One Article Review

Accueil - L'article:
Source SANS.webp SANS Institute
Identifiant 4605
Date de publication 2016-07-23 18:11:20 (vue: 2016-07-23 18:11:20)
Titre It Is Our Policy, (Sat, Jul 23rd)
Texte How many times have you heard someone say out loud our our security policy requires...?Many times we hear and are sometimes even threatened with the security policy. Security policy should set behavioral expectations and be the basis for every technical, administrative and physical control that is implemented. Unfortunately, solid security policies are often elusive for several key reasons.I regularly get the question, How many security policiesshould I have? My response is often found by raising my hands and wiggling my fingers in the air. There is nothing magic about the number of security policies, my observation is that many times there are more security policies than are actually needed.One of the most important aspects of a security policy, just like the jar ofmayonnaise in your refrigerator, is anExpiration Date. This non technical control can help facilitate regular updates to account for current issues being faced and capabilities that may not have existed when the security policy was originally created. Think of this as a built in process to ensure that it is regularly reviewed-considera recurring calendar reminder.Should your employees be expected to memorize all of your security policies and is that even realistic for them? I hope not for their sake. What if you redefine the win by each of your employees knowingwhere to find the policywhen faced with a decision?ACentral Locationfor security policies, versus being spread all over your companyis best and can serve as theset of guardrails to protect both the employee and the company. This will serve as a key resource for everyone to go to when regular faced with a decision of is this allowed or not in the security policy.Finally, as you start to develop or even assess the quality of your security policy, there are several">Human Resources - Because many times employee behavior is involved in an incidentLegal - Because many times employee behavior is involved in an incidentPrivacy - Because sometimes personally identifiable information is involved in an incidentInformation Security - Because threats against company systems and data are involved in an incidentPhysical Security - Because sometimes an employee needs to be encouraged to leave as a part of an incident">Take a look at theSANS policy websiteand look for anyany topics that may be missing in your organization.All that said, what two things can you do next week to improve your security policies? Let us know in the comments area!"> (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Envoyé Oui
Condensat 23rd >human >take about account acentral actually administrative against air all allowed anexpiration anyany are area aspects assess attribution basis because behavior behavioral being best both built calendar can capabilities center comments commons company companyis considera control created creative current data date decision develop each edu elusive employee employees encouraged ensure even every everyone existed expectations expected faced facilitate finally find fingers found get guardrails hands have hear heard help hope how https://isc identifiable implemented important improve incident incidentinformation incidentlegal incidentphysical incidentprivacy information internet involved issues jar jul just key know knowingwhere leave let license like locationfor look loud magic many may memorize missing more most needed needs next non noncommercial not nothing number observation ofmayonnaise often one organization originally our out over part personally physical policies policiesshould policy policywhen process protect quality question raising realistic reasons recurring redefine refrigerator regular regularly reminder requires resource resources response reviewed said sake sans sat say security serve set several should solid someone sometimes spread start states storm systems technical than them thesans theset things think threatened threats times topics two unfortunately united updates versus websiteand week what when wiggling will win your
Tags
Stories
Notes
Move


L'article ne semble pas avoir été repris aprés sa publication.


L'article ne semble pas avoir été repris sur un précédent.
My email: