1) Search for sample security policies on the Web. Identify and analyze two EISP
ID: 3686557 • Letter: 1
Question
1) Search for sample security policies on the Web. Identify and analyze two EISP and two ISSP sample policies. Copy and paste them into the document then individually compare these with the framework presented in Chapter 4 and comment on the policies' comprehensiveness. Make sure you identify all your sources properly. 2) Using the framework presented in our readings, draft a sample issue-specific security policy for an organization. At the beginning of your document, identify and describe the organization for which you are creating the policy and then complete the policy using the framework. Cite sources if necessary. Length of Research Assignment: 150-250 words
Explanation / Answer
1)
Enterprise Information Security Policy
Issue-Specific Security Policy
It directly supports the Organization.
It Supports both members and Organization.
Executive level document
Organization level document
It does not required continuous modification
It required continuous modification
End user is responsible
Every department is responsible
EISP will cover all issues
Sometimes it fails to cover all issues
---------------------------------------------------------------------------------------------------------------------------------------------------------------------
2)
Security for IT organization:
---------------------------
Scope:
-----
This policy is limited to IT organization which is to apply security and it will be check and maintained
by administrator. But it depends on various departments.
Maintainance:
-------------
Every department head will take care upto his level. Security officer or administrator officer
will check every week.
Roles and Responsibilities:
---------------------------------------------
(i) IT administrator is responsible to coordinate all department heads.
(ii) His responsible is to check policy settings day to day
(iii) coordinate information security with all departments
(iv) must give support always whenever required
(v) Give access to users as per requirement
Enterprise Information Security Policy
Issue-Specific Security Policy
It directly supports the Organization.
It Supports both members and Organization.
Executive level document
Organization level document
It does not required continuous modification
It required continuous modification
End user is responsible
Every department is responsible
EISP will cover all issues
Sometimes it fails to cover all issues
Related Questions
Navigate
Integrity-first tutoring: explanations and feedback only — we do not complete graded work. Learn more.