|
Abstract: . . . improving available resources/responsibilities Any revision to the policyshould obtain management approval. Summary The ISO 17799 is widely becoming a framework for manyorganizations seeking toimplement a comprehensive information security . . . . . . following implementation guidelines on what a policy document should contain: a) a definition of information security, its scope and objectives b) a statement of management’s support for securityin conjunction with business objectives c) a framework . . . . . . one ‘main security category,’ followed by two controls. The security policy document should be approved by management and communicatedto all employees. Lastly, there should be a planned reviewof the policy. . . . . . . iso 17799 Page 1 ISO 17799 : Scope and implementation– Security Policy. By Gregory Yhan, MCAD.net, CISSP Introduction As information security becomesincreasingly . . . . . . for information security. The Security Policy clause has one ‘main security category,’ followed by two controls. The security policy document should be approved by management and communicatedto all employees. Lastly, there should be a . . . . . . document should be approved by management and communicatedto all employees. Lastly, there should be a planned reviewof the policy. . . . --1404,6,117,1634,7019
|