<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xml:base="http://www.securityprocedure.com" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
 <title>Policies</title>
 <link>http://www.securityprocedure.com/tag/policies</link>
 <description>The taxonomy view with a depth of 0.</description>
 <language>en</language>
<item>
 <title>Download Free Policy &amp; Procedure Manager 4.5 for Regulatory Compliance Standards</title>
 <link>http://www.securityprocedure.com/download-free-policy-procedure-manager-45-regulatory-compliance-standards</link>
 <description>&lt;p&gt;&lt;b&gt;The web-based Policy &amp;amp; Procedure Manager&lt;/b&gt; provides your staff with instant access to your organization&#039;s policies and procedures. It notifies those who are required to read specific documents and tracks who has read them. You can use the software to create, review, approve, and archive all of your documents, not just policies and procedures. Email reminders and reports ensure that everything stays up to date. You can also organize documents according to any regulatory compliance standards - such as Sarbanes Oxley, ISO 9000, JCAHO, HIPAA, state guidelines.&lt;/p&gt;
&lt;p&gt;Size: 29.57MB&lt;br /&gt;
License: Free to try&lt;br /&gt;
Requirements: Windows 95/98/Me/NT/2000/XP&lt;br /&gt;
Limitations: 30-day trial&lt;br /&gt;
Date Added: February 19, 2008 &lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.download.com/Policy-Procedure-Manager/3000-2076_4-10154760.html?hhTest=1&amp;amp;tag=lst-6&amp;amp;cdlPid=10794949	&quot;&gt;Download Page&lt;/a&gt;&lt;/p&gt;
</description>
 <comments>http://www.securityprocedure.com/download-free-policy-procedure-manager-45-regulatory-compliance-standards#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/audit">Audit</category>
 <category domain="http://www.securityprocedure.com/tag/download">Download</category>
 <category domain="http://www.securityprocedure.com/tag/policies">Policies</category>
 <category domain="http://www.securityprocedure.com/tag/procedures">Procedures</category>
 <pubDate>Fri, 11 Jul 2008 05:32:45 -0500</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">227 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>Four Types of Security Policies</title>
 <link>http://www.securityprocedure.com/four-types-security-policies</link>
 <description>&lt;ul&gt;
&lt;li&gt;Military security policy (also called a governmental security policy) is a security policy developed primarily to provide confidentiality.&lt;/li&gt;
&lt;li&gt;Commercial security policy is a security policy developed primarily to provide integrity.&lt;/li&gt;
&lt;li&gt;Confidentiality policy is a security policy dealing only with confidentiality.&lt;/li&gt;
&lt;li&gt;Integrity policy is a security policy dealing only with integrity.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;
&lt;b&gt;A military security policy&lt;/b&gt; (also called a governmental security policy) is a security policy developed primarily to provide confidentiality.&lt;/p&gt;
&lt;p&gt;The name comes from the military&#039;s need to keep information, such as the date that a troop ship will sail, secret. Although integrity and availability are important, organizations using this class of policies can overcome the loss of eitherfor example, by using orders not sent through a computer network. But the compromise of confidentiality would be catastrophic, because an opponent would be able to plan countermeasures (and the organization may not know of the compromise).&lt;/p&gt;
&lt;p&gt;Confidentiality is one of the factors of privacy, an issue recognized in the laws of many government entities (such as the Privacy Act of the United States and similar legislation in Sweden). Aside from constraining what information a government entity can legally obtain from individuals, such acts place constraints on the disclosure and use of that information. Unauthorized disclosure can result in penalties that include jail or fines; also, such disclosure undermines the authority and respect that individuals have for the government and inhibits them from disclosing that type of information to the agencies so compromised.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/four-types-security-policies&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/four-types-security-policies#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/policies">Policies</category>
 <category domain="http://www.securityprocedure.com/tag/security">Security</category>
 <pubDate>Thu, 10 Jul 2008 02:42:24 -0500</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">216 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>The truth about IT security policy</title>
 <link>http://www.securityprocedure.com/truth-about-it-security-policy</link>
 <description>&lt;p&gt;&amp;quot;&amp;hellip;IT security policy for IT auditor day to day perspective..&amp;quot;&lt;/p&gt;
&lt;p&gt;I&#039;ve been working for the IT security policy and procedures making for the last four years. And my main responsibility for that period is doing consulting services for the company who need to comply with some kind of security standard such as Sarbanes Oxley, ISO 27001 or event just some guidelines from our government.&lt;/p&gt;
&lt;p&gt;Security policy and procedures are my main deliverables. So if you see my client you will see that in their office, there are a lot of policy and procedures that created by many prestigious company, my company is also contributed there. They took international standard such as COBIT or ITIL to ensure that the company confidential data is keep secure&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/truth-about-it-security-policy&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/truth-about-it-security-policy#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/policies">Policies</category>
 <category domain="http://www.securityprocedure.com/tag/procedures">Procedures</category>
 <category domain="http://www.securityprocedure.com/tag/security">Security</category>
 <pubDate>Thu, 26 Jun 2008 02:58:48 -0500</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">175 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>Well writen policy using 5Ws of Journalism</title>
 <link>http://www.securityprocedure.com/well-writen-policy-using-5ws-journalism</link>
 <description>&lt;p&gt;The written policy should clear up confusion, not generate new problems. When preparing a document for a specific audience, remember that the writer will not have the luxury to sit down with each reader and explain what each item means and how it impacts the user&#039;s daily assignments. Know the audience for whom the policies are being developed. Remember the reading and comprehension level of the average employee. When writing the policy, remember the &quot;5 Ws of Journalism 101&quot;:&lt;/p&gt;
&lt;p&gt;What: what is to be protected (the topic)&lt;br /&gt;
Who: who is responsible (responsibilities)&lt;br /&gt;
Where: where within the organization does the policy reach (scope)&lt;br /&gt;
How: how compliance will be monitored (compliance)&lt;br /&gt;
When: when does the policy take effect&lt;br /&gt;
Why: why the policy was developed&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/well-writen-policy-using-5ws-journalism&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/well-writen-policy-using-5ws-journalism#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/audit">Audit</category>
 <category domain="http://www.securityprocedure.com/tag/policies">Policies</category>
 <category domain="http://www.securityprocedure.com/tag/procedures">Procedures</category>
 <pubDate>Thu, 22 May 2008 14:15:00 -0500</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">141 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>What is the first priority in IT audit?</title>
 <link>http://www.securityprocedure.com/what-first-priority-it-audit</link>
 <description>&lt;p&gt;If you’re the first person responsible for performing information system audit in your company, then what is your first priority? Repairing the IT process in your company? Prepare risk control matrices or just recruit another experience IS auditor for brainstorming with you?&lt;/p&gt;
&lt;p&gt;In my experience, all start from planning first. Yes IT planning plays the significant role at this stage. Remember that auditing mean a lot of interaction with a lot of departments and function across the company. So coordination is the first issue to be noted.&lt;/p&gt;
&lt;p&gt;Have you ever be in this situation?&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/what-first-priority-it-audit&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/what-first-priority-it-audit#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/audit">Audit</category>
 <category domain="http://www.securityprocedure.com/tag/policies">Policies</category>
 <category domain="http://www.securityprocedure.com/tag/procedures">Procedures</category>
 <pubDate>Mon, 19 May 2008 16:33:45 -0500</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">138 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>Effective information security programs are well-written policy statements</title>
 <link>http://www.securityprocedure.com/effective-information-security-programs-are-well-written-policy-statements</link>
 <description>&lt;p&gt;The cornerstones of effective information security programs are well-written policy statements. This is the wellspring of all other directives, standards, procedures, guidelines, and other supporting documents. As with any assessment process, it is important to ensure that policies establish the direction management wants to go with regard to security&lt;/p&gt;
&lt;p&gt;When reviewing policies, Thomas R. Peltier in his book about Managing a Network Vulnerability Assessment said that it will be necessary to remember that there are three general types of policies:&lt;/p&gt;
&lt;p&gt;&lt;b&gt;General or global policies.&lt;/b&gt;&lt;br /&gt;
These are high-level policy statements that define the intent of a specific topic and its scope within the organization. It also assigns responsibilities for implementation and compliance with the policy. Typical information security general or global policies include:&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/effective-information-security-programs-are-well-written-policy-statements&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/effective-information-security-programs-are-well-written-policy-statements#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/audit">Audit</category>
 <category domain="http://www.securityprocedure.com/tag/policies">Policies</category>
 <category domain="http://www.securityprocedure.com/tag/procedures">Procedures</category>
 <category domain="http://www.securityprocedure.com/tag/security">Security</category>
 <pubDate>Thu, 17 Apr 2008 19:59:53 -0500</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">119 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>How to design audit log policy</title>
 <link>http://www.securityprocedure.com/how-design-audit-log-policy</link>
 <description>&lt;p&gt;Enabling audit log is an issue -as we discussed before. But leave it to management how to decide this feature, because whatever the decision we still need to making audit log policy to ensure the activities become effective.&lt;/p&gt;
&lt;p&gt;Here is some topics that should be put clear in audit log policy&lt;/p&gt;
&lt;h3&gt;1. Event logging&lt;/h3&gt;
&lt;p&gt;What kind of activity that should be logged. All administrator activities or only sensitive activity for several users. Other approach such as based on hour log -the audit log will be enabled only in working hours. Auditor should clearly state which event that should be logged.&lt;/p&gt;
&lt;h3&gt;2. Log recording and archiving&lt;/h3&gt;
&lt;p&gt;Archiving log to write once disk, archiving to tape storage or just put in hard disk is also a must stated in log policy. How long any security breaches will be archived.&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/how-design-audit-log-policy&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/how-design-audit-log-policy#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/policies">Policies</category>
 <category domain="http://www.securityprocedure.com/tag/system-log">System Log</category>
 <pubDate>Sun, 09 Mar 2008 01:07:42 -0600</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">65 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>How to design social networking website policy</title>
 <link>http://www.securityprocedure.com/how-design-social-networking-website-policy</link>
 <description>&lt;p&gt;The latest update of Linkedin.com one of the most popular social networking site for professional, is proven evidence that the social network is become very important in our life. The function is shift, not only as communication media but its also become place to find new career, develop larger network to corporate research.&lt;/p&gt;
&lt;p&gt; However the massive usage of social network website also becomes another challenge for industry to create good enterprise policy for this matter. Any other idea, how to develop social networking website policy?&lt;/p&gt;
&lt;p&gt; Read also:&lt;br /&gt;&lt;a href=&quot;http://searchsecurity.techtarget.com/tip/0,289483,sid14_gci1299375,00.html&quot;&gt;Social networking threats manageable with good enterprise policy&lt;/a&gt;.&lt;br /&gt;&lt;a href=&quot;http://www.news.com/8301-13577_3-9881459-36.html&quot;&gt;LinkedIn&#039;s latest updates take a few hints from Facebook&lt;br /&gt;&lt;/a&gt;&lt;br /&gt; &amp;nbsp;&lt;/p&gt;
</description>
 <comments>http://www.securityprocedure.com/how-design-social-networking-website-policy#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/news">News</category>
 <category domain="http://www.securityprocedure.com/tag/policies">Policies</category>
 <category domain="http://www.securityprocedure.com/tag/procedures">Procedures</category>
 <pubDate>Sun, 02 Mar 2008 22:22:44 -0600</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">48 at http://www.securityprocedure.com</guid>
</item>
<item>
 <title>Do you agree with this corporate blogging policy?</title>
 <link>http://www.securityprocedure.com/do-you-agree-corporate-blogging-policy</link>
 <description>&lt;p&gt;This policy provides guidance to ensure that company use of blogging and online dialogue appropriately considers the responsible engagement in this new, rapidly growing space of relationship, learning and collaboration.  &lt;/p&gt;
&lt;p&gt;1. Knowing and following Company Code of Conduct&lt;br /&gt;
2. Blogs are not corporate communications but are individual interactions. Identify yourself but ensure to protect your privacy,&lt;br /&gt;
3. Use a disclaimer when posting a blog that has something to do with work or subjects associated with Company.&lt;br /&gt;
4. Respect copyright, fair use and financial disclosure laws.&lt;br /&gt;
5. Don&#039;t provide confidential or other proprietary information.&lt;br /&gt;
6. Don&#039;t cite or reference clients, partners or suppliers without their approval.&lt;br /&gt;
7. Respect your audience and show proper consideration for others&#039; privacy on topics that can be inflammatory such as politics and religion.&lt;br /&gt;
8. Find out who else is blogging on the topic and cite them. &lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;http://www.securityprocedure.com/do-you-agree-corporate-blogging-policy&quot;&gt;read more&lt;/a&gt;&lt;/p&gt;</description>
 <comments>http://www.securityprocedure.com/do-you-agree-corporate-blogging-policy#comments</comments>
 <category domain="http://www.securityprocedure.com/tag/policies">Policies</category>
 <category domain="http://www.securityprocedure.com/tag/procedures">Procedures</category>
 <category domain="http://www.securityprocedure.com/tag/standard">Standard</category>
 <pubDate>Sun, 02 Mar 2008 21:48:28 -0600</pubDate>
 <dc:creator>root</dc:creator>
 <guid isPermaLink="false">46 at http://www.securityprocedure.com</guid>
</item>
</channel>
</rss>
