
So what is a security policy? To put it simply, it is actually a formal set of rules which individuals of an organization must comply as long as they have access to the organization's information assets and properties. For example, individuals must not use the organization's information assets in an unethical manner. The security policy also involves four major factors: secure,monitor,test and improve.