- Acceptable Use Policy - Template policy clarifying the acceptable use of IT devices and networks. [MS Word]
- Acceptable Use Policy - Defines acceptable use of IT equipment and computing services, and the appropriate employee security measures to protect the organization's corporate resources and proprietary information. [MS Word]
- Acquisition Assessment Policy - Defines responsibilities regarding corporate acquisitions and the minimum requirements of an acquisition assessment to be completed by the information security group. [MS Word]
- Analog/ISDN Line Policy - Defines policy for analog/ISDN lines used for FAXing and data connections.
- Antivirus Policy - From the State of Vermont Agency of Administration. Mandates the use of antivirus software on applicable systems. [PDF]
- Antivirus Policy - Requirements for effective virus detection and prevention. Written for a laboratory environment but easy to adapt for other settings. [MS Word]
- Application Service Provider Policy - Security criteria for an ASP. [PDF]
- Audit Policy - Defines requirements and provides authority for the information security team to conduct IT audits and risk assessments. [PDF]
- Awareness and Training Policy - From Georgia Perimeter College. Mandates an ongoing and creative general security awareness program supplemented with more specific training where needed. [PDF]
- Backup Policy - Sample policy requires a cycle of daily and weekly backups (although monthly backups are also advisable!).
- Backup Policy - Sample policy from the University of North Carolina requires daily, weekly and monthly backups (sometimes known as 'grandfather, father, son').
- Campus Security Policy - An overarching security policy from Berkeley University includes links to more specific and detailed policies.
- Campus Security Policy - High level information security policy from Washington University.
- Communications and Operations Management Policy - One of a set of template policies for UK local councils from the West Midlands Local Government Association. [MS Word]
- Computer Telephone and Desk Use Policy - One of a set of template policies for UK local councils from the West Midlands Local Government Association. [MS Word]
- Database Password Policy - Defines requirements for securely storing and retrieving database usernames and passwords. [MS Word]
- Dial-in Access Policy - Policy regarding the use of dial-in connections to corporate networks. [MS Word]
- Disaster Recovery Policy - Basic DR policy in just over one side. [PDF]
- Disclosure And Blogging Policies - An open source document containing a suite of information security policy statements regarding employees blogging or contributing to other online media, written in the form of checklists. [MS Word]
- DMZ Security Policy - Sample policy establishing security requirements of equipment to be deployed in the corporate De-Militarized Zone. [MS Word]
- Electronic Communications Policy - Formal policy from the University of California covering email and other electronic communications mechanisms [PDF]
- Email Forwarding Policy - Email must not be forwarded automatically to an external destination without prior approval from the appropriate manager. [PDF]
- Email Policy - Policy from the University of Colorado on the use of, access to, and disclosure of electronic mail.
- Email Policy - Policy from Northern Illinois University's IT Services group. Outlines some unacceptable uses.
- Email Policy - One of a set of template policies for UK local councils from the West Midlands Local Government Association. [MS Word]
- Email Retention Policy - Sample policy to help employees determine which emails should be retained and for how long.
- Encryption Policy - Defines encryption algorithms that are suitable for use within the organization. [MS Word]
- Ethics Policy - Sample policy intended to 'establish a culture of openness, trust and integrity'.
- Ethics Policy - Ethical behavior underpins all procedural security controls. This ethics policy from Spirent is a useful model.
- Extranet Policy - Defines the requirement that third party organizations requiring access to the organization's networks must sign a third-party connection agreement. [MS Word]
- FIPS 140-2 Security Policy - Security policy for the OpenSSL FIPS software object module, required for validation against FIPS (Federal Information Processing Standard) 140-2. [PDF]
- Government Security Policy - The New Zealand Government's information security policy, based on the 2000 version of ISO/IEC 17799. [ZIP file containing PDF and MS Word versions]
- HSPD-12 Privacy Policy - Sample privacy policy from the US Government including Privacy Act systems of records notices, Privacy Act statements and a privacy impact assessment, designed to satisfy the requirements of HSPD-12 “Policy for a Common Identification Standard for Federal Employees and Contractors”.
- Human Resources Information Security Policy - One of a set of template policies for UK local councils from the West Midlands Local Government Association. [MS Word]
- Incident Response Policy - Yale University's policy regarding assessing IT security incidents, forming response teams and responding. [PDF]
- Information & Communications Technology (ICT) Security Policy - High level security policy from Dublin City University. [MS Word]
- Information Protection Policy - One of a set of template policies for UK local councils from the West Midlands Local Government Association. [MS Word]
- Information Security Incident Management Policy - One of a set of template policies for UK local councils from the West Midlands Local Government Association. [MS Word]
- Information Security Policies - Wiki developed by Holistic Operational Security Readiness Evaluation, a collaborative open project building a library of sample information security policies, supporting standards and other documents.
- Information Security Policies - An extensive collection of information security policy samples at SecurityDocs.
- Information Security Policies - 111-page security policy manual from the Australian New South Wales Department of Commerce, based on ISO/IEC 27001. [PDF]
- Information Security Policies - Policies from CSPO Tools Inc., some of which are available without charge as PDF files or for an annual subscription as MS Word files, along with additional content.
- Information Security Policies - The Information Security Toolkit from UCISA (University Colleges and Information Systems Association) contains a suite of security policy and guidance documents reflecting and cross-referenced against BS7799, intended for use in universities. [PDF documents]
- Information Security Policies - SANS consensus research project offering around 30 editable information security policies.
- Information Security Policies - NIST's collection of well over 100 security policies and related awareness materials, mostly from US Government bodies.
- Information Security Policy - An information security policy from the University of Illinois.
- Information Security Policy - High level security policy/guideline from the Department of Health and Human Resources. [PDF]
- Information Security Policy - High-level information security policy statement for the Childhood Cancer Research Group at Oxford University.
- Information Security Policy Overview - Summarises the suite of template policies provided for UK local government use by the West Midlands Local Government Association. [MS Word]
- Information Sensitivity Policy - Sample policy defining the assignment of sensitivity levels to information. [PDF]
- Internet Acceptable Use Policy - One page Acceptable Use Policy example. [PDF]
- Internet Acceptable Use Policy - One of a set of template policies for UK local councils from the West Midlands Local Government Association. [MS Word]
- Internet DMZ Equipment Policy - Sample policy defining the minimum requirement for all equipment located outside the corporate firewall. [PDF]
- IP Network Security Policy - Example security policy to demonstrate policy writing techniques introduced in three earlier articles.
- ISMS Policy - A high level (single page) policy statement from Ricoh, supporting their Information Security Management System. [PDF]
- ISO/IEC 27001 Policies - Typical headings for a security policy aligned broadly with the ISO/IEC 27002 standard for information security management systems.
- ISO27k Toolkit - Collection of information security policies, procedures etc. aligned with the ISO/IEC 27000-series standards and provided under the Creative Commons license. [PDF]
- IT Access Policy - One of a set of template policies for UK local councils from the West Midlands Local Government Association. [MS Word]
- IT Infrastructure Security Policy - One of a set of template policies for UK local councils from the West Midlands Local Government Association. [MS Word]
- IT Security Policy - IT security policy example/how-to guide from Enterprise Ireland.
- IT Security Policy - Information technology security policy at Murdoch University, complete with supporting standards and guidelines.
- Laboratory Security Policy - Policy to secure confidential information and technologies in the labs and protect production services and the rest of the organization from lab activities. [MS Word]
- Laptop Security Policy - From the National Health Service. [MS Word]
- Law Enforcement Data Security Standards - IT security policy applicable to the Victoria Police in Australia. 93 pages based on ISO/IEC 27002 and related standards. [PDF]
- Legal Responsibilities Policy - One of a set of template policies for UK local councils from the West Midlands Local Government Association. [MS Word]
- Modem Policy - Sample policy from Sandstorm, designed as an addition to an existing Remote Access Policy, if one exists, or simply to stand alone.
- Network Security Policy - Example security policy for a data network from the University of Toronto.
- Network Security Policy Guide - Watchguard's guide to creating an overarching network information security policy, supported by subsidiary policies. [PDF]
- Password Policy - Defines standards for creating, protecting and changing strong passwords. [MS Word]
- Password Policy - A password policy presented in the form of a series of security awareness posters. "Passwords are like underwear ..." [PDF]
- Password Standard - 32 page extended policy document from the New Zealand government, explains both risks and control requirements. [PDF]
- Personnel Security Policy - Example policy covering pre-employment screening, security policy training etc. [PDF]
- Privacy Policy - Generic policy for websites offering goods and services, with an important warning to seek qualified legal advice in this area.
- Privacy Policy - Concise policy (just 3 paragraphs) published by the School of Graduate Studies at Norwich University.
- Remote Access Policy - Defines standards for connecting to a corporate network from any host. [MS Word]
- Remote Working Policy - One of a set of template policies for UK local councils from the West Midlands Local Government Association. [MS Word]
- Removable Media Policy - One of a set of template policies for UK local councils from the West Midlands Local Government Association. [MS Word]
- Resource Utilization Policy - Policy template by Walt Kobus defines requirements for resilience, redundancy and fault tolerance in information systems. [PDF]
- Risk Assessment Policy - Defines requirements and authorizes the information security team to identify, assess and remediate risks to the organization's information infrastructure. [MS Word]
- Router Security Policy - Sample policy establishing the minimum security requirements for all routers and switches connecting to production networks. [MS Word]
- Security Policy Primer - General advice for those new to writing information security policies. [PDF]
- Server Security Policy - Defines standards for minimal security configuration for servers inside the organization's production network, or used in a production capacity. [PDF]
- Software Policy - One of a set of template policies for UK local councils from the West Midlands Local Government Association. [MS Word]
- Standard Practice Guide - Policy covering appropriate use of information resources and IT at the University of Michigan. [PDF]
- Telecommuting/Teleworking Policy - Sample policy on teleworking covering employment as well as information security issues.
- The ePolicy Institute - Provides policies and resources on information security and other related topics.
- Third Party Connection Agreement - Sample agreement for establishing a connection to an external party. [PDF]
- University Information Security Policies - A set of information security policies from the University of Louisville.
- University Information Security Policies - Electronic resource usage and security policies from the University of Pennsylvania.
- Virtual Private Network Policy - Defines the requirements for Remote Access IPSec or L2TP Virtual Private Network (VPN) connections to the organization's network. [PDF]
- Wireless Communication Policy - Sample policy concerning the use of unsecured wireless communications technology. [PDF]
Last update: Jul 4, 2010 07:47:14. Powered by the Open Directory Project.