Writing Information Security Policies

Book description

Administrators, more technically savvy than their managers, have started to secure the networks in a way they see as appropriate. When management catches up to the notion that security is important, system administrators have already altered the goals and business practices. Although they may be grateful to these people for keeping the network secure, their efforts do not account for all assets and business requirements Finally, someone decides it is time to write a security policy. Management is told of the necessity of the policy document, and they support its development. A manager or administrator is assigned to the task and told to come up with something, and fast! Once security policies are written, they must be treated as living documents. As technology and business requirements change, the policy must be updated to reflect the new environment--at least one review per year. Additionally, policies must include provisions for security awareness and enforcement while not impeding corporate goals. This book serves as a guide to writing and maintaining these all-important security policies.

Table of contents

  1. Copyright
  2. About the Author
  3. About the Technical Reviewers
  4. Acknowledgments
  5. Tell Us What You Think
  6. Introduction
  7. Starting the Policy Process
    1. What Information Security Policies Are
      1. About Information Security Policies
      2. Why Policies Are Important
      3. When Policies Should Be Developed
      4. How Policies Should Be Developed
      5. Summary
    2. Determining Your Policy Needs
      1. Identify What Is to Be Protected
      2. Identify From Whom It Is Being Protected
      3. Data Security Considerations
      4. Backups, Archival Storage, and Disposal of Data
      5. Intellectual Property Rights and Policies
      6. Incident Response and Forensics
      7. Summary
    3. Information Security Responsibilities
      1. Management Responsibility
      2. Role of the Information Security Department
      3. Other Information Security Roles
      4. Understanding Security Management and Law Enforcement
      5. Information Security Awareness Training and Support
      6. Summary
  8. Writing the Security Policies
    1. Physical Security
      1. Computer Location and Facility Construction
      2. Facilities Access Controls
      3. Contingency Planning
      4. General Computer Systems Security
      5. Periodic System and Network Configuration Audits
      6. Staffing Considerations
      7. Summary
    2. Authentication and Network Security
      1. Network Addressing and Architecture
      2. Network Planning
      3. Network Access Control
      4. Login Security
      5. Passwords
      6. User Interface
      7. Access Controls
      8. Telecommuting and Remote Access
    3. Internet Security Policies
      1. Understanding the Door to the Internet
      2. Administrative Responsibilities
      3. User Responsibilities
      4. World Wide Web Policies
      5. Application Responsibilities
      6. VPNs, Extranets, Intranets, and Other Tunnels
      7. Modems and Other Backdoors
      8. Employing PKI and Other Controls
      9. Electronic Commerce
      10. Summary
    4. Email Security Policies
      1. Rules for Using Email
      2. Administration of Email
      3. Use of Email for Confidential Communication
      4. Summary
    5. Viruses, Worms, and Trojan Horses
      1. The Need for Protection
      2. Establishing the Type of Virus Protection
      3. Rules for Handling Third-Party Software
      4. User Involvement with Viruses
      5. Summary
    6. Encryption
      1. Legal Issues
      2. Managing Encryption
      3. Handling Encryption and Encrypted Data
      4. Key Generation Considerations
      5. Key Management
      6. Summary
    7. Software Development Policies
      1. Software Development Processes
      2. Testing and Documentation
      3. Revision Control and Configuration Management
      4. Third-Party Development
      5. Intellectual Property Issues
      6. Summary
  9. Maintaining the Policies
    1. Acceptable Use Policies
      1. Writing the AUP
      2. User Login Responsibilities
      3. Use of Systems and Network
      4. User Responsibilities
      5. Organization’s Responsibilities and Disclosures
      6. Common-Sense Guidelines About Speech
      7. Summary
    2. Compliance and Enforcement
      1. Testing and Effectiveness of the Policies
      2. Publishing and Notification Requirements of the Policies
      3. Monitoring, Controls, and Remedies
      4. Administrator’s Responsibility
      5. Logging Considerations
      6. Reporting of Security Problems
      7. Considerations When Computer Crimes Are Committed
      8. Summary
    3. The Policy Review Process
      1. Periodic Reviews of Policy Documents
      2. What the Policy Reviews Should Include
      3. The Review Committee
      4. Summary
  10. Appendixes
    1. Glossary
    2. Resources
      1. Incident Response Teams
      2. Other Incident Response Information
      3. Virus Protection
      4. Vendor-Specific Security Information
      5. Security Information Resources
      6. Security Publications
      7. Industry Consortia and Associations
      8. Hacker and “Underground” Organizations
      9. Health Insurance Portability and Accountability Act
      10. Survivability
      11. Cryptography Policies and Regulations
      12. Security Policy References
    3. Sample Policies
      1. Sample Acceptable Use Policy
      2. Sample Email Security Policy
      3. Sample Administrative Policies

Product information

  • Title: Writing Information Security Policies
  • Author(s): Scott Barman
  • Release date: November 2001
  • Publisher(s): Sams
  • ISBN: 157870264X