-
Book Overview & Buying
-
Table Of Contents
Executive's Cybersecurity Program Handbook
By :
In this chapter, we discussed what governance is and how to enforce it through policy. Auditors will, without a doubt, look for your PSPs to understand the technologies in place, how they are configured, and your stance on an implemented control. This means that if you have a standard for antivirus software and it states how often it should be updated, the auditor will look to verify that it is configured that way.
This also helps to train your IT staff on the proper use of technology. AUPs are written for employees so they know what is and is not acceptable use of company-owned equipment. If you have a written policy that states, “Cannot use company-owned equipment for personal use,” that tells the employee not to use their company cell phone to make personal calls. You may also have a policy that discourages employees from using offensive language or describing what is acceptable for social media. If you have a bring your own device (BYOD) policy, that should...