10: 4 Security Policies Flashcards
Security Policy Framework (4)
Policies, Standards, Guidelines, Procedures
Security Policies
Provide foundation for a security program, carefully written, require compliance from all employees, are approved at the highest levels of the org
Security Standards
Provide specific details of security controls, derive authority from policies, require compliance from all employees
Security Guidelines
Provide security advice to the organization, follow best practices from industry, not mandatory
Security Procedures
Outline a step-by-step process for an activity, may require compliance
Data Security Policy Criteria
Foundational Authority for Data Security Efforts, Clear Expectations for data security responsibilities, guidance for requesting access to information, process for granting policy exceptions
Data Storage Policies
Appropriate locations, access control requirements, encryption requirements,
Data Transmission Policies
Protect data in motion, covering encryption requirements and acceptable transmission mechanisms
Data lifecycle policies
Describe end of life for data (data retention policies - how long data elements are kept, data disposal policies - how to destroy data that’s no longer needed)