Security Policy



The security policy is the single most important security work product by acting as a central repository for all strategies and rules for ensuring proper security. A security policy is typically developed at the organizational level (e.g., business unit level), but is may also be developed for a data or contact center or for a single software-intensive system. It typically drives the development and content of subsequent documents including detailed standards, procedures, and guidelines

Definition

The security policy is the security work product that formally and succinctly documents all strategies and rules for ensuring proper security.

Objectives

The typical objectives of the security policy is to:

Benefits

The typical benefits of the security policy are to:

Contents

The typical contents of the security policy are:

Stakeholders

The typical stakeholders of the security policy are:

Phases

Preconditions

The security policy typically can be started if the following preconditions hold:

Inputs

The security policy typically has the following inputs:

Guidelines

Conventions

The security policy is typically constrained by the following conventions:

Examples