General then...and I don't mean the following to be a criticism or whatever (I'll include the answers for my current employer as an example, sigh). <br>
<br>
I have to ask the 3 basic questions of security:<br>
<br>
1 - Do you have a Security Policy? (Yes, I believe we do.)<br>
<br>
2 - Have you ever read it? (Nope, don't even know where to find it.)<br>
<br>
3 - Do you understand it? (See last question...ack!)<br>
<br>
<br>
Definition:<br>
<br>
A Security Policy defines how an organization manages, protects, and distributes sensitive information and resources. Security experts agree that a good security policy is essential and that network security is not really possible without one.<br>
<br>
An effective security policy is known by everyone. It should be widely distributed and part of ongoing training. That said, I don't think that my current employer has an effective security policy. In fact, a majority of companies don't... which is why crackers and hackers are so effective at what they do.