the two or three things your own team has stopped seeing. If you want the written framework to hang all of this on, the IT Security Policies and Procedures Manual gives you the editable documents to start from.

Write Information Security Policies

If you take the time to implement these 10 tips for IT security policies, you’ll be doing a great deal to ensure the security of your IT data. No IT system is perfect, of course, but if you take these ten easy steps, you’ll minimize or eliminate the majority of security threats to your IT system.

What are you doing to ensure the security, integrity, and availability of your company’s data? Is there anything you’d add to (or remove from) this list? What’s your biggest concern, information security-wise?

Frequently Asked Questions

What should an information security policy actually contain?

At minimum: scope and who it applies to, acceptable use of company devices and accounts, password and multi-factor authentication rules, access control by role, mobile and remote working rules, backup and recovery requirements, patching and asset life cycle expectations, incident reporting steps, and the named owner who reviews the whole thing on a set schedule.

How often should employees be forced to change passwords?

Current federal guidance points away from calendar-driven resets. Require length, screen new passwords against known breached lists, turn on multi-factor authentication, and force a change when there is evidence that a credential has been compromised.

How often should we test our backups?

Test a real restore at least quarterly, and test it onto hardware that is not the original machine. Keep at least one copy offline or immutable so ransomware cannot reach it, and record who performed each restore test and how long it took.

Does a small business really need a written security policy?

Yes, and usually a short one. Cyber insurers, enterprise customers and auditors increasingly ask to see written controls, and a two-page policy that staff have read and acknowledged does more for you than a fifty-page document nobody opens.

Discover Dash

Best Manual Deals