天极Yesky
  • 笔记本电脑
    笔记本
  • 台式电脑
    台式机
  • 手机
    手机
  • 电脑硬件DIY
    DIY硬件
  • CPU
    主板
    音箱
  • 硬盘
    显卡
    键鼠
  • 内存光驱
    显示器
    机箱电源

  • 数码相机DC
    数码相机
  • MP3播放器
    MP3/MP4
  • 数码摄像机DV
    摄像机
  • 电脑外设
    外设
  • 网络
    网络
  • 服务器
    服务器
  • 数字家庭
    数字家庭
  • 群乐
    群乐
  • 产品报价 行情 经销商 渠道 评测 | 软件 设计 网页 开发 安全 论坛 E时代 游戏 图片 壁纸 下载 网摘 博客 索尼专区 Vista 科技奥运
    天极网
    Issues to cover in a security policy
    作者: James Michael Stewart
    出处:
    责任编辑:
    [ 2004-06-17 18:25 ]


     

    Issues to cover in a security policy
    James Michael Stewart

    The security policy of an organization drives the entire structure of physical, administrative and technical security deployed. Without a thorough security policy defining what should be done, the results of the haphazard deployment of security controls will be woefully insufficient.

    There are at least ten areas of concern that an organization's security policy should address. I've borrowed these ten areas from the CISSP Common Body of Knowledge (CBK). The CISSP or Certified Information Systems Security Professional is a security certification offered by (ISC)2 (www.isc2.org). Even if you don't want to pursue the certification, I highly recommend reviewing the CBK assembled for this exam.

    The ten areas are:

    1. Access Control Systems & Methodology
    2. Applications & Systems Development
    3. Business Continuity Planning
    4. Cryptography
    5. Law, Investigation & Ethics
    6. Operations Security
    7. Physical Security
    8. Security Architecture & Models
    9. Security Management Practices
    10. Telecommunications, Network & Internet Security

    Your security policy should address each of these areas specifically and distinctly. Otherwise, your policy is incomplete and the resultant security scheme deployed by your organization probably has significant gaps that can be exploited.

    About the author
    James Michael Stewart is a researcher and writer for Lanwrights, Inc.

    笔名:
    请您注意:

     遵守国家有关法律、法规,尊重网上道德,承担一切因您的行为而直接或间接引起的法律责任。

     天极网拥有管理笔名和留言的一切权利。
    相关内容