Enterprise Information Security Policy
Enterprise Information Security Policy
Enterprise Information Security Policy
The EISP must directly support the organization’s vision and mission statements. It must
also be defensible if legal challenges arise. It is an executive-level document, drafted by the
chief information security officer (CISO) in consultation with the chief information officer
(CIO) and other executives. Usually 2–10 pages long, it shapes the security philosophy in
the IT environment. The EISP does not typically require frequent or routine modification
unless the strategic direction of the organization changes.
EISP Elements
Although the specifics of EISPs vary from organization to organization, EISP documents
should include the following elements: