Organizational Security:

From HORSE - Holistic Operational Readiness Security Evaluation.
Revision as of 12:40, 15 June 2007 by Mdpeters (talk | contribs) (→‎'''Organizational Security''')
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to navigation Jump to search

Organizational Security

ISO 27002 (17799) defines Security Policy objectives to provide management direction and support for information security. This section provides templates for an Information Security Program Charter and supporting policies that are required to comply with ISO Security Policy objectives.

1. Sample ISO Information Security Program Charter
The Information Security Program Charter is required to comply with ISO Security Policy objectives and serves as the capstone document for the Information Security Program that empowers the Program to manage Information Security-related business risks.


2. Sample ISO Information Handling Standard
This Information Handling Standard is required to comply with ISO Communications and Operations Management objectives and builds on the objectives established in the Asset Protection Policy by providing specific instructions and requirements for handling information assets. These instructions address handling requirements for printed, electronically stored and electronically transmitted information.


3. Sample Remote Access Standard
The Remote Access Standard for information assets will be provided only to meet an approved business need or perform prescribed job responsibilities to comply with ISO Organizational Security requirements. Remote access must be facilitated by using Company-approved methods and programs.