Components of a Comprehensive Security Policy
This topic describes the components of a comprehensive a security policy.
The figure shows the hierarchy of a corporate policy structure aimed at effectively meeting the needs of all audiences. Most corporations should use a suite of policy documents to meet their wide and varied needs.
■ Governing policy: This policy is a high-level treatment of security concepts that are important to the company. Managers and technical custodians are the intended audience. The governing policy controls all security-related interaction among business units and supporting departments in the company. In terms of detail, the governing policy answers the "what" security policy questions.
■ Technical policies: Security staff members use technical policies as they carry out their security responsibilities for the system. These policies are more detailed than the governing policy and are system- or issue-specific (for example, access control or physical security issues). In terms of detail, technical policies answer the "what," the "who," the "when," and the "where" security policy questions.
■ End-user policies: This document covers all security topics important to end users. In terms of detail level, end-user policies answer the "what," "who," "when," and "where" security policy questions at an appropriate level of detail.
Most of the discussion in this course will focus on the specific needs met by technical policies.
© 2006 Cisco Systems, Inc. Introduction to Network Security Policies 1-125
Governing Policy Comes from the Top
Governing policy includes these key components:
• A statement of the issue that the policy addresses
• A statement about your position on the policy
• How the policy applies in the environment
• The roles and responsibilities of those affected by the policy
• What level of compliance to the policy is necessary
• Which actions, activities, and processes are allowed and which are not
• What consequences of noncompliance are
The governing policy outlines the security concepts that are important to the company for managers and technical custodians.
■ The governing policy controls all security-related interactions among business units and supporting departments in the company.
■ The governing policy aligns closely with existing company policies, especially human resource policies, but also any other policy that mentions security-related issues such as email, computer use, or related information technology (IT) subjects.
■ The governing policy is placed at the same level as all company-wide policies.
■ The governing policy supports the technical and end-user policies.
The figure lists the key components of the governing policy.
1-126 Security Cisco Network Devices (SND) v2.0 © 2006 Cisco Systems, Inc.
Technical and User Policies
Categories of technical policies describe the duties of the security staff in specified technical areas:
- General policies
- E-mail policies
- Remote access policies
- Telephony policies
- Application policies
- Network policies
- DMZ policies
- Lab policies
User policies detail specific duties and responsibilities for end users.
SPAN Engineering
General security policies: •Acceptable use policy •Account access policy •Acquisition assessment policy
•Audit policy •Information sensitivity policy
•Password policy •Risk assessment policy •Global web server policy
Security staff members use the technical policies in the conduct of their daily security responsibilities. These policies are more detailed than the governing policy and are system- or issue-specific (for example, router security or physical security issues). These policies are essentially security handbooks that describe what the security staff does, but not how the security staff performs its functions.
The end-user policy is a single policy document that covers all the policy topics pertaining to information security that end users should know about, comply with, and implement. This policy may overlap with the technical policies and is at the same level as a technical policy. Grouping all end-user policies together means that users have to go only to one place and read one document to learn everything that they need to do to ensure compliance with the company security policy.
© 2006 Cisco Systems, Inc. Introduction to Network Security Policies 1-127
General policies: • AUP
E-mail policies: • Automatically forwarded policy
• Audit policy
• Information sensitivity policy
• Password policy
• Risk assessment policy
• Global web server policy
• Account access request policy
• Acquisition assessment e-mail policy
• Spam (see AUP) Remote access policies:
• Dial-in access policy
• Remote access policy
• VPN security policy Telephony policy:
• Analog and ISDN line security policy
The figure shows some of the security policies used by Cisco Systems. The SANS Institute (http://www.sans.org) lists similar policies and provides many templates for these policies that you can adopt for your own organizational requirements. Not all organizations need all of these policies. One of your first tasks will be to select and adopt these policies templates as applicable:
■ Here is a list of general policies:
— Acceptable use policy (AUP): Defines the acceptable use of equipment and computing services, and the appropriate employee security measures to protect the organization corporate resources and proprietary information
— Account access request policy: Formalizes the account and access request process within the organization (Users and system administrators who bypass the standard processes for account and access requests can lead to legal action against the organization.)
— Acquisition assessment policy: Defines the responsibilities regarding corporate acquisitions and defines the minimum requirements of an acquisition assessment that the information security group must complete
— Audit policy: Conducts audits and risk assessments to ensure integrity of information and resources, investigates incidents, ensures conformance to security policies, or monitors user and system activity where appropriate
— Information sensitivity policy: Defines the requirements for classifying and securing information in a manner appropriate to its sensitivity level
— Password policy: Defines the standards for creating, protecting, and changing strong passwords
— Risk assessment policy: Defines the requirements and provides the authority for the information security team to identify, assess, and remediate risks to the information infrastructure associated with conducting business
— Global web server policy: Defines the standards required by all web hosts
1-128 Security Cisco Network Devices (SND) v2.0
© 2006 Cisco Systems, Inc.
— Automatically forwarded e-mail policy: Documents the policy restricting automatic e-mail forwarding to an external destination without prior approval from the appropriate manager or director
— E-mail policy: Defines the standards to prevent tarnishing the public image of the organization
— Spam policy: (Spam is covered in the AUP.)
■ Here is a list of remote access policies:
— Dial-in access policy: Defines the appropriate dial-in access and its use by authorized personnel
— Remote access policy: Defines the standards for connecting to the organization network from any host or network external to the organization
— Virtual private network (VPN) security policy: Defines the requirements for remote access IPsec or Layer 2 Tunneling Protocol (L2TP) VPN connections to the organization network
■ Here is a type of telephony policy:
— Analog and ISDN line policy: Defines the standards for use of analog and ISDN lines for sending and receiving faxes and for connection to computers
© 2006 Cisco Systems, Inc. Introduction to Network Security Policies 1-129
Application policies: • Acceptable encryption
Network policies:
• Extranet policy
• Minimum requirements for policy
• Database credentials network access policy
• Network access standards
• Router and switch security coding policy • Interprocess policy
• Server security policy
• Wireless communications communications policy
• Project security policy
• Source code protection policy policy
These policy templates will also need to be selected and adopted:
■ Application policies: There is a wide range of application policies. Here are some of the listings:
— Acceptable encryption policy: Defines the requirements for encryption algorithms used within the organization
— Application service provider (ASP) policy: Defines the minimum security criteria that an ASP must execute before the organization uses them on a project
— Database credentials coding policy: Defines the requirements for securely storing and retrieving database usernames and passwords
— Interprocess communications policy: Defines the security requirements that any two or more processes must meet when they communicate with each other using a network socket or operating system socket
— Project security policy: Defines requirements for project managers to review all projects for possible security requirements
— Source code protection policy: Establishes minimum information security requirements for managing product source code
■ Network policies: There are many network policies as well. Here are some of the listings:
— Extranet policy: Defines the requirement that third-party organizations requiring access to the organization networks must sign a third-party connection agreement
— Minimum requirements for network access policy: Defines the standards and requirements for any device requiring connectivity to the internal network
— Network access standards: Defines the standards for secure physical port access for all wired and wireless network data ports
1-130 Security Cisco Network Devices (SND) v2.0
© 2006 Cisco Systems, Inc.
— Router and switch security policy: Defines the standards for minimal security configuration for routers and switches inside a company production network or used in a production capacity
— Server security policy: Defines the standards for minimal security configuration for servers inside a company production network or used in a production capacity
— Wireless communication policy: Defines standards for wireless systems used to connect to the organization networks
© 2006 Cisco Systems, Inc. Introduction to Network Security Policies 1-131
Types of Technical Policies (Cont.)
DMZ policies:
• DMZ equipment
• DMZ application server
• DMZ web entitlement
Lab policies:
• Active directory trust process
• Internal lab security policy
• Lab antivirus policy
These policy templates will also need to be selected and adopted.
■ Here is a list of demilitarized zone (DMZ) policies:
— DMZ equipment: Defines the standards that all equipment in the organization in the DMZ must meet
— DMZ application server: Defines the standards required that all application servers in the organization in the DMZ must meet
— DMZ web entitlement: Defines the minimum authentication standards required by all applications that run on any web infrastructure in the organization in the DMZ must meet
■ Here is a list of lab policies:
— Active directory trust process: Defines the process used to grant a security trust with the production active directory
— Internal lab security policy: Defines the requirements for internal labs to ensure that lab use does not compromise confidential information and technologies and that lab activities do not compromise production services and the interests of the organization
— Lab antivirus policy: Defines the requirements that all computers connected to the organization lab networks must meet to ensure effective virus detection and prevention
1-132 Security Cisco Network Devices (SND) v2.0 © 2006 Cisco Systems, Inc.
Continue reading here: Adaptive Threat Defense
Was this article helpful?
Readers' Questions
-
may10 months ago
- Reply
-
katja1 year ago
- Reply
-
dinodas1 year ago
- Reply
-
sirkka1 year ago
- Reply
-
leanna1 year ago
- Reply
-
fre-swera1 year ago
- Reply