RE: Building a Company Computer Use/Security Policy

From: Meidinger Chris (chris.meidinger_at_badenit.de)
Date: 01/17/05

  • Next message: Cory Foy: "Re: SOX Compliance and assesment"
    To: "Samuel S. Kempf" <samk@rjpromotions.com>, security-basics@securityfocus.com
    Date: Mon, 17 Jan 2005 19:22:11 +0100
    
    

    Hi Samuel,

    i would recommend "Writing Security Policies" from New Riders Press. Don't
    have my copy here at work, but it's good.

    The sans reading room is also excellent --> sans.org/rr

    Cheers,

    Chris

    > -----Original Message-----
    > From: Samuel S. Kempf [mailto:samk@rjpromotions.com]
    > Sent: Monday, January 17, 2005 1:33 AM
    > To: security-basics@securityfocus.com
    > Subject: Building a Company Computer Use/Security Policy
    >
    > I've recently taken over the position of I.T. Director for a
    > mid-sized company that has no IT policy of any sort currently
    > in place, aside from a vague mention in the no compete
    > agreement about not giving proprietary data to other
    > companies. One of my prime initiatives at the moment is to
    > implement such a policy, something I've never been
    > responsible for before. Can anyone point me to sites/articles
    > on how to do this? Or, better yet, does anyone know of such a
    > policy available online that I could use as a basis for my
    > company? Any suggestions are most welcome.
    >
    > Samuel S. Kempf
    >


  • Next message: Cory Foy: "Re: SOX Compliance and assesment"

    Relevant Pages

    • Re: Local Group Policy
      ... Chris S. brought next idea: ... My understanding is that for GPOs, the LSDOu precedence takes effect in an AD. I've been told that there's no need to configure the Local grp. ... The reason given to me is that the Domain or OU policy will takes effect when the client workstation or member server is connected to the AD. ... disconnecting it from the AD and after reboot - this mean that all the ...
      (microsoft.public.windows.group_policy)
    • Re: local admin can join computer to domain
      ... Hi Chris, ... Domain Users Cannot Join Workstation or Server to a Domain ... >> a) you can always disable Add Workstation do domain policy in AD ... >> c) you should have written security policy that will let users know what ...
      (microsoft.public.win2000.security)
    • RE: Running Unmanaged code LogonUser() on a UNC Path
      ... Hi Chris, ... >The assembly is actually located on a file server and not on the local ... >in the Runtime Security Policy section of .NET Framework configuration? ... >Framework Configuration" my assembly with the LogonUser API call in it ...
      (microsoft.public.dotnet.framework.aspnet.security)
    • Re: default domain controller group policy newbie question...
      ... "Chris" wrote in message ... If i want certain users to have more complex password requirements ... than other "normal" users on the domain, where within Group Policy would I ... > grab and process this policy and it applies to all domain-based accounts ...
      (microsoft.public.win2000.active_directory)
    • Re: Restricting Internet Access
      ... you create this policy. ... Chris ... > I created a GPO that only included one option set; ...
      (microsoft.public.windows.group_policy)

  • Quantcast