A number of people have asked me for suggestions of third party online references which provide guidance upon how to make better security policies. Clearly Risk and Security policy should be the foundation of all things security in each of our organisations and yet in many cases security policies fail horribly. Here are some of the reasons why policies often fail:
I found the following links from Steve Riley's security policy session @ IT Forum:
Information Security Policies Made Easy, 9/e by Charles Cresson Wood Information Security Policy World SANS Security Policy Project Site Security Handbook
Information Security Policies Made Easy, 9/e by Charles Cresson Wood
Information Security Policy World
SANS Security Policy Project
Site Security Handbook