官术网_书友最值得收藏!

Information security policies

Information security policies establish the rules where organizations can direct funding, people, processes, and technology in a retable and secure manner. NIST SP 800-95, Guide to Secure Web Services, defines policy as:

"Statements, rules or assertions that specify the correct or expected behavior of an entity."

Information security policies are developed by examining compliance requirements, obligations under the law, and organization-wide policies and practices. These policies are responsible for establishing rules behind how an organization develops and operates systems utilizing their system's engineering life cycle (SELC) or system's development life cycle (SDLC).

主站蜘蛛池模板: 治多县| 普格县| 汉川市| 武清区| 都匀市| 邵武市| 邳州市| 奉新县| 开平市| 双桥区| 台南市| 吉安县| 绍兴县| 谷城县| 资兴市| 长治市| 仁化县| 磐安县| 从化市| 琼海市| 吴堡县| 桐梓县| 抚远县| 湖州市| 屏东市| 南岸区| 屏东市| 邢台市| 抚顺市| 正安县| 尚志市| 连平县| 东乌珠穆沁旗| 定远县| 当阳市| 新田县| 冷水江市| 麻阳| 项城市| 突泉县| 汶上县|