Corporate Security Policies by Infosec
12h 36mIntermediate2025-06-12
Authors

Infosec Institute
Course details
Policies, procedures and other governance documents are an essential part of managing an organization and employees, and especially for cybersecurity programs. In this course, the cybersecurity training experts at Infosec Institute explain the characteristics of good governance documents and how to review, update and implement them. Effective governance documents can help build efficiency, reduce error, improve security, and reduce legal liability risks.
Skills covered
IT Service ManagementGovernance, Risk, and ComplianceIncident ResponseDevOpsCybersecurityNetwork and System AdministrationOne-Off
Concepts
A Framework for Better Corporate Security Policy Foundations
- 01 - Introduction to corporate security policies
- 02 - What are security policies, and why do we need them
- 03 - Rules introduced - Let s talk about what they are in general
- 04 - Internal rules - Organization policies, procedures, and more
- 05 - Rethinking the rules pyramid as a platform
- 06 - Three platforms plus a fourth to build your policies
- 07 - Planning policies and internal rules conceptually
- 08 - Building internal rules conceptually
- 09 - Effective governance documents look like this
- 10 - The people who write, read, and approve security policies
- 11 - Policy knowledge and skills introduced
- 12 - Summary
1. Business Needs for Security Policies
- 13 - Introduction to business needs for policies
- 14 - The business mission is always first
- 15 - Knowing your organization's mission, business, and culture
- 16 - Ethics, business, security, and policies
- 17 - Good internal rules help the business achieve its mission
- 18 - Synchronizing business needs and priorities
- 19 - Summary
2. Incorporating Legal Requirements into Security Policies
- 20 - Introduction to external laws and rules
- 21 - Legal implications of policies and procedures
- 22 - Introduction to law and regulation
- 23 - Introducing laws as external rules to inform policies
- 24 - Cybersecurity laws and regulations, part 1
- 25 - Cybersecurity laws and regulations, part 2
- 26 - When and how to seek legal review
- 27 - Summary
3. External Guidance to Assist with Security Policies
- 28 - External guidance to assist with security policies overview
- 29 - Government regulatory guidance
- 30 - Finding good sample infosec policies from the internet
- 31 - Cybersecurity frameworks
- 32 - Books, articles, and other resources
- 33 - Tools to assist with creating and managing policies
- 34 - Summary
4. Planning the Security Document Project
- 35 - Introduction to planning the policy project
- 36 - Planning for when you don't have time to plan
- 37 - Planning, scoping, and selling (evangelizing) the project
- 38 - Where are we now, and where do we want to go
- 39 - Who should be on your team, and who else should be involved
- 40 - Summary
5. Managing and Executing the Security Document Project
- 41 - Overview of project management and execution
- 42 - Project management basics
- 43 - Overview of all steps and phases
- 44 - Review your project's scope and avoid scope creep
- 45 - Starting the project - Project kickoff
- 46 - Review relevant existing internal rules
- 47 - People skills for managing and communicating in your project
- 48 - Resolving differences of opinion
- 49 - Reading, writing, technical writing, and editing
- 50 - Tracking changes within documents and version control
- 51 - Security and technical decisions
- 52 - Gaining approval and finalizing the documents
- 53 - Publication, training, and implementing phases
- 54 - Summary
6. Using and Maintaining Your New Policies
- 55 - Post-project
- 56 - Document usage and the maintenance phase
- 57 - When to start a new document project
- 58 - Summary