logo

5 tips for writing a cybersecurity policy that doesn’t suck

ID: 21929aa7-8b5e-5d7c-b416-8d3c9fd41e4c

STIX ID: report--21929aa7-8b5e-5d7c-b416-8d3c9fd41e4c

Feed Name: Expel Blog

Date Published: 2019-09-17

Date Updated: 2026-04-27

Author: John Lawrence

...
...

## Executive Summary This blog-style guidance explains how to create practical, applicable, and concise enterprise cybersecurity policies, defines related terms (policy, procedure, audit, assessment), and offers pro tips—align with business goals, make policies realistic and always applicable, write in plain English, and keep documents short—plus recommendations for review steps and external resources (NATO CCDCOE, NCCoE, NIST CSF).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.