Skip to main content

๐Ÿ’ผ 12.1 A comprehensive information security policy that governs and provides direction for protection of the entity's information assets is known and current.

Descriptionโ€‹

Empty...

Similarโ€‹

  • Internal
    • ID: dec-b-a2068b77

Sub Sectionsโ€‹

SectionSub SectionsInternal RulesPoliciesFlags
๐Ÿ’ผ 12.1.1 An overall information security policy is established, published, maintained, and disseminated to all relevant personnel, as well as to relevant vendors and business partners.
๐Ÿ’ผ 12.1.2 The information security policy is reviewed at least once every 12 months, and updated as needed to reflect changes to business objectives or risks to the environment.
๐Ÿ’ผ 12.1.3 The security policy clearly defines information security roles and responsibilities for all personnel, and all personnel are aware of and acknowledge their information security responsibilities.
๐Ÿ’ผ 12.1.4 Responsibility for information security is formally assigned to a Chief Information Security Officer or other information security knowledgeable member of executive management.