官术网_书友最值得收藏!

Planning policy

A planning policy in this context has to do with developing the information security program. This policy sets the foundation for an organization's information security program and is one of the initial activities that should be undertaken when an organization is beginning to mature its information security capability. Additionally, this policy establishes rules around the development, documentation, periodic update, and implementation of security plans for organizational information systems.

A planning policy should address:

  • The establishment of organizational roles—CIO, CISO, system owner, data owner, data custodian, and so on
  • What should be included and what should the update frequency be for the information security program plan?
  • What artifacts should be developed to ensure repeatable processes around information security control selection, development, and implementation?
主站蜘蛛池模板: 合川市| 济阳县| 通榆县| 且末县| 和顺县| 磴口县| 九寨沟县| 龙门县| 浮山县| 蓝田县| 雷州市| 吉林市| 车致| 嵩明县| 东明县| 平遥县| 蒙自县| 宁德市| 瑞安市| 明水县| 平江县| 宁陕县| 甘南县| 岳阳市| 桃园县| 兴国县| 洛隆县| 台州市| 大新县| 长武县| 东海县| 崇阳县| 临洮县| 通城县| 北海市| 岳普湖县| 山阴县| 台安县| 常熟市| 博爱县| 汉源县|