Information security policy -: what do international information security standards say?

被引:91
作者
Höne, K [1 ]
Eloff, JHP [1 ]
机构
[1] Rand Afrikaans Univ, Dept Comp Sci, Johannesburg, South Africa
关键词
information security policy; international standards; information security; elements; characteristics;
D O I
10.1016/S0167-4048(02)00504-7
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
One of the most important information security controls, is the information security policy. This vital direction-giving document is, however, not always easy to develop and the authors thereof battle with questions such as what constitutes a policy. This results in the policy authors turning to existing sources for guidance. One of these sources is the various international information security standards. These standards are a good starting Point for determining what the information security policy should consist of, but should not be relied upon exclusively for guidance. Firstly, they are not comprehensive in their coverage and furthermore, tending to rather address the processes needed for successfully implementing the information security policy. It is far more important the information security policy must fit in with the organisation's culture and must therefore be developed with this in mind.
引用
收藏
页码:402 / 409
页数:8
相关论文
共 14 条
  • [1] BOWDEN JS, 2001, SECURITY POLICY
  • [2] *BRIT STAND I, 1999, COD PRACT INF SEC MA
  • [3] Bundesamt fur Sicherheit in der Informationstechnik, 1999, IT BAS PROT MAN
  • [4] *DEP TRAD IND, 2000, BUS MAN GUID INF SEC
  • [5] HELWIG SM, 2000, SECURITY POLICY HIGH
  • [6] *INT INF SEC FDN, 1999, GASSP VERS 2
  • [7] *ISF, 2000, FOR STAND GOOD PRACT
  • [8] *ISO IEC, 2001, 13335 PDTR
  • [9] *JISC, 2001, DEV INF SEC POL
  • [10] *OFF INF TECHN, 2001, INF SEC GUID NSW GOV