Why a written security procedure — 2017 regulations requirement
The 2017 Information Security Regulations are not a recommendation — they are binding secondary legislation. Article 4 explicitly requires a written, signed, and current information security procedure for every database, at every security level (basic, medium, high). The procedure is the single document the Israeli Privacy Authority asks for first in an audit. Without it, you have an automatic finding — regardless of what controls actually exist in practice. A good procedure is not a wall poster; it is the working document that translates law into day-to-day operations: who is allowed to do what, with which data, under what conditions, and what to do when something goes wrong.