In: Computer Science
For the given scenario to design a security policy as an IT security specialist for the organisation, let's get abrief idea of what a security policy is.Let's get started
Security Policy: In bussiness and organisations a security policy is aset of rules and procedure as an written documents that outlines for all individuals that how to protect the company's physical and information technology (IT) assets. A security policy is a "living document" which means it is continuously updated as technology and employee requirements change So this document is often considered as never finished document. It also needs to outline damages to those items.
The objectives of security policy is the preservation of privacy, ethics, and accessibility of systems and information used by an organization employees.
Confidentiality involves the protection of assets from
unauthorized entities
Integrity assure the improvement of assets is handled in a
specified manner
Availability is a state of the system in which authorized users
have continuous access to the assets
How to Develop Policy:
Security policy must be based on the results of a risk assessment.Institutions such as the International Organization of Standardization (ISO) and the U.S. National Institute of Standards and Technology (NIST) have published standards and best practices for security policy formation also finding these risk assessment clears the picture to policy makers of security needs of the Organisation.The steps to build a successful security policy includes:
The most important security polices:
<<<<As a security policy is a huge doument In the given time i can only provide this much information.Please do upvote.It motivates us to do better.For any doubt or query reach us in comments.Be safe>>>>>