

Objective: To provide management direction and support for information security in accordance with business requirements and relevant laws and regulations.
Control
An information security policy document shall be approved by management, and published and communicated to all employees and relevant external parties.
Control
The information security policy shall be reviewed at planned intervals or if significant changes occur to ensure its continuing suitability, adequacy, and effectiveness.
© Copyright Castleforce 2007-2012. Web design by Theme Group