官术网_书友最值得收藏!

Information security policies

Information security policies establish the rules where organizations can direct funding, people, processes, and technology in a retable and secure manner. NIST SP 800-95, Guide to Secure Web Services, defines policy as:

"Statements, rules or assertions that specify the correct or expected behavior of an entity."

Information security policies are developed by examining compliance requirements, obligations under the law, and organization-wide policies and practices. These policies are responsible for establishing rules behind how an organization develops and operates systems utilizing their system's engineering life cycle (SELC) or system's development life cycle (SDLC).

主站蜘蛛池模板: 融水| 乡城县| 萝北县| 黄石市| 大竹县| 奉新县| 永丰县| 德化县| 墨脱县| 绍兴县| 邵东县| 鲁山县| 南昌县| 景德镇市| 道孚县| 大名县| 绥江县| 武汉市| 新津县| 黄浦区| 饶平县| 青龙| 新津县| 遵化市| 西吉县| 呼伦贝尔市| 长汀县| 南丹县| 咸阳市| 绥化市| 拉孜县| 微山县| 广宁县| 瑞丽市| 荔波县| 轮台县| 富锦市| 竹山县| 吉水县| 铁岭市| 巍山|