- Acceptable Encryption Policy
Defines requirements for encryption algorithms used within the organization.
http://www.sans.org/newlook/resources/policies/Acceptable_Encryption_Policy.pdf
(Added: Thu Apr 06 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- Acceptable Use Policy
Defines acceptable use of equipment and computing services, and the appropriate employee security measures to protect the organization's corporate resources and proprietary information.
http://www.sans.org/newlook/resources/policies/Acceptable_Use_Policy.pdf
(Added: Mon Apr 03 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- Acquisition Assessment Policy
Defines responsibilities regarding corporate acquisitions, and defines the minimum requirements of an acquisition assessment to be completed by the information security group.
http://www.sans.org/newlook/resources/policies/Aquisition_Assessment_Policy.pdf
(Added: Wed Apr 05 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- Analog/ISDN Line Policy
Defines standards for use of analog/ISDN lines for Fax sending and receiving, and for connection to computers.
http://www.sans.org/newlook/resources/policies/Analog_Line_Policy.pdf
(Added: Mon Apr 03 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- Anti-Virus Guidelines
Defines guidelines for effectively reducing the threat of computer viruses on the organization's network.
http://www.sans.org/resources/policies/Anti-virus_Guidelines.pdf
(Added: Thu Apr 06 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- Application Service Provider Policy
Defines minimum security criteria that an ASP must fulfil in order to be considered for use on a project by the organization.
http://www.sans.org/newlook/resources/policies/Application_Service_Providers.pdf
(Added: Wed Apr 05 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- Application Service Provider Standards
Sample set of minimum security standards that an application service provider must meet to be considered for use by a corporation.
http://www.sans.org/newlook/resources/policies/asp_standards.pdf
(Added: Thu Apr 06 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- Audit Policy
Defines the requirements and provides the authority for the information security team to conduct audits and risk assessments.
http://www.sans.org/newlook/resources/policies/Audit_Policy.pdf
(Added: Mon Apr 03 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- Automatically Forwarded Email Policy
Documents the requirement that no email will be automatically forwarded to an external destination without prior approval from the appropriate manager or director.
http://www.sans.org/newlook/resources/policies/Automatically_Forwarded_Email_Policy.pdf
(Added: Sat Apr 01 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- Company Email Policy
A menu of clauses suitable for email acceptable use policies.
http://www.cli.org/emailpolicy/top.html
(Added: Mon Apr 03 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- Computing Policies
The electronic resource usage and security policy for the University of Pennsylvania.
http://www.upenn.edu/computing/policy/
(Added: Thu Apr 06 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- Database Password Policy
Defines requirements for securely storing and retrieving database usernames and passwords.
http://www.sans.org/newlook/resources/policies/DB_Credentials_Policy.pdf
(Added: Fri Mar 31 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- Dial-in Access Policy
Sample policy controlling the use of dial-in connection to corporate networks.
http://www.sans.org/newlook/resources/policies/Dial-in_Access_Policy.pdf
(Added: Thu Mar 30 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- DMZ Lab Security Policy
Sample policy establishing the minimum security requirements of any equipment to be deployed in the corporate De-Militarized Zone.
http://www.sans.org/newlook/resources/policies/DMZ_Lab_Security_Policy.pdf
(Added: Thu Apr 06 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- Enterprise Ireland How To Guides
A combined security policy and security procedures example document.
http://www.enterprise-ireland.com/ebusiness/guides/internal_security/internal_security_index.htm
(Added: Wed Apr 05 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- ePolicy Institute
Policies on information security and other topics.
http://www.epolicyinstitute.com
(Added: Thu Apr 06 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- Extranet Policy
Defines the requirement that third party organizations requiring access to the organization's networks must sign a third-party connection agreement.
http://www.sans.org/newlook/resources/policies/Extranet_Policy.pdf
(Added: Wed Apr 05 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- Information Sensitivity Policy
Sample policy defining the assignment of sensitivity levels to information.
http://www.sans.org/newlook/resources/policies/Information_Sensitivity_Policy.pdf
(Added: Thu Apr 06 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- Internal Lab Security Policy
Defines requirements for internal labs to ensure that confidential information and technologies are not compromised, and that production services and interests of the organization are protected from lab activities.
http://www.sans.org/newlook/resources/policies/Internal_Lab%20Security_Policy.pdf
(Added: Wed Apr 05 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- Internet DMZ Equipment Policy
Sample policy defining the minimum requirement for all equipment located outside the corporate firewall.
http://www.sans.org/newlook/resources/policies/Internet_DMZ_Equipment_Policy.pdf
(Added: Thu Mar 30 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- Introduction to Security Policies, Part Four: A Sample Policy
Examples of security policies to demonstrate writing styles.
http://www.securityfocus.com/infocus/1497
(Added: Wed Apr 05 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- K-20 Network Acceptable Use Policy
Policy on acceptable use of a school network, along with information for parents and an informed consent form.
http://www.k12.wa.us/K-20/AUPSchBoardNetworkUse.aspx
(Added: Wed Apr 05 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- Lab Anti-Virus Policy
Defines requirements which must be met by all computers connected to an organization's lab networks to ensure effective virus detection and prevention.
http://www.sans.org/resources/policies/Lab_Anti-Virus_Policy.pdf
(Added: Mon Apr 03 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- New York State Office for Technology - Information Security Policy
Example of how to define high level information security principles and architecture, leading to an overall information security policy.
http://www.irm.state.ny.us/security/security.htm
(Added: Mon Apr 03 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- Password Protection Policy
Defines standards for creating, protecting and changing strong passwords.
http://www.sans.org/newlook/resources/policies/Password_Policy.pdf
(Added: Mon Apr 03 2006 Rating: 0.00 Votes: 0)
Rate It
Review It