Cybersecurity Glossary

Security Policy

The short written rules that say how your organisation handles technology and data.

What Security Policy means

A workable set of policies covers acceptable use, passwords and authentication, devices, data handling and incident reporting. For a small organisation these should be a few readable pages, not a binder. A policy nobody has read protects nobody.

Why Security Policy matters for small businesses and nonprofits

Clients, insurers and funders increasingly ask for these documents. More usefully, written rules are what let you act consistently when someone breaks them, and what stop every decision being reargued.

What to do about Security Policy

Three steps to deal with Security Policy

  • Write short policies in plain language and have everyone acknowledge them
  • Review annually and after any incident
  • Make sure each policy names the person responsible for it

Not sure where you stand on this?

We review your current setup against the basics, tell you plainly what is covered and what is not, and give you a ranked list with effort and cost. No jargon and no scare tactics.