Sample Security Plan Index
As mentioned at the beginning of this chapter, security policies differ greatly in how complex and specific they are. Some policies may be as simple as an electronic memorandum designating a particular employee as the point of contact to create accounts for anyone needing access to a database or system. For most companies, however, a more formal document may be in order. Here is a sample generic index of topics you might include in a security plan:
|
Topics |
|---|
|
Corporate Philosophy on Security |
|
Configuration of the Operating Systems by Divisions |
|
Configuration of the Databases for each System by Division |
|
Configuration of Applications by Database and System for Each Division |
|
Configuration of Single Sign-on Utility |
|
Composition of Certificates of Authority |
|
USERID Guidelines for a Database Account |
|
USERID Guidelines for an Operating System Account |
|
Password Guidelines for a Database Account |
|
Password Guidelines for an Operating System Account |
|
Operating System Access Types |
|
Database Access Types |
|
Authorization for Establishment of User Accounts |
|
Establishing a USERID for a Database |
|
Establishing a USERID for an Operating System |
|
User Administration—Accounts Creation |
|
User Administration—Appropriate Roles by Application |
|
User Administration—Appropriate Views by Application |
|
User Administration—Administrator Privileges |
|
User Administration—for Applications |
|
Establishing Access to an Application |
|
Revoking Access to an Application |
|
Revoking Access to an Application ... |
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access