InfoSec-Policy Based Management System

AID: 3390
  • Status: Published

6730 points

  • Byseaninman
  • TypeBest Practices
  • Posted on2010-07-13 at 07:18:41
Awards
  • Community Pick
  • Experts Exchange Approved
In an early article I gave some Tips for Writing Information Security Policies.  I’d like to continue with this topic and provide a framework that will hopefully make it easier for you to develop all policies, standards & procedures needed for an Information Security Program.

There are many different ways to approach policy documentation.  What I have found to be the most effective for users, auditors & management to read and understand is to create a separate document for policy, standard and procedure for each topic.  Let me explain by using the example “Password Policy“.

PBMS-Pyramid.png
  • 11 KB
  • Policy Based Management System Pyramid
Policy Based Management System Pyramid
So at the top of the pyramid there is Policy.  This is the overall policy that gives the “marching orders” to your users, policies should not change that often. Using our example the password policy a policy statement might be:
Passwords must be complex.

Next there is Standards. This document will list out the technical details to support the policy.  Using our example, the standards may be:
Passwords must be 8 characters long & contain upper case, lower case, number, symbol.

Following standards is Procedures. Your procedures are basically “How To’s“, creating these documents
could be beneficial in cutting down support calls on how to do certain tasks.  Again using our example of the password policy, one procedure document could be:

Changing Passwords

Finally there is what I call Supporting Documentation.  Basically these documents are forms or checklists.  Supporting documentation may not be needed for each topic covered, but could be helpful for users that are required to follow these documents.

Okay, you're probably thinking, WOW this guy just quadrupled my documentation!  Well, that's true; however once this project is underway it really does make sense and enables you to manage documentation more effectively.

If you document everything in one big document that document will probably include policies, standards, and maybe some procedures.  As I said earlier, policies shouldn’t change very often, however standards can change fairly regularly.  So if you change one item in your large document that contains all IT Policies & Standards, you now have to get that entire document approved again (could take a while, depending on who all first approved the document).  However, if you had one standards document for that specific topic, the approver would only need to review and approve that one item, not the policy or other policies and standards that doesn’t even apply to what was modified.

Using our example, you might have the following for Passwords.

Password Policy – CIO or Sr. Management approval depending on the organization
Password Standards - Sr. Management approval, depending on organization
Password Procedures - Department Manager, or Team Lead approval, depending on organization

I have used this framework many times to help develop IT Policies, Standards and Procedures for Corporate IT department with great success.  In my next article I will talk about Document Management.  If you have comments or questions please post a comment.

Reposted from my personal blog http:\\www.thesecuritypub.com
    Asked On
    2010-07-13 at 07:18:41ID3390
    Tags

    Security Policies

    ,

    Documentation

    Topic

    Miscellaneous Security

    Views
    1634

    Comments

    Author Comment

    by: seaninman on 2010-07-14 at 18:04:11ID: 17018

    They are reposted from my personal blog.

    Add your Comment

    Please Sign up or Log in to comment on this article.

    Join Experts Exchange Today

    Gain Access to all our Tech Resources

    Get personalized answers

    Ask unlimited questions

    Access Proven Solutions

    Search 3.2 million solutions

    Read In-Depth How-To Guides

    1000+ articles, demos, & tips

    Watch Step by Step Tutorials

    Learn direct from top tech pros

    And Much More!

    Your complete tech resource

    See Plans and Pricing

    30-day free trial. Register in 60 seconds.

    Loading Advertisement...

    Top Misc Security Experts

    1. breadtan

      145,843

      Master

      3,100 points yesterday

      Profile
      Rank: Genius
    2. Russell_Venable

      38,663

      0 points yesterday

      Profile
      Rank: Wizard
    3. ahoffmann

      27,636

      0 points yesterday

      Profile
      Rank: Genius
    4. richrumble

      25,321

      0 points yesterday

      Profile
      Rank: Genius
    5. DaveHowe

      17,129

      2,000 points yesterday

      Profile
      Rank: Genius
    6. SSharma

      16,184

      0 points yesterday

      Profile
      Rank: Genius
    7. younghv

      12,906

      0 points yesterday

      Profile
      Rank: Genius
    8. DaveBaldwin

      12,728

      0 points yesterday

      Profile
      Rank: Genius
    9. Tolomir

      12,268

      0 points yesterday

      Profile
      Rank: Genius
    10. ve3ofa

      11,032

      0 points yesterday

      Profile
      Rank: Genius
    11. dvt_localboy

      10,600

      0 points yesterday

      Profile
      Rank: Sage
    12. pand0ra_usa

      10,600

      0 points yesterday

      Profile
      Rank: Guru
    13. rpggamergirl

      10,364

      0 points yesterday

      Profile
      Rank: Genius
    14. abbright

      10,292

      0 points yesterday

      Profile
      Rank: Guru
    15. kode99

      9,900

      0 points yesterday

      Profile
      Rank: Genius
    16. erniebeek

      9,250

      0 points yesterday

      Profile
      Rank: Genius
    17. slemmesmi

      8,200

      0 points yesterday

      Profile
      Rank: Guru
    18. motnahp00

      8,102

      0 points yesterday

      Profile
      Rank: Sage
    19. CoccoBill

      7,364

      0 points yesterday

      Profile
      Rank: Sage
    20. giltjr

      7,187

      900 points yesterday

      Profile
      Rank: Genius
    21. tedbilly

      7,000

      0 points yesterday

      Profile
      Rank: Genius
    22. arnold

      6,800

      0 points yesterday

      Profile
      Rank: Genius
    23. MASQUERAID

      6,800

      0 points yesterday

      Profile
      Rank: Genius
    24. ZShaver

      6,800

      0 points yesterday

      Profile
      Rank: Master
    25. madunix

      6,624

      0 points yesterday

      Profile
      Rank: Sage

    Hall Of Fame