Preface This document is intended to address the importance of having a written and enforceable Information Technology (IT) security policy, and to provide an overview of the necessary components of an effective policy. The reader will gain an understanding of the basic processes, methodologies, and procedures needed to initiate the development of an organization-wide IT Security Policy. A security policy is a document that defines the security requirements for an organization. It identifies assets that need protection and the extent to which security solutions should go to protect them. Some organizations create a security policy as a single document and other organizations create multiple security policies with each one focused on a separate area (Stewart, Chapple, & Gibson, 2004). When developing an IT Security Policy you should keep in mind the “defense in-depth” model. In other words, you should not be relying on one principal means of protection (or layer); instead, you should develop your security program so that it provides multiple layers of defense. This will ensure maximum protection of your data and resources and will minimize the potential for compromise. Please keep in mind that we can only protect ourselves from known and existing exploits. We are all possible targets of zero day exploits! However, an effective IT security program will be enabling you to detect anomalies in network traffic and take the necessary steps toward mitigation. (Albright, 2002) Lebanese National Security Policy Guidelines v1.7 Page 5|

Select target paragraph3