In today's hi-tech world, conventional physical security methods are simply insufficient for the protection of an organisation's information assets. This is because of the ever-increasing dependency on the use of electronic data in everyday business process activities. Since it is an information security policy that forms the basis for a security program, the importance of developing an effective policy is quite significant. Another phenomenon that has brought about a need for proper Information security policies is the fact that Information Technology is constantly evolving. As a result, new and changing security threats have to be constantly counter-acted. The intended objective of this paper is to provide a concise and generic methodology for the development, implementation and maintenance of a strategic information security policy. It must be noted that this project deals solely with policy development and it is therefore not indented to replace official and/or commercia...