Securing your data and network, inside and outside the perimeter
Topic: User Policies
A best practice is to make sure employees understand what they can and can't do
Blog: Some Simple Ways to Be More Security Conscious
Article: The Four Myths of Cyber Security
News: Social Networks Cost UK Firms Billions in 'Wasted' Time
Related Topics
Business Culture, E-mail and Web Policies
Lowering Your IT Costs with Oracle Database 11g Release 2This white paper identifies the key capabilities a database management solution needs to successfully deliver more information with higher quality of service, make more efficient use of IT budgets, and reduce the risk of change in data centers.
Software Forum: Information On Demand Virtual ExperienceThis interactive virtual forum presents leading IT experts providing the insights you need to turn your information into a strategic driver for innovation, business optimization and competitive differentiation.

Data management tips and techniques that insure ease of access, comprehensive security and absolute privacy for your invaluable company information.

Indispensable technologies and best practices to maintain your organization's most valuable asset.

Comprehensive power protection solutions.

Virtualization solutions, management tips and industry insights to promote and insure the lifespan of your business.
Disaster Recovery & Business Continuity Template PackPrepare your company for any type of disaster you can envision and those you cannot. Immediately download this comprehensive set of templates and tools for documenting your business contingency plans.
IT Security Manual TemplateImmediately download a customizable set of documents and templates that covers every aspect of IT Security. These templates are compliant with ISO27000, HIPPAA and Sarbanes oxley standards.
One thing I'm starting to recommend as best practice is that there be a specific sub-set of your security policies dedicated to minimizing the risk of data loss - a 'Data Security Policy' if you will. This includes things like guidance on not duplicating data when unnecessary, appropriate approval processes before sharing data, encryption policies and more. As most of the security concern an organization has is actually about protecting the data, calling it out specifically in your policy is a good approach.
Michael Argast, Security Analyst, Sophos