Great Circle Associates Firewalls
(March 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: books on security policies
From: Mike Harmon <mharmon @ mail . state . mo . us>
Date: Fri, 15 Mar 1996 15:06:52 -0600 (CST)
To: Peter Gregory <peterg @ mccaw-stg . com>
Cc: firewalls @ greatcircle . com
In-reply-to: <9603111625 . AA07746 @ radiatore . mccaw-stg . com>


On Mon, 11 Mar 1996, Peter Gregory wrote:

> folks,
> 
> are there any books in print that address real-life security policies?
> there are any number of books on security (both networks and systems), but
> none that i have seen to date discuss - in any detail - an organization's
> security policies: what they should include, etc.
> 
> thanks,
> 
> peter gregory
> 
> --
> 
> Peter Gregory  [NICname PG11]  peter .
 gregory @
 attws .
 com
> Systems/Network Architect, AT&T Wireless Services, Strategic Technologies Group
> 
Check out a company called Baseline Software, Inc.
                           P. O. Box 1219 
                           Sausalito, CA  94966-1219
                           Voice: (800) 829-9955 
                           Email: info @
 baselinesoft .
 com
                           
This company puts out a product called "Information Security Policies 
Made Easy.  It's a 426-page 8-1/2" X 11" book, and everything that's in the 
book is also distributed on diskette in ASCII, Word Perfect, and WinWord 
format.  What you get is 730 boilerplate policies that cover every 
possible scenario, from PC security to I-net security to physical security.
 
There's also some nice supporting doc dealing with putting together 
infosec policies and a bunch of appendices containing, among other 
things, a very good bibliography of infosec references, professional 
organization data, and names and addresses of a bunch of infosec-related 
publications.
 
The basic idea is that you can cut and paste the machine-readable stuff 
right into your policy docs, use search-and-replace to change "Company X" 
to whatever your organization's name is, and call it your own.
 
The package costs $500, which is cheap when you consider the amount of 
person-hours it would take to dig this stuff out for yourself!
 
We bought it here, and don't regret it.
 
Mike Harmon
Security Administrator
MO Highway & Transportation Dept.



References:
Indexed By Date Previous: Re: VPN solutions (BorderGuard)
From: Darren Reed <avalon @ coombs . anu . edu . au>
Next: http on ports > 1023
From: srzpem @ swissre . ch (Martin Peter)
Indexed By Thread Previous: Re: books on security policies
From: John Bell <job @ hprofsdv . nwscc . sea06 . navy . mil>
Next: Re: books on security policies
From: amolitor @ anubis . network . com (Andrew Molitor)

Google
 
Search Internet Search www.greatcircle.com