6.5. Writing Your Own Security Policy
To help you get a jumpstart on writing your security policies, we include two sample policies in the sidebars "A sample corporate antivirus policy" and "A sample mobile device usage policy," in this chapter. Feel free to use these policies, or policy templates that you find on the Web, and fill in the needs of your organization.
Your security guidelines specify how to
Put a policy into action.
Define who has responsibility for deployment of the technologies required to support the policy.
Decide what the systems or users do if there is a breach in the security policy.
Take recourse when policies have been violated.
Assign responsibility for correcting the issue.
Establish a timeline for an action such as "all viruses outbreaks will be investigated and a plan put in place within 24 hours of the first reported infection."
A sample corporate antivirus policyOverview: This policy describes the Company XYZ policy on antivirus applications. Included in this policy are guidelines specifying antivirus updates, scan intervals, and recommended antivirus applications. It also specifies e-mail antivirus policies — blocked attachments, network antivirus scanning, and anti-spam techniques. Purpose: This policy has been designed to protect Company XYZ from the ongoing threat of viruses, worms, and other forms of malware. Policy:
|
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access