官术网_书友最值得收藏!

Systems and services acquisitions policy

The purpose of the systems and services acquisition policy is to ensure that the information security program is properly inserted into the acquisitions life cycle of an organization, helping to ensure that secure and safe products are procured for the organization. Additionally, this policy ties-in the need for an effective SDLC approach, with information security being a key player.

What the system and services acquisitions policy should address:

  • Allocating sufficient resources to adequately protect organizational information systems
  • Employing system development life cycle processes that incorporate information security considerations
  • Employing software usage and installation restrictions
  • Ensuring that third-party providers employ adequate security measures to protect information, applications, and/or services outsourced from the organization
主站蜘蛛池模板: 三河市| 沾化县| 惠安县| 澄城县| 红河县| 延边| 屏山县| 南澳县| 万载县| 巴彦淖尔市| 安徽省| 铜山县| 丹巴县| 太仆寺旗| 瓦房店市| 红桥区| 天峨县| 连云港市| 海兴县| 天等县| 磴口县| 阳山县| 磴口县| 明溪县| 岗巴县| 霍林郭勒市| 洞口县| 龙岩市| 宝鸡市| 中宁县| 乌拉特前旗| 汉川市| 渭南市| 宝清县| 化州市| 罗甸县| 丹寨县| 犍为县| 道孚县| 泗水县| 广昌县|