|
Database Password Policy
Defines requirements for securely storing and retrieving database usernames and passwords.
http://www.sans.org/newlook/resources/poli...
Company Email Policy
A menu of clauses suitable for email acceptable use policies.
http://www.cli.org/emailpolicy/top.html
Server Security Policy
Defines standards for minimal security configuration for servers inside the organization's production network, or used in a production capacity.
http://www.sans.org/newlook/resources/poli...
Introduction to Security Policies, Part Four: A Sample Policy
Examples of security policies to demonstrate writing styles.
http://www.securityfocus.com/infocus/1497
DMZ Lab Security Policy
Sample policy establishing the minimum security requirements of any equipment to be deployed in the corporate De-Militarized Zone.
http://www.sans.org/newlook/resources/poli...
Anti-Virus Guidelines
Defines guidelines for effectively reducing the threat of computer viruses on the organization's network.
http://www.sans.org/resources/policies/Ant...
Sample Policies
Handy collection of information security policy samples.
http://www.attackprevention.com/Policies_a...
IT Security
Information technology security policy at Murdoch University, complete wth supporting standards and guidelines.
http://www.murdoch.edu.au/admin/policies/i...
Information Sensitivity Policy
Sample policy defining the assignment of sensitivity levels to information.
http://www.sans.org/newlook/resources/poli...
Sample ISO 27001 Policies
A policy template consisting of headings aligned with the new ISO standard for information security management.
http://www.27001-online.com/secpols.htm
Enterprise Ireland How To Guides
A combined security policy and security procedures example document.
http://www.enterprise-ireland.com/ebusines...
ePolicy Institute
Policies on information security and other topics.
http://www.epolicyinstitute.com
Sandstorm Modem Policy
This policy is designed to be an addition to an existing Remote Access Policy, if one exists, or to simply stand alone.
http://www.sandstorm.net/products/phoneswe...
Application Service Provider Standards
Sample set of minimum security standards that an application service provider must meet to be considered for use by a corporation.
http://www.sans.org/newlook/resources/poli...
Computing Policies
The electronic resource usage and security policy for the University of Pennsylvania.
http://www.upenn.edu/computing/policy/
University of Colorado Email Policy
This administrative policy statement sets forth the University's policy with regard to use of, access to, and disclosure of electronic mail to assist in ensuring that the University's resources serve those purposes.
http://www.cusys.edu/~policies/General/ema...
Application Service Provider Policy
Defines minimum security criteria that an ASP must fulfil in order to be considered for use on a project by the organization.
http://www.sans.org/newlook/resources/poli...
Virtual Private Network Policy
Defines the requirements for Remote Access IPSec or L2TP Virtual Private Network (VPN) connections to the organization's network.
http://www.sans.org/newlook/resources/poli...
NIST
Extensive collection of well over 100 security policies and related awareness materials, mostly from US Government bodies.
http://csrc.nist.gov/fasp/jump.html
Automatically Forwarded Email Policy
Documents the requirement that no email will be automatically forwarded to an external destination without prior approval from the appropriate manager or director.
http://www.sans.org/newlook/resources/poli...
Third Party Connection Agreement
Sample agreement for establishing a connection to an external party.
http://www.sans.org/newlook/resources/poli...
Internet DMZ Equipment Policy
Sample policy defining the minimum requirement for all equipment located outside the corporate firewall.
http://www.sans.org/newlook/resources/poli...
Wireless Communication Policy
Sample policy concerning the use of unsecured wireless communications technology.
http://www.sans.org/newlook/resources/poli...
Audit Policy
Defines the requirements and provides the authority for the information security team to conduct audits and risk assessments.
http://www.sans.org/newlook/resources/poli...
Telecommuting/Teleworking Sample Policy
Sample policy on teleworking covering employment as well as information security issues.
http://www.womans-work.com/teleworking_pol...
Password Protection Policy
Defines standards for creating, protecting and changing strong passwords.
http://www.sans.org/newlook/resources/poli...
K-20 Network Acceptable Use Policy
Policy on acceptable use of a school network, along with information for parents and an informed consent form.
http://www.k12.wa.us/K-20/AUPSchBoardNetwo...
University of Auckland Information Security Management Policies
Set of acceptable use and technical policies covering common information security issues.
http://www.auckland.ac.nz/security/Policie...
Information Security Policy
An information security policy from the University of Illinois.
http://www.obfs.uillinois.edu/manual/centr...
SANS Security Policy Project
A consensus research project supporting rapid development and implementation of information security policies.
http://www.sans.org/resources/policies/
Total Enterprise Security Solutions LLC
Templates for information security policies, guidelines, checklists and procedures, including PDF samples of several common policies.
http://www.tess-llc.com/TESS-DOR-EXAMPLES....
Dial-in Access Policy
Sample policy controlling the use of dial-in connection to corporate networks.
http://www.sans.org/newlook/resources/poli...
|