官术网_书友最值得收藏!

Planning policy

A planning policy in this context has to do with developing the information security program. This policy sets the foundation for an organization's information security program and is one of the initial activities that should be undertaken when an organization is beginning to mature its information security capability. Additionally, this policy establishes rules around the development, documentation, periodic update, and implementation of security plans for organizational information systems.

A planning policy should address:

  • The establishment of organizational roles—CIO, CISO, system owner, data owner, data custodian, and so on
  • What should be included and what should the update frequency be for the information security program plan?
  • What artifacts should be developed to ensure repeatable processes around information security control selection, development, and implementation?
主站蜘蛛池模板: 金山区| 瓮安县| 买车| 巴马| 吉木乃县| 崇左市| 滦南县| 长宁县| 曲沃县| 永济市| 乐东| 乌什县| 札达县| 大渡口区| 平和县| 咸阳市| 东阳市| 江华| 体育| 临沂市| 高雄市| 公主岭市| 吉安市| 大宁县| 福州市| 蕉岭县| 藁城市| 临湘市| 耿马| 北票市| 蚌埠市| 晋城| 伊宁县| 班玛县| 铁岭市| 西峡县| 阿拉善左旗| 剑川县| 大庆市| 临夏县| 友谊县|