Components of a Comprehensive Security Policy

This topic describes the components of a comprehensive a security policy.

Policy Hierarchy

The figure shows the hierarchy of a corporate policy structure aimed at effectively meeting the needs of all audiences. Most corporations should use a suite of policy documents to meet their wide and varied needs.

■ Governing policy: This policy is a high-level treatment of security concepts that are important to the company. Managers and technical custodians are the intended audience. The governing policy controls all security-related interaction among business units and supporting departments in the company. In terms of detail, the governing policy answers the "what" security policy questions.

■ Technical policies: Security staff members use technical policies as they carry out their security responsibilities for the system. These policies are more detailed than the governing policy and are system- or issue-specific (for example, access control or physical security issues). In terms of detail, technical policies answer the "what," the "who," the "when," and the "where" security policy questions.

■ End-user policies: This document covers all security topics important to end users. In terms of detail level, end-user policies answer the "what," "who," "when," and "where" security policy questions at an appropriate level of detail.

Most of the discussion in this course will focus on the specific needs met by technical policies.

© 2006 Cisco Systems, Inc. Introduction to Network Security Policies 1-125

Governing Policy Comes from the Top

Governing policy includes these key components:

• A statement of the issue that the policy addresses

• A statement about your position on the policy

• How the policy applies in the environment

• The roles and responsibilities of those affected by the policy

• What level of compliance to the policy is necessary

• Which actions, activities, and processes are allowed and which are not

• What consequences of noncompliance are

The governing policy outlines the security concepts that are important to the company for managers and technical custodians.

■ The governing policy controls all security-related interactions among business units and supporting departments in the company.

■ The governing policy aligns closely with existing company policies, especially human resource policies, but also any other policy that mentions security-related issues such as email, computer use, or related information technology (IT) subjects.

■ The governing policy is placed at the same level as all company-wide policies.

■ The governing policy supports the technical and end-user policies.

The figure lists the key components of the governing policy.

1-126 Security Cisco Network Devices (SND) v2.0 © 2006 Cisco Systems, Inc.

Technical and User Policies

Categories of technical policies describe the duties of the security staff in specified technical areas:

- General policies

- E-mail policies

- Remote access policies

- Telephony policies

- Application policies

- Network policies

- DMZ policies

- Lab policies

User policies detail specific duties and responsibilities for end users.

SPAN Engineering

General security policies: •Acceptable use policy •Account access policy •Acquisition assessment policy

•Audit policy •Information sensitivity policy

•Password policy •Risk assessment policy •Global web server policy

Security staff members use the technical policies in the conduct of their daily security responsibilities. These policies are more detailed than the governing policy and are system- or issue-specific (for example, router security or physical security issues). These policies are essentially security handbooks that describe what the security staff does, but not how the security staff performs its functions.

The end-user policy is a single policy document that covers all the policy topics pertaining to information security that end users should know about, comply with, and implement. This policy may overlap with the technical policies and is at the same level as a technical policy. Grouping all end-user policies together means that users have to go only to one place and read one document to learn everything that they need to do to ensure compliance with the company security policy.

© 2006 Cisco Systems, Inc. Introduction to Network Security Policies 1-127

General policies: • AUP

E-mail policies: • Automatically forwarded policy

• Audit policy

• Information sensitivity policy

• Password policy

• Risk assessment policy

• Global web server policy

• Account access request policy

• Acquisition assessment e-mail policy

• Spam (see AUP) Remote access policies:

• Dial-in access policy

• Remote access policy

• VPN security policy Telephony policy:

• Analog and ISDN line security policy

The figure shows some of the security policies used by Cisco Systems. The SANS Institute (http://www.sans.org) lists similar policies and provides many templates for these policies that you can adopt for your own organizational requirements. Not all organizations need all of these policies. One of your first tasks will be to select and adopt these policies templates as applicable:

■ Here is a list of general policies:

— Acceptable use policy (AUP): Defines the acceptable use of equipment and computing services, and the appropriate employee security measures to protect the organization corporate resources and proprietary information

— Account access request policy: Formalizes the account and access request process within the organization (Users and system administrators who bypass the standard processes for account and access requests can lead to legal action against the organization.)

— Acquisition assessment policy: Defines the responsibilities regarding corporate acquisitions and defines the minimum requirements of an acquisition assessment that the information security group must complete

— Audit policy: Conducts audits and risk assessments to ensure integrity of information and resources, investigates incidents, ensures conformance to security policies, or monitors user and system activity where appropriate

— Information sensitivity policy: Defines the requirements for classifying and securing information in a manner appropriate to its sensitivity level

— Password policy: Defines the standards for creating, protecting, and changing strong passwords

— Risk assessment policy: Defines the requirements and provides the authority for the information security team to identify, assess, and remediate risks to the information infrastructure associated with conducting business

— Global web server policy: Defines the standards required by all web hosts

1-128 Security Cisco Network Devices (SND) v2.0

© 2006 Cisco Systems, Inc.

— Automatically forwarded e-mail policy: Documents the policy restricting automatic e-mail forwarding to an external destination without prior approval from the appropriate manager or director

— E-mail policy: Defines the standards to prevent tarnishing the public image of the organization

— Spam policy: (Spam is covered in the AUP.)

■ Here is a list of remote access policies:

— Dial-in access policy: Defines the appropriate dial-in access and its use by authorized personnel

— Remote access policy: Defines the standards for connecting to the organization network from any host or network external to the organization

— Virtual private network (VPN) security policy: Defines the requirements for remote access IPsec or Layer 2 Tunneling Protocol (L2TP) VPN connections to the organization network

■ Here is a type of telephony policy:

— Analog and ISDN line policy: Defines the standards for use of analog and ISDN lines for sending and receiving faxes and for connection to computers

© 2006 Cisco Systems, Inc. Introduction to Network Security Policies 1-129

Application policies: • Acceptable encryption

Network policies:

• Extranet policy

• Minimum requirements for policy

• Database credentials network access policy

• Network access standards

• Router and switch security coding policy • Interprocess policy

• Server security policy

• Wireless communications communications policy

• Project security policy

• Source code protection policy policy

These policy templates will also need to be selected and adopted:

■ Application policies: There is a wide range of application policies. Here are some of the listings:

— Acceptable encryption policy: Defines the requirements for encryption algorithms used within the organization

— Application service provider (ASP) policy: Defines the minimum security criteria that an ASP must execute before the organization uses them on a project

— Database credentials coding policy: Defines the requirements for securely storing and retrieving database usernames and passwords

— Interprocess communications policy: Defines the security requirements that any two or more processes must meet when they communicate with each other using a network socket or operating system socket

— Project security policy: Defines requirements for project managers to review all projects for possible security requirements

— Source code protection policy: Establishes minimum information security requirements for managing product source code

■ Network policies: There are many network policies as well. Here are some of the listings:

— Extranet policy: Defines the requirement that third-party organizations requiring access to the organization networks must sign a third-party connection agreement

— Minimum requirements for network access policy: Defines the standards and requirements for any device requiring connectivity to the internal network

— Network access standards: Defines the standards for secure physical port access for all wired and wireless network data ports

1-130 Security Cisco Network Devices (SND) v2.0

© 2006 Cisco Systems, Inc.

— Router and switch security policy: Defines the standards for minimal security configuration for routers and switches inside a company production network or used in a production capacity

— Server security policy: Defines the standards for minimal security configuration for servers inside a company production network or used in a production capacity

— Wireless communication policy: Defines standards for wireless systems used to connect to the organization networks

© 2006 Cisco Systems, Inc. Introduction to Network Security Policies 1-131

Types of Technical Policies (Cont.)

DMZ policies:

• DMZ equipment

• DMZ application server

• DMZ web entitlement

Lab policies:

• Active directory trust process

• Internal lab security policy

• Lab antivirus policy

These policy templates will also need to be selected and adopted.

■ Here is a list of demilitarized zone (DMZ) policies:

— DMZ equipment: Defines the standards that all equipment in the organization in the DMZ must meet

— DMZ application server: Defines the standards required that all application servers in the organization in the DMZ must meet

— DMZ web entitlement: Defines the minimum authentication standards required by all applications that run on any web infrastructure in the organization in the DMZ must meet

■ Here is a list of lab policies:

— Active directory trust process: Defines the process used to grant a security trust with the production active directory

— Internal lab security policy: Defines the requirements for internal labs to ensure that lab use does not compromise confidential information and technologies and that lab activities do not compromise production services and the interests of the organization

— Lab antivirus policy: Defines the requirements that all computers connected to the organization lab networks must meet to ensure effective virus detection and prevention

1-132 Security Cisco Network Devices (SND) v2.0 © 2006 Cisco Systems, Inc.

Continue reading here: Adaptive Threat Defense

Was this article helpful?

+1 -2

Readers' Questions

  • may
    What are the major components of an information systems security policy?
    10 months ago
  • - Acceptable Use Policy - Systems Access Control - Network Security - Data Encryption - Employee Security Training - Physical Security - Data Classification - Incident Response and Reporting - Business Continuity and Disaster Recovery
    • katja
      What are the components of a comprehensive security plan?
      1 year ago
      1. Risk Assessment: Identify potential security risks and vulnerabilities, analyze threats and determine their impact.
      2. Security Policies and Procedures: Establish clear, comprehensive security policies and procedures to guide employees and users in minimizing security risks.
      3. Physical Security: Establish measures to protect facilities and equipment, such as security cameras, locks, access control systems and other physical security measures.
      4. Employee Security Training: Provide ongoing employee security training to ensure employees are aware of security protocols and potential risks.
      5. Access Control: Establish rules and processes to grant or deny access to sensitive information and systems, and regularly monitor and audit access.
      6. Network Security: Implement network security measures to protect against unauthorized access and malicious attacks.
      7. Data Security: Encrypt data to protect from unauthorized use, and regularly back up data to protect against loss.
      8. System Monitoring: Monitor systems for changes or anomalies, and investigate and flag suspicious activities.
      9. Response Plan: Develop a response plan that details processes to follow in the event of a security breach, and define roles for responders.
      10. Compliance: Ensure that security protocols meet applicable laws, regulations and policies.
      • dinodas
        What are the components of issues specific security policy?
        1 year ago
        1. Access Control: Establishing appropriate access control methods to restrict access to systems, applications, and networks.
        2. Incident Response: Establishing a plan to respond to any security-related incidents, such as a data breach.
        3. Data Protection: Establishing a system to protect confidential data from unauthorized access and use.
        4. Authentication: Establishing procedures to verify the identity of users and to ensure that only authenticated users can access the system.
        5. Network Security: Establishing guidelines and protocols to protect the network from external threats and unauthorized access.
        6. System Security: Establishing guidelines and protocols to ensure the secure operation of computer systems and applications.
        7. Education and Training: Establishing a program to educate and train personnel in the proper use of systems and applications.
        8. Monitoring and Auditing: Establishing procedures to monitor the system and applications for threats and vulnerabilities.
        • sirkka
          What are component of issue specific security policy?
          1 year ago
          1. Access Control: Establishing rules and regulations governing access to sensitive information and resources.
          2. Data Encryption: Using encryption to ensure that sensitive data remains secure.
          3. Risk Assessment: Determining the risks associated with a given system and developing strategies for mitigating those risks.
          4. Authentication: Verifying the identity of users and granting them appropriate access to the system and its data.
          5. Auditing and Monitoring: Keeping logs of system activity and monitoring those logs to detect unusual or suspicious behavior.
          6. Incident Response: Developing and implementing plans and procedures for responding to security incidents.
          7. Training and Awareness: Ensuring that users understand the security policies and their role in following them.
          • leanna
            What are the components of issue specific security policy?
            1 year ago
            1. Risk management: Identifying, assessing, and mitigating security risks related to the specific issue.
            2. Access control: Controlling the access to systems and data related to the issue.
            3. Auditing and logging: Regularly monitoring and tracking activities related to the issue.
            4. Data protection: Implementing measures to protect the confidentiality, integrity, and availability of data related to the issue.
            5. User authentication: Verifying identity and establishing trust when accessing systems and data related to the issue.
            6. Data classification: Assigning levels of sensitivity to data related to the issue and implementing appropriate procedures for handling it.
            7. Encryption: Encrypting data related to the issue to protect its confidentiality and integrity.
            8. Incident response: Defining procedures to handle incidents related to the issue.
            9. Education and training: Training users on the security policy related to the issue.
            • fre-swera
              What are the components of comprehensive security?
              1 year ago
              1. Infrastructure Protection – Securing physical facilities, networks, and systems from unauthorized access or disruption.
              2. Firewall and Network Defense – Protecting networks from malicious traffic, viruses, and other unauthorized access.
              3. Authentication and Authorization – Confirming the identity of users and allowing only authorized users access to systems.
              4. Access Control – Controlling who can access specific systems and data.
              5. Data Encryption – Protecting data in transit and at rest by converting it into a form that is indecipherable without a key.
              6. Intrusion Detection and Prevention – Detecting and blocking malicious traffic and other efforts to compromise the security of a system.
              7. Patch Management – Keeping critical systems and network infrastructure up to date with the latest security patches.
              8. Vulnerability Management – Identifying and addressing security weaknesses in systems and networks before an attack can occur.
              9. Security Auditing and Monitoring – Regularly monitoring and testing security systems to ensure their effectiveness.
              10. Disaster Recovery and Business Continuity – Ensuring the continued availability of systems and data in the event of a disaster.