Skip to main content

Security Policies in a Global Organization

In global organizations, some unique challenges can arise in creating and maintaining effective Information Security Policies, such as policy differences arising through merger or acquisition, varying risk tolerance levels among business units, legal and cultural differences. Some organizations may require region-specific policies that may be more restrictive than global policies, but cannot invalidate the global policies. This paper addresses the concept of creating a tiered structure Information Security Policy and a tiered approval structure, whereby some policies apply globally throughout the organization, and other policies apply to specific geographical, or regional entities.

501 (PDF, 1.84MB)

25 Feb 2002
ByGerald Long
Share
All papers are copyrighted

No re-posting of papers is permitted

Subscribe to GIAC’s Monthly Newsletter

Receive expert insights, priority access to certifications, essential updates on regulatory changes and industry developments.

Security Policies in a Global Organization