Microsoft Windows Vista Community Forums - Vistaheads
Driver Scanner 2009 - Free Scan Now



Welcome to the Microsoft Windows Vista Community Forums - Vistaheads, YOUR Largest Resource for Windows Vista related information.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so , join our community today!

If you have any problems with the registration process or your account login, please contact us.

Cyber Security Awareness Tip #6: Developing policies and Distribution, (Sat, Oct 6th)

Security News



Click On Your Flag for Translation
Simplified Chinese French Spanish Italian Portugeuse Japanese German Dutch
Reply
  #1 (permalink)  
Old 10-06-2007
Steve's Avatar
Steve Steve is offline
Moderator
 
Join Date: Sep 2006
Location: Emerald Isle
Posts: 46,133
Steve is a jewel in the roughSteve is a jewel in the roughSteve is a jewel in the rough
Thanks: 7
Thanked 24 Times in 11 Posts
Cyber Security Awareness Tip #6: Developing policies and Distribution, (Sat, Oct 6th)
One of the cornerstones of security is policy and as much as most of us dislike writing them, without them we are all pretty much floundering around. So todays tips relate to developing and distributing policies.

Well get the basics out of the way. Why do we need policies? Policies outline the dos and donts for the organisations. Staff and management both know where they stand in relation to important issues. Policies also help modify behaviour, people are surfing for porn, you put a policy in place to help modify that behaviour.

So what do we need? These are the few of the duh points, but important nonetheless:

Make sure you have senior management support.
Write SMART policies. Specific, Measurable, Achievable, Realistic, Time based policies
Keep the audience in mind when writing policies.
If it doesnt have the word MUST in it maybe move it to a guideline or standard. Or in other words keep policies as policies, guidelines as guidelines and procedures as procedures. Youll only confuse the message if you mix them.
Make sure you have a compliance statement, people need to know what happens if the policy is not followed.
Make sure it is available to everyone
Regularly review the policy
Get legal to check them out.
Collaborate with stakeholders in developing the policy.
Make sure you cover items of specific risk in the organisation
Make sure the policy is in line with the corporate objectives and overall security posture
Get people to sign that they have read and understood the polices.
Reinforce the message regularly


After writing the polices you will need to make sure it is disseminated. There have been plenty of examples over the years where people have been sacked and then re-instated because of weak or policies that werent enforced or enforced inconsistently. The traditional methods are publishing on the intranet, as part of the induction process, document management systems, etc. A good idea is to develop a quiz which must be taken by staff. That way the lessons are reinforced and you have a register of who has read and understood the policy.

So which polices do you need? It depends on the organisation and if you are working to standards like ISO/IEC 27001, or SOX, etc. The basic ones I think you should consider are:

Information security policy
Acceptable usage policy (make sure you cover internet and email usage)
Remote access
Access control policy
Information Classification Policy


Thats a quick start to the day, send in tips for disseminating policies, reinforcing the message, some good practices and the bad.

Cheers



Mark H - Shearwater



More...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Cyber Security Awareness tips #5 - Social Engineering and Dumpster Diving Awareness, (Fri, Oct 5th) Steve Security News 0 10-05-2007 05:57
Cyber Security Awareness Tip #4: Enabling the Road Warrior, (Thu, Oct 4th) Steve Security News 0 10-04-2007 02:30
Cyber Security Awareness Tip #3: Getting the Boss Involved, (Wed, Oct 3rd) Steve Security News 0 10-03-2007 15:40
Cyber Security Awareness Tip #2: Multimedia Tools, Online Training, and Useful Websites, (Tue, Oct 2nd) Steve Security News 0 10-02-2007 19:53
Cyber Security Awareness Tip #1: Penetrating the This Does Not Apply To Me Attitude, (Mon, Oct 1st) Steve Security News 0 10-01-2007 01:41


All times are GMT +1. The time now is 05:30.


Registry Mechanic - Free Scan Now
Driver Scanner 2009 - Free Scan Now




Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119