Skip to main content
Term Paper Master's 1,313 words

Developing information security policies for organizational networks

~7 min read 7 sections
Abstract

Even though the significance of information security for businesses is more and more recognized, the difficulty of issues involved means that the size and shape of information security policies may differ widely from company to company. This may depend on a lot of factors, including the size of the company, the sensitivity of the business information they own and deal with in their marketplace, and the numbers and types of information and computing systems they use.

✍️ How to write this paper — guide & tools
Essay 1,313 words

Computers and the Internet

Security Policies

Even though the significance of information security for businesses is more and more recognized, the difficulty of issues involved means that the size and shape of information security policies may differ widely from company to company. This may depend on a lot of factors, including the size of the company, the sensitivity of the business information they own and deal with in their marketplace, and the numbers and types of information and computing systems they use. For a large company, developing a single policy document that speaks to all types of users inside the organization and addresses all the information security issues necessary may prove impossible. "A more effective concept is to develop a suite of policy documents to cover all information security bases; these can be targeted for specific audiences, making a more efficient process for everyone" (Information Security Policy - A Development Guide for Large and Small Companies, 2007). This paper examines four different security policies that need to be considered when developing and maintaining a good overall information security policy.

Wireless Communication Policy

The purpose of this policy is to secure and protect the information assets owned by a company. Companies provide computer devices, networks, and other electronic information systems in order to meet missions, goals, and initiatives. Companies grant access to these resources as a privilege and must manage them responsibly to maintain the confidentiality, integrity, and availability of all information assets. This policy specifies the conditions that wireless infrastructure devices must satisfy to connect to the company's network. Only those wireless infrastructure devices that meet the standards specified in this policy or are granted an exception by the Information Security Department are approved for connectivity to the company's network (Wireless Communication Policy, n.d.).

Workstation Security Policy

The purpose of this policy is to provide guidance for workstation security for any company's workstations in order to make certain the security of information on the workstation and information the workstation may have access to. "Additionally, the policy provides guidance to ensure the requirements of the HIPAA Security Rule "Workstation Security" Standard 164.310(c) are met. This policy applies to all employees, contractors, workforce members, vendors and agents with a company -owned or personal-workstation connected to the company's network. Appropriate measures must be taken when using workstations to ensure the confidentiality, integrity and availability of sensitive information, including protected health information (PHI) and that access to sensitive information is restricted to authorized users" (Workstation Security Policy, n.d.).

Internet usage Policy

The Internet usage Policy applies to all Internet users or people working for the company, including permanent full-time and part-time workers, contract workers, temporary agency workers, business partners, and vendors who access the Internet through the computing or networking resources. The company's Internet users are anticipated to be familiar with and to conform to this policy, and are also required to use their general sense and exercise their good judgment while using Internet services (Internet usage Policy, n.d.).

Server Audit Policy

The purpose of this policy is to ensure all servers deployed at a company are configured according to the company's security policies. Servers deployed at the company shall be audited at least annually and as prescribed by applicable regulatory compliance. Audits may be conducted to:

Ensure integrity, confidentiality and availability of information and resources

Ensure conformance to company security policies

This policy covers all servers owned or operated by the company. This policy also covers any server present on the company's premises, but which may not be owned or operated by the company. Servers in use for the company support critical business functions and store company sensitive information. Improper configuration of servers could lead to the loss of confidentiality, availability or integrity of these systems (Server Audit Policy, n.d.).

Conclusion

A security policy is basically a plan, outlining what the company's critical assets are, and how they must and can be protected. Its chief purpose is to provide staff with a brief summary of the adequate use of any of Information Assets, as well as to clarify what is considered as permissible and what is not, therefore engaging them in securing the company's critical systems. In order to comprehend the significance of a security policy, staff needs to be conscious and completely understand the penalties of violating the policy, thus exposing critical systems to a spiteful attacker, or causing unintentional damage to other companies worldwide. Violations should be handled consequently; those who in one way or the other breach upon the security policy should be made aware that they may face being put through a trial period, which comprises the limited use of some of the company information assets until they can show they are capable to act in a secure manner while using the corporate systems. They should also be aware that in some severe cases they also may risk being fired or even prosecuted (Danchev, 2003).

Organizations must be prepared to enforce every stipulation the policy makes so policies must be focused and specific. Security administrators need to define objectives for their particular organization, based on the value of that information and the specific risks that information faces (van der Walt, 2010). The aforementioned policies do just this. They are all concerned with the risks that are involved both internally and externally for any company. Companies let entities both internally and externally access company information and so there is a need to have security policies in place in order to minimize any risk that might be present.

247 Words Hidden
Discussion247 words
In today's high-tech and interconnected world, every corporation needs a well developed security policy. Threats exist from both within the walls of each company as…
Cite This Paper
PaperDue. (2012). Developing information security policies for organizational networks. PaperDue. https://www.paperdue.com/essay/computers-and-the-internet-security-68446

Always verify citation format against your institution’s current style guide requirements.