- CISSP in 21 Days(Second Edition)
- M. L. Srinivasan
- 241字
- 2021-07-14 11:04:27
Security policies, standards, procedures, and guidelines
Policies, standards, procedures, and guidelines form a quartet of organizational mechanisms in protecting information:
- Security policies are high-level statements that provide management intent and direction for information security. They describe the what of the description.
- Security standards provide prescriptive statements, control objectives, and controls for enforcing security policies. In a way, they provide the how of the description. They can be internally developed by the organization and/or published by standard bodies, such as National Institute of Standards and Technology (NIST), International Organization for Standardization (ISO), or country-specific standard bodies.
- Security procedures are step-by-step instructions to implement the policies and standards.
- Security guidelines provide the best practice methods to support security controls selection and implementation. They can be used in whole or part while implementing security standards.
For example, NIST Special Publication 800-14, Generally Accepted Principles and Practices for Securing Information Technology Systems provides procedures and guidelines for System security life cycle.
International Organization for Standardization (ISO) along with International Electro-Technical Commission (IEC) has published code of practice guidelines and a standard for Information Security Management System (ISMS). They are as follows:
- ISO/IEC 27002: Code of practice for information security. This standard provides a list of best practices an organization could adopt for security management.
- ISO/IEC 27001: This standard specifies the management framework required for Information Security and is a certifiable standard. Organizations can seek certification against this standard for their Information Security Management System (ISMS).
推薦閱讀
- 架構不再難(全5冊)
- 無代碼編程:用云表搭建企業數字化管理平臺
- Java Web基礎與實例教程
- Learning AndEngine
- Mastering AndEngine Game Development
- JavaScript入門經典
- 51單片機C語言開發教程
- Natural Language Processing with Java and LingPipe Cookbook
- Mastering Apache Storm
- Visual Basic語言程序設計上機指導與練習(第3版)
- Java EE 7 Development with WildFly
- C#網絡編程高級篇之網頁游戲輔助程序設計
- Building Scalable Apps with Redis and Node.js
- Visual C++ 開發從入門到精通
- AngularJS Web Application Development Cookbook