官术网_书友最值得收藏!

Systems and services acquisitions policy

The purpose of the systems and services acquisition policy is to ensure that the information security program is properly inserted into the acquisitions life cycle of an organization, helping to ensure that secure and safe products are procured for the organization. Additionally, this policy ties-in the need for an effective SDLC approach, with information security being a key player.

What the system and services acquisitions policy should address:

  • Allocating sufficient resources to adequately protect organizational information systems
  • Employing system development life cycle processes that incorporate information security considerations
  • Employing software usage and installation restrictions
  • Ensuring that third-party providers employ adequate security measures to protect information, applications, and/or services outsourced from the organization
主站蜘蛛池模板: 霍城县| 元谋县| 漳平市| 涡阳县| 两当县| 沁源县| 黎城县| 新建县| 信宜市| 仙游县| 乌拉特后旗| 余姚市| 维西| 塔河县| 莱芜市| 陈巴尔虎旗| 肇源县| 泸西县| 奉贤区| 绥芬河市| 象山县| 鹤山市| 武功县| 邵武市| 蕲春县| 阳朔县| 许昌县| 宣恩县| 宁晋县| 阿勒泰市| 安庆市| 左云县| 平武县| 巴林左旗| 渝中区| 营山县| 无锡市| 岳池县| 太仆寺旗| 黄骅市| 嘉定区|