13.1 Policies Flashcards
Password policy should include:
Education for end users. Strong password requirements, such as the following:
Minimum password lengths
Restrictions on the use of proper names
Password expiration
No previously used passwords allowed
No words spelled out completely within the password
The use of characters from the following groups:
Uppercase letters
Lowercase letters
Numbers
Special characters
Data Loss Prevention DLP, target activities at 3 levels:
Client level (data in operation) Network level (data in transit) Storage level (data at rest)
Incident response plan may outline various phases including:
Prepare, identify, contain, eradicate, recover, review.
An AUP should be:
Clear
Concise
Detailed regarding acceptable and unacceptable use of the network
Congruent with the associated overall security policies of the organization
Concrete regarding consequences of AUP violations