From the course: Writing Security Policies and Standards
Unlock the full course today
Join today to access over 24,700 courses taught by industry experts.
Common security policies and standards
From the course: Writing Security Policies and Standards
Common security policies and standards
Security policies and standards are crucial for protecting sensitive information and maintaining secure operations. Frameworks like ISO 27001, HIPAA, and PCI DSS dictate foundational security policies that every compliant organization must adopt. For instance, ISO 27001 mandates 25 specific policies, including an information security policy, a data protection policy, and an acceptable use policy. While some policies are explicitly named within the frameworks, organizations can adapt them to fit their operational environment better. For example, the clear desk and clear screen policy required by ISO 27001 might be integrated into a broader physical security policy. As long as the essential elements of mandatory policies are preserved, organizations can ensure compliance while tailoring policies to their specific needs. Here are 10 common security policies typically found in organizations striving to achieve compliance and secure operations. Information Security Policy, Data Protection…
Practice while you learn with exercise files
Download the files the instructor uses to teach the course. Follow along and learn by watching, listening and practicing.
Contents
-
-
-
What are policies, standards, procedures, and guidelines?3m 52s
-
(Locked)
Common security policies and standards2m 43s
-
(Locked)
Mapping policies to governance frameworks3m 2s
-
(Locked)
The security policy lifecycle3m 28s
-
(Locked)
Creating a security policy architecture diagram3m 32s
-
(Locked)
Challenge: Distinguish between security directives1m 54s
-
(Locked)
Solution: Distinguish between security directives2m 13s
-
-
-
-
-
-