Defines requirements for encryption algorithms used within the organization.
Defines acceptable use of equipment and computing services, and the appropriate employee security measures to protect the organization's corporate resources and proprietary information.
Defines minimum security criteria that an ASP must execute in order to be considered for use on a project by the organization.
Outlines the minimum security standards for the ASP. This policy is referenced in the ASP Policy above.
Robert Comella
View Computer Disaster Recovery Plan (PDF) (46KB)
SANS Technology Institute White Paper Project
July 2009
Defines requirements for securely storing and retrieving database usernames and passwords.
Rick D. Smith
View End User Encryption Key Protection Policy (PDF) (92KB)
SANS Technology Institute White Paper Project
August 2009
Rick D. Smith
View End User Encryption Key Protection Poster (PDF) (207KB)
SANS Technology Institute White Paper Project
August 2009
Defines standards for creating, protecting, and changing strong passwords.
John Brozycki
View Software Installation Policy (PDF) (16KB)
SANS Technology Institute White Paper Project
November 2007
John Brozycki
View Software Installation Policy Poster PDF (868KB)
SANS Technology Institute White Paper Project
November 2007
Russell Meyer
View Workstation Security Policy (Word Doc) (52KB)
SANS Technology Institute White Paper Project
February 2008
Russell Meyer
View Workstation Security Poster (Word Doc) (1.1MB)
SANS Technology Institute White Paper Project
February 2008
Download Course
Excerpts Below
Infosec Policy Excerpt (pdf)
Infosec Policy Excerpt (pptx)