Policy Manual

From: Chris Berry (compjma@hotmail.com)
Date: 02/26/03

  • Next message: SMiller@unimin.com: "RE: e-mail policies"
    From: "Chris Berry" <compjma@hotmail.com>
    To: oclug@oclug.org, security-basics@securityfocus.com, windows2000@freelists.org
    Date: Wed, 26 Feb 2003 10:30:28 -0800
    
    

    Prior to my taking over here the previous admin had not bothered to write
    any policy. To try and increase professionalism and to get up to speed with
    HIPPA compliance I'm putting together a policy and proceedures manual. Here
    is a list of some of the documents I'm going to put together:

    Criticality Analysis
    Backup Plan
    Disaster Recovery Plan
    Emergency Plan
    Testing & Revision Procedures
    Access Authorization Policy (technical)
    Access Control Policy (technical)
    Access Modification Policy (technical)
    System Activity Records
    Compliance Certification
    Supervision Policy
    Temporary Authorization Records
    Permanent Authorization Records
    Clearance Policy
    Security Policy
    Security Training Records
    Security Training Outline
    Hardware Installation and Upgrade Policy
    Software Installation and Upgrade Policy
    Hardware Maintenance Policy
    Software Update Policy
    Security Testing Policy
    Periodic Review Policy
    Computer Hardware Inventory
    Computer Software Inventory
    Virus Checking Policy
    Security Response Plan
    Security Incident Report
    Security Response Plan
    Risk Management Plan
    Risk Analysis
    HIPPA Sanction Policy
    Information Security Responsibility Outline
    Physical Security Plan
    Employee Termination Policy
    Natural Hazards Defense Plan
    Security Responsibilities Outline
    Identity Security Policy
    Data Segregation Plan

    There will probably be quite a few more by the time I'm done. I'd like to
    ask if anyone has any documentation that they would be willing to share. In
    return, I'll happily provide the finished manual to anyone that would like a
    copy.

    Chris Berry
    compjma@hotmail.com
    Systems Administrator
    JM Associates

    "Linux and I have a love/hate relationship. I hate its complexity until I
    figure out how something works, then I love its power."

    _________________________________________________________________
    The new MSN 8: smart spam protection and 2 months FREE*
    http://join.msn.com/?page=features/junkmail



    Relevant Pages

    • Fwd: Oh Dear, Where to start?!
      ... It seems to me you need two things: an organizational policy, ... finish college and break into the real world of computer security. ... experience in the field of network security and policy ... updates, driver updates, and recommended updates. ...
      (Security-Basics)
    • RE: [fw-wiz] PIX vs Checkpoint vs Sonicwall vs Netscreen - comme nts?
      ... All NetScreen appliances rely on custom-designed ASICs (Application ... Specific Integrated Circuits) for security policy enforcement. ... supports a finite number of "rules" or "policies". ...
      (Firewall-Wizards)
    • RE: Cant set Local Security policies. They fail to save
      ... predefined Security Template on SBS 2003 to restore security groups ... run "gpupdate.exe /force" under command prompt to force the policy ... reboot the Server to test. ... and then logon to client computer to test if user can save system logs. ...
      (microsoft.public.windows.server.sbs)
    • RE: [fw-wiz] PIX vs Checkpoint vs Sonicwall vs Netscreen - comme nts?
      ... The report you cite is CheckPoint originated and deals with older NetScreen ... All NetScreen appliances rely on custom-designed ASICs (Application ... Specific Integrated Circuits) for security policy enforcement. ...
      (Firewall-Wizards)
    • Re: No Shut Down or Restart for Domain Admins
      ... run rsop.msc from your DC and check which policy is responsible to this. ... I have created a group policy in a development network and imported it ... NT AUTHORITY\Authenticated Users Read (from Security Filtering) No ... Enforce user logon restrictions Enabled ...
      (microsoft.public.windows.server.active_directory)