Great Circle Associates Firewalls
(March 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: books on security policies
From: John Bell <job @ hprofsdv . nwscc . sea06 . navy . mil>
Date: Mon, 11 Mar 96 22:42:52 EST
To: firewalls @ greatcircle . com
In-reply-to: <9603111625 . AA07746 @ radiatore . mccaw-stg . com>; from "Peter Gregory" at Mar 11, 96 8:25 am
Mailer: Elm [revision: 70.85.2.1]
Reply-to: job @ hprofsdv . nwscc . sea06 . navy . mil

> 
> folks,
> 
> are there any books in print that address real-life security policies?
> there are any number of books on security (both networks and systems), but
> none that i have seen to date discuss - in any detail - an organization's
> security policies: what they should include, etc.
> 
> thanks,
> 
> peter gregory
> 
> --
> 
> Peter Gregory  [NICname PG11]  peter .
 gregory @
 attws .
 com
> Systems/Network Architect, AT&T Wireless Services, Strategic Technologies Group
> 

1) Determine your assetts and organizational needs
2) Decide which assetts warrant extra protection
3) Form a consensus on the type/level of protection required
4) Write this information down
5) Hand this document to your Technical and Legal departments, in order
   to determine if policy implementation is feasible
6) If step "5" is a go, have technical/legal author procedure docs
   which will be referenced by the policy doc
7) Make changes as organizational needs and/or assetts change

That's about as close to a policy template that you'll see. Policies tend
to be tailored, not one-size-fits-all. By definition, this requires
extra effort (effort well spent up front, _before_ implementation).

If I'm missing anything, please feel free to pipe up :-).

Have fun,
--
                       John Bell, CACI Inc. - Federal
           Bloomington, Indiana (Midwest RE-Engineering Division)
        job @
 hprofsdv .
 nwscc .
 sea06 .
 navy .
 mil -OR- jbii @
 mama .
 indstate .
 edu
                      "Hi ho! Yow! I'm surfing ARPANET!"
                 - anagram for "The Information Superhighway"


Follow-Ups:
References:
Indexed By Date Previous: Re: Firewalls: NT versus UNIX
From: Michael Dillon <michael @ memra . com>
Next: Re: Firewalls: NT versus UNIX
From: C Matthew Curtin <cmcurtin @ gatekeeper . cb . att . com>
Indexed By Thread Previous: books on security policies
From: peterg @ mccaw-stg . com (Peter Gregory)
Next: Re: books on security policies
From: jgt10 @ amdahl . com (John G. Thompson)

Google
 
Search Internet Search www.greatcircle.com