具体描述
Almost every book on network security talks about developing a "security policy" as part of the security planning process. A good security policy should be the basis for every successful security program, yet over 60-percent of companies do not have policies or have policies that are out of date. Those references that do talk about security policies provide little information on how to actually prepare one. Fewer still help you develop and implement a good policy document that evolves with your evolving security needs. Writing Information Security Polices will help anyone involved in company seurity write a policy that can be both implemented and updated as needed, weather involved in the management or actual technical side of the business.
作者简介
目录信息
1 What information security policies are
2 Determining your policy needs
3 Information security responsibilities
II Writing the Security Policies
4 Physical security
5 Authentication and network security
6 Internet security policies
7 Email security policies
8 Viruses, worms and trojan horses
9 Encryption
10 Software development policies
III Maintaining the Policies
11 Acceptable use policies
12 Compliance and enforcement
13 The policy review process
IV Appendices
A Glossary
B Resources
C Sample Policies
· · · · · · (收起)