Writing Information Security Policies

Writing Information Security Policies
复制标题

编写信息安全政策

DOI:
--
复制
发表时间:
2001
期刊:
影响因子:
--
通讯作者:
S. Barman
S. Barman
中科院分区:
--
文献类型:
--
作者:
S. Barman

文献摘要

被引文献

相似文献

来自出版商: 管理员比他们的经理更精通技术,已经开始以他们认为合适的方式保护网络。当管理层意识到安全性很重要时,系统管理员已经改变了目标和业务实践。虽然他们可能会感谢这些人保持网络安全,但他们的努力并没有考虑到所有资产和业务需求。最后,有人决定是时候编写安全策略了。管理层被告知政策文件的必要性,他们支持其发展。一个经理或管理员被分配到任务,并告诉拿出一些东西,并迅速!一旦安全策略被写入,它们就必须被视为活文档。随着技术和业务需求的变化,必须更新策略以反映新的环境,至少每年进行一次审查。此外,政策必须包括安全意识和执行的规定,同时不妨碍公司目标。本书是编写和维护这些重要安全策略的指南。
From the Publisher: Administrators, more technically savvy than their managers, have started to secure the networks in a way they see as appropriate. When management catches up to the notion that security is important, system administrators have already altered the goals and business practices. Although they may be grateful to these people for keeping the network secure, their efforts do not account for all assets and business requirementsFinally, someone decides it is time to write a security policy. Management is told of the necessity of the policy document, and they support its development. A manager or administrator is assigned to the task and told to come up with something, and fast!Once security policies are written, they must be treated as living documents. As technology and business requirements change, the policy must be updated to reflect the new environmentat least one review per year. Additionally, policies must include provisions for security awareness and enforcement while not impeding corporate goals. This book serves as a guide to writing and maintaining these all-important security policies.