How to Write an Information Security Policy

16.06.2009

Drucken |  Versand |  PDF

* How would you describe the different types of information you work with

* Which types of information do you rely on to make decisions

* Are there any information types that are more of a concern to keep private than others

From these questions, an information classification system can be developed (e.g. customer info, financial info, marketing info, etc), and appropriate handling procedures for each can be described at the business process level. (Editor's note: See also Jason Stradley's provocative take on data classification and related issues.)

Of course, a seasoned security professional will also have advice on how to mold the management opinions with respect to security into a comprehensive organizational strategy. Once it is clear that the security professional completely understands management's opinions, it should be possible to introduce a security framework that is consistent with it. The framework will be the foundation of the organization's Information Security Program, and thus will service as a guide for creating an outline of the information security policy.

zurueck
Seite: 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8
weiter
Newsletter von CIO.de
Exklusiv
Exklusiv Blackberry
Wirtschaftsmeldungen
Karriere
Security
Dynamic IT
Healthcare IT
Whitepaper
IT-Berater
Retail-IT
Finance-Forum
SAP

UMFRAGE
Kommt der Verkaufsstart über Online-Shops mit einem Basissortiment von 2500 Artikeln für den Media Markt noch rechtzeitig?
Ja, der starke Markenname wird den Erfolg bringen.
Ja, aber nur wenn das gesamte Sortiment angeboten wird.
Nein, der Zug ist gegenüber der Konkurrenz abgefahren.
Ich bin unentschieden.
» Abstimmen

SERVICE