 | 
| | FAQs, Help, and Tutorials - Security, Computers 8
Acceptable Use PolicyAcceptable Use Policy
Defines acceptable use of IT equipment and computing services, and the appropriate employee security measures to protect the organization's corporate resources and proprietary information. [MS Word]
|
Acquisition Assessment PolicyAcquisition Assessment Policy
Defines responsibilities regarding corporate acquisitions and the minimum requirements of an acquisition assessment to be completed by the information security group. [MS Word]
|
Analog/ISDN Line PolicyAnalog/ISDN Line Policy
Defines policy for analog/ISDN lines used for FAXing and data connections.
|
Anti-Virus PolicyAnti-Virus Policy
Requirements for effective virus detection and prevention. Written for a laboratory environment but easy to adapt for other settings. [MS Word]
|
Application Service Provider PolicyApplication Service Provider Policy
Security criteria for an ASP. [PDF]
|
Audit PolicyAudit Policy
Defines requirements and provides authority for the information security team to conduct IT audits and risk assessments. [PDF]
|
Backup PolicyBackup Policy
Sample policy from the University of North Carolina requires daily, weekly and monthly backups (sometimes known as 'grandfather, father, son').
|
Backup PolicyBackup Policy
A primer to help small businesses write their own backup policies.
|
Backup PolicyBackup Policy
Sample policy requires a cycle of daily and weekly backups (monthly backups are also advisable).
|
Campus Security PolicyCampus Security Policy
An overarching security policy from Berkeley University includes links to more specific and detailed policies.
|
Campus Security PolicyCampus Security Policy
High level information security policy from Washington University.
|
Certification and Accreditation PolicyCertification and Accreditation Policy
Policy template by Walt Kobus defines requirements and responsibilities for security assurance throughout the system development process. [PDF]
|
Communications PolicyCommunications Policy
Datacommunications security policy template by Walt Kobus defines network security control requirements. [PDF]
|
Cryptography PolicyCryptography Policy
Cryptographic policy template by Walt Kobus. [PDF]
|
Data Classification PolicyData Classification Policy
Policy template by Walt Kobus describes the classification of information according to sensitivity (primarily confidentiality). [PDF]
|
Database Password PolicyDatabase Password Policy
Defines requirements for securely storing and retrieving database usernames and passwords. [MS Word]
|
Dial-in Access PolicyDial-in Access Policy
Policy regarding the use of dial-in connections to corporate networks. [MS Word]
|
Disaster Recovery PolicyDisaster Recovery Policy
Basic DR policy in just over one side. [PDF]
|
Disaster Recovery PolicyDisaster Recovery Policy
Succinct DR policy from Imperial College, London.
|
DMZ Security PolicyDMZ Security Policy
Sample policy establishing security requirements of equipment to be deployed in the corporate De-Militarized Zone. [MS Word]
|
Electronic Communications PolicyElectronic Communications Policy
Formal policy from the University of California covering email and other electronic communications mechanisms [PDF]
|
Email Forwarding PolicyEmail Forwarding Policy
Email must not be forwarded automatically to an external destination without prior approval from the appropriate manager. [PDF]
|
Email PolicyEmail Policy
Northern Illinois University email policy
|
Email Retention PolicyEmail Retention Policy
Sample policy to help employees determine which emails should be retained and for how long.
|
Encryption PolicyEncryption Policy
Defines encryption algorithms that are suitable for use within the organization. [MS Word]
|
The ePolicy InstituteThe ePolicy Institute
Provides policies and resources on information security and other related topics.
|
Ethics PolicyEthics Policy
Ethical behavior underpins all procedural security controls. This ethics policy from Spirent is a useful model.
|
Ethics PolicyEthics Policy
Sample policy intended to 'establish a culture of openness, trust and integrity'.
|
Extranet PolicyExtranet Policy
Defines the requirement that third party organizations requiring access to the organization's networks must sign a third-party connection agreement. [MS Word]
|
Government Security PolicyGovernment Security Policy
The New Zealand Government's information security policy, based on the 2000 version of ISO/IEC 17799. [ZIP file containing PDF and MS Word versions]
|
Holistic Operational Security Readiness EvaluationHolistic Operational Security Readiness Evaluation
Collaborative open project building a library of sample information security policies, supporting standards and other documents through a wiki.
|
HSPD-12 Privacy PolicyHSPD-12 Privacy Policy
Sample privacy policy including Privacy Act systems of records notices, Privacy Act statements and a privacy impact assessment, designed to satisfy the requirements of HSPD-12 “Policy for a Common Identification Standard for Federal Employees and Contractors”
|
Identification and Authentication PolicyIdentification and Authentication Policy
I&A policy template by Walt Kobus defines requirements for access control. [PDF]
|
Information Data Ownership PolicyInformation Data Ownership Policy
Policy template by Walt Kobus defines the roles and responsibilities of owners, custodians and users of information systems. [PDF]
|
Information Security PoliciesInformation Security Policies
Templates for information security policies, guidelines, checklists and procedures by Walt Kobus.
|
Information Security PoliciesInformation Security Policies
The Information Security Toolkit from UCISA (University Colleges and Information Systems Association) contains a suite of security policy and guidance documents reflecting and cross-referenced against BS7799, intended for use in universities. [PDF documents]
|
Information Security PoliciesInformation Security Policies
NIST's collection of well over 100 security policies and related awareness materials, mostly from US Government bodies.
|
Information Security PoliciesInformation Security Policies
An extensive collection of information security policy samples at SecurityDocs.
|
Information Security PoliciesInformation Security Policies
111-page security policy manual from the Australian New South Wales Department of Commerce, based on ISO/IEC 27001. [PDF]
|
Information Security PoliciesInformation Security Policies
Set of acceptable use and technical policies from the University of Auckland covering common information security issues.
|
Information Security PoliciesInformation Security Policies
SANS consensus research project offering around 30 editable information security policies.
|
Information Security PolicyInformation Security Policy
High level security policy/guideline from the Department of Health and Human Resources. [PDF]
|
Information Security PolicyInformation Security Policy
An information security policy from the University of Illinois.
|
Information Security PolicyInformation Security Policy
High-level information security policy statement for the Childhood Cancer Research Group at Oxford University.
|
Information Sensitivity PolicyInformation Sensitivity Policy
Sample policy defining the assignment of sensitivity levels to information. [PDF]
|
Internet Acceptable Use PolicyInternet Acceptable Use Policy
One page Acceptable Use Policy example. [PDF]
|
Internet DMZ Equipment PolicyInternet DMZ Equipment Policy
Sample policy defining the minimum requirement for all equipment located outside the corporate firewall. [PDF]
|
IP Network Security PolicyIP Network Security Policy
Example security policy to demonstrate policy writing techniques introduced in three earlier articles.
|
ISO/IEC 27001 PoliciesISO/IEC 27001 Policies
Typical headings for a security policy aligned broadly with the ISO/IEC 27002 standard for information security management systems.
|
ISO27k ToolkitISO27k Toolkit
Collection of information security policies, procedures etc. aligned with the ISO/IEC 27000-series standards and provided under the Creative Commons license. [PDF]
|
IT Security PolicyIT Security Policy
Information technology security policy at Murdoch University, complete wth supporting standards and guidelines.
|
IT Security PolicyIT Security Policy
IT security policy example/how-to guide from Enterprise Ireland.
|
K-20 Network Acceptable Use PolicyK-20 Network Acceptable Use Policy
Policy on acceptable use of a school network, along with information for parents and an informed consent form. Developed in Washington State.
|
Laboratory Security PolicyLaboratory Security Policy
Policy to secure confidential information and technologies in the labs and protect production services and the rest of the organization from lab activities. [MS Word]
|
Law Enforcement Data Security StandardsLaw Enforcement Data Security Standards
IT security policy applicable to the Victoria Police in Australia. 93 pages based on ISO/IEC 27002 and related standards. [PDF]
|
Modem PolicyModem Policy
Sample policy from Sandstorm, designed as an addition to an existing Remote Access Policy, if one exists, or simply to stand alone.
|
Network Security PolicyNetwork Security Policy
Example security policy for a data network from the University of Toronto.
|
Network Security Policy GuideNetwork Security Policy Guide
Watchguard's guide to creating an overarching network information security policy, supported by subsidiary policies. [PDF]
|
Password PolicyPassword Policy
A password policy presented in the form of a series of security awareness posters. "Passwords are like underwear ..." [PDF]
|
Password PolicyPassword Policy
Defines standards for creating, protecting and changing strong passwords. [MS Word]
|
Personnel Security PolicyPersonnel Security Policy
Example policy covering pre-employment screening, security policy training etc. [PDF]
|
Physical Security PolicyPhysical Security Policy
Policy template by Walt Kobus defines requirements for physical access control to sensitive facilities and use of ID badges. [PDF]
|
Privacy PolicyPrivacy Policy
Generic policy for websites offering goods and services, with an important warning to seek qualified legal advice in this area.
|
Privacy PolicyPrivacy Policy
Concise policy (just 3 paragraphs) published by the School of Graduate Studies at Norwich University.
|
Remote Access PolicyRemote Access Policy
Defines standards for connecting to a corporate network from any host. [MS Word]
|
Resource Utilization PolicyResource Utilization Policy
Poilicy template by Walt Kobus defines requirements for resilience, redundancy and fault tolerance in information systems. [PDF]
|
Risk Assessment PolicyRisk Assessment Policy
Defines requirements and authorizes the information security team to identify, assess and remediate risks to the organization's information infrastructure. [MS Word]
|
Router Security PolicyRouter Security Policy
Sample policy establishing the minimum security requirements for all routers and switches connecting to production networks. [MS Word]
|
Security Audit PolicySecurity Audit Policy
Audit policy template by Walt Kobus. [PDF]
|
Security Management PolicySecurity Management Policy
General information security policy template by Walt Kobus. [PDF]
|
Security Policy PrimerSecurity Policy Primer
General advice for those new to writing information security policies. [PDF]
|
Server Security PolicyServer Security Policy
Defines standards for minimal security configuration for servers inside the organization's production network, or used in a production capacity. [PDF]
|
Standard Practice GuideStandard Practice Guide
Policy covering appropriate use of information resources and IT at the University of Michigan. [PDF]
|
Telecommuting/Teleworking PolicyTelecommuting/Teleworking Policy
Sample policy on teleworking covering employment as well as information security issues.
|
Third Party Connection AgreementThird Party Connection Agreement
Sample agreement for establishing a connection to an external party. [PDF]
|
University Information Security PoliciesUniversity Information Security Policies
Electronic resource usage and security policies from the University of Pennsylvania.
|
University Information Security PoliciesUniversity Information Security Policies
A set of information security policies from the University of Louisville.
|
Use of Electronic MailUse of Electronic Mail
Policy from the University of Colorado on the use of, access to, and disclosure of electronic mail.
|
User Data Protection PolicyUser Data Protection Policy
Policy template by Walt Kobus defines requirements for access controls, least privilege, integrity etc. to secure personal data. [PDF]
|
Virtual Private Network PolicyVirtual Private Network Policy
Defines the requirements for Remote Access IPSec or L2TP Virtual Private Network (VPN) connections to the organization's network. [PDF]
|
Wireless Communication PolicyWireless Communication Policy
Sample policy concerning the use of unsecured wireless communications technology. [PDF]
|
|
|
|
|
|