Information security policy - the basics
Anyone wanting the key elements of an information security policy need look no further than the Information Commissioner’s website for a neat Guidance Note on the Security of Personal Information. The measures outlined apply equally to other business sensitive information as well as to personal information and it is only an outline so that it can be filled out with your own policies and procedures.
Even if you don’t want a full-on security policy, it is useful to check through the lists to make sure you have covered the basics.
You can find it here: http://www.ico.gov.uk/upload/documents/library/data_protection/practical_application/security%20v%201.0_plain_english_website_version1.pdf
Mandy Webster
14 January 2008