- GASSP Home Page
pop
Generally Accepted System Security Principles, developed by The International Information Security Foundation.
http://web.mit.edu/security/www/gassp1.html
(Added: Wed Apr 05 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- How to Develop a Network Security Policy White Paper
pop
This document is for business executives, and others, who want to know more about Internet and internetworking security, and what measures you can take to protect your site.
http://wwws.sun.com/software/whitepapers/wp-security-devsecpolicy/
(Added: Wed Apr 05 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- IT Security Cookbook
pop
An excellent guide to computer & network security with a strong focus on writing and implementing security policy. This is primarily for security managers and system administrators.
http://www.boran.com/security/
(Added: Mon Apr 03 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- Acceptable Use Policy Report
A report on Acceptable Usage Policy: what corporations expect of it, a case study, and a framework for creating your own policy.
http://members.iinet.net.au/~colinwee/mbt/acceptableuse/
(Added: Mon Apr 03 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- Aelita Enterprise Directory Manager
Secure "Rules and Roles" management platform that facilitates secure Exchange and Active Directory administration.
http://www.aelita.com/products/enterprisedirectorymanager/
(Added: Mon Apr 03 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- AmiWall.org
Proxy based system to aid in implementing employee internet use policies.
http://www.amiwall.org/
(Added: Thu Apr 06 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- An Overview of Corporate Computer User Policy
Article discusses the elements of a corporate security policy, which it calls the gateway to a company`s intellectual property. The main threat to information security within a company is its employees.
http://www.sans.org/rr/papers/50/535.pdf
(Added: Wed Apr 05 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- Best Practices in Network Security
Knowing how and what to protect and what controls to put in place is difficult. It takes security management, including planning, policy development and the design of procedures.
http://enterprisesecurity.symantec.com/article.cfm?articleid=42&PID=372347
(Added: Thu Apr 06 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- Browsing with a Loaded Gun
A strong web Security Policy is key to keeping your company safe in the net-centric world. (PDF format)
http://www.pentasafe.com/whitepapers/LoadedGun.PDF
(Added: Mon Apr 03 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- Building and Implementing a Successful Information Security Policy
White paper providing the reader with new and innovative aspects on the process of building a Security Policy, as well as managing a Security Awareness Program.
http://www.windowsecurity.com/pages/security-policy.pdf
(Added: Thu Apr 06 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- Building Effective, Tailored Information Security Policy
20th NISSC Internet Technical Security Policy Panel
http://csrc.nist.gov/nissc/1997/panels/isptg/pescatore/html/
(Added: Wed Apr 05 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- Canada's Export Controls
Unofficial / unverified article describing Canada's export controls on cryptographic software.
http://www.efc.ca/pages/doc/crypto-export.html
(Added: Wed Apr 05 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- CERT Practice Modules: Improving Security
Determine contractor ability to comply with your organization's security policy.
http://www.cert.org/security-improvement/practices/p019.html
(Added: Mon Apr 03 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- CERT Practice Modules: Responding to Intrusions
Establish policies and procedures for responding to intrusions.
http://www.cert.org/security-improvement/modules/m06.html
(Added: Mon Apr 03 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- CERT Practice Modules: Securing Desktop Workstations
Develop and promulgate an acceptable use policy for workstations.
http://www.cert.org/security-improvement/practices/p034.html
(Added: Wed Apr 05 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- CobiT User Group
International user group and hub for CobiT, the emerging IT control and security methodology.
http://www.controlit.org
(Added: Mon Apr 03 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- Common Criteria Evaluation and Validation Scheme
The US government agency overseeing the Common Criteria security certification Program
http://niap.nist.gov/cc-scheme
(Added: Thu Mar 30 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- Computer and Information Security Policy
Formal IT security policy helps establish standards for IT resource protection by assigning program management responsibilities and providing basic rules, guidelines, and definitions for everyone in the organization. Policy thus helps prevent inconsistencies that can introduce risks, and policy serves as a basis for the enforcement of more detailed rules and procedures.
http://secinf.net/info/policy/hk_polic.html
(Added: Mon Apr 03 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- Create Order with a Strong Policy
A well-written, well-run security policy prevents cracks from appearing in your network's foundation.
http://www.networkmagazine.com/article/NMG20000710S0015
(Added: Wed Apr 05 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- Developing an Information Security Strategy
This whitepaper describes the steps needed to develop an organization-wide information security strategy.
http://www.hartgregorygroup.com/sec-strategies/LogicalSecurityStrategy.PDF
(Added: Wed Apr 05 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- Do you have an intrusion detection response plan?
Discussion of what should go into the creation of an intrusion detection plan and the expected results.
http://www.nwfusion.com/newsletters/sec/0913sec1.html
(Added: Mon Apr 03 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- E-Policy
E-policy is a corporate statement and set-of-rules to protect the organization from casual or intentional abuse that could result in the release of sensitive information, IT system failures or litigation against the organization by employees or other parties.
http://www.c2c.com/industry/whitepapers_policy.htm
(Added: Wed Apr 05 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- Formulating a Wireless LAN Security Policy: Relevant Issues, Considerations and Implications
[Word Document] This paper represents the security issues related to the use of wireless (vs wired) LAN technology and recommends a number of key implementation guidelines to ensure the secure deployment of wireless LAN services in the company.
http://www.giac.org/practical/David_Quay_GSEC.doc
(Added: Wed Apr 05 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- How to Develop Good Security Policies and Tips on Assessment and Enforcement
[Word Document] Invest the time up front to carefully develop sound policies and then identify ways to gauge their effectiveness and assess the level of compliance within your organization. Commit to spending the time and resources required to ensure that the policies are kept current and accurately reflect your company's security posture.
http://www.giac.org/practical/Kerry_McConnell_GSEC.doc
(Added: Sat Apr 01 2006 Rating: 0.00 Votes: 0)
Rate It
Review It
- IASEP Data Security Protocol
An archive website from the Purdue Research Foundation, containing a range of example security policy sets.
http://iasep.soe.purdue.edu/protocol/MAIN_DOC/table_of_contents.htm
(Added: Sat Apr 01 2006 Rating: 0.00 Votes: 0)
Rate It
Review It