|
Abstract: . . . configuration, new applications) Review results utilized for evaluating and updating the Security Policy 36 Conclusions There is no “out of the box” security solution Customize Security Policies content, structure, security guidelines Utilize best practice, Information Security Standards Effective implementation context-dependent . . . . . . approval of senior management” *RUSecureTM Information Security Policies 28 Security Policies Content -7- (based on ISO 17799) VII. Systems development and maintenance Security requirements of systems “built-in” security Security in application systems Message authentication, hash algorithms, cryptography Cryptographic controls To protect the confidentiality, authenticity or integrity of information (encryption, digital signatures, key management) 29 Examples* “All new hardware installations . . . . . . applications) Review results utilized for evaluating and updating the Security Policy 36 Conclusions There is no “out of the box” security solution Customize Security Policies content, structure, security guidelines Utilize best practice, Information Security Standards Effective implementation context-dependent . . . . . . 18 months Occasional when major changes occur (e.g. network configuration, new applications) Review results utilized for evaluating and updating the Security Policy 36 Conclusions There is no “out of the box” security solution Customize Security Policies content, structure, security guidelines Utilize best practice, Information Security Standards Effective implementation context-dependent . . . . . . management processes. Business continuity management should include controls to identify and reduce risks, limit the consequences of damaging incidents, and ensure the timely resumption of essential operations. 31 Security Policies Content -9- (based on ISO 17799) IX. Compliance Compliance with legal requirements Data protection and privacy of personal information Intellectual property rights (IPR) Regulation of cryptographic controls Compliance with security policy 32 Examples* “P ersons responsible . . . --2456,5,246,2399,12278
|