Writer kỹ thuật (s) - Công ty của bạn hoặc bộ phận an ninh đã có thể có một nhà văn kỹ thuật về nhân viên có thể hỗ trợ bằng văn bản chính sách bảo mật. Ngay cả nếu họ không thể chịu trách nhiệm chính cho dự án chính sách bảo mật thông tin, một nhà văn-nhà kỹ thuật có thể là một nguồn tài nguyên có giá trị để giúp lập kế hoạch dự án chính sách của bạn, | 9. Policy Document Outline In addition to the policy statements that will form the main body of your policy documents see Appendices 1-2 for sample policy outlines each policy should include the following sections. Introduction This section should introduce the policy by name and locate it within the hierarchy of other existing information security and company policy documents. Purpose State the main goals of the policy this will explain the reason for the policy and will help readers understand how the policy should be used. Legal and compliance issues should also be mentioned in here. Include statements on any specific legislation the policy is designed to adhere to. Scope The scope is a statement of the infrastructure and information systems to which the policy applies and the people who are stakeholders in it. Stakeholders would typically include anyone who is a user of the information or systems covered by the policy. Roles and Responsibilities This is a statement of the structures through which the responsibilities for policy implementation breldelegated throughout the company. Jobrolesmay be specified in this section . Database Administrators DBAs Technical Custodians Field Office employees etc. Sanctions and Violations This section details to what extent breaking policy is considered a violation . it is HR-related and therefore related to an employee s contract or is it an information security department matter This section should also detail how violations should be reported who to and what actions should be taken in the event of a violation. It should also include information on what sanctions will be carried out resulting from a violation for example verbal or written warnings etc . Revisions and Updating Schedule This section defines who is responsible for making updates and revisions to the policy and how often these will take place. It may be useful to include a reference to the document as a living document which can be