Chapter 4 - Policy Flashcards
Policy
- should never conflict with law
- must be able to stand up in court if challenged
- must be properly supported and administered
..
Bulls Eye model
Policies
Networks
Systems
Applications
Policies
Standards
Guidelines
Procedures
Policies : Sanctioned by management, defines what you can do and not do
Standards: Detailed minimum specification
Guidelines: Recommendation for compliance
Procedures: Step by step instructions for compliance
Example
Policies :
Standards:
Guidelines:
Procedures:
Policies : Use strong policy, frequently changed
Standards:must be at least 8 characters, with ag least…
Guidelines: We recommend you don’t use family or pet names
Procedures: in order to change your password, first click on the Windows Start button, then …
practices: according to X, most organisations requires employees to change passwords semi annually
Enterprise infosec policy (EISP), based on and supports organisation’s mission and vision.
Issues specific Infosec policy (ISSP), provides guidance to all members of the organisation regarding the use of IT
System specific infosec policy (SysPs), guides the management and technical specifications of particular technologies and systems.
Guidelines for development and implementation:
- Develop using industry accepted practices, and formally approved by management
- Distributed to all employees
- Read by all employees
- Understood by all employees
- Formally agreed by act of affirmation
- Uniformly applied and enforced
Three general causes lead to unethical and illegal behaviour: ignorance, accident, and intent.
Deterrence can be created when three conditions are present:
- fear of penalty
- probability of being caught
- probability of the penalty being applied