·
Policy:
->Outlines the security roles and
responsibilities.
->defines the scope of the
information need to be protected.
->provide a high level description
of control that must be in place to protect information.
->In addition it should make
preference to the standard and guidelines that support it.
->it should make preference to the
standard and guidelines that support it.
->should be produced by senior
management.
·
Standard:
->are low level mandatory controls
that helps, enforce &
support mandatory control.
·
Guidelines:
->consists of recommended non-mandatory
controls that helps supports standard and served as references when no
applicable standard is in place
·
Procedure:
->consists of step-by-step instruction to assist
worker in implementing various policy ,standard & guidelines.
No comments:
Post a Comment