XML Feeds

Search Big4Guy

Custom Search

Sponsored

« Sarbanes Oxley Internal Controls documentation - How Much is Enough?CISA Exam Test Prep Questions - Test Data for System Validation »

Sample Information Security Policy on Access Control

Sample Information Security Policy on Access Control

Recently, I was reading a some samples of information security policies. Here is one example of a information security policy on access controls.

“Security procedures must be implemented to prevent unauthorized access to computers, network resources and data. Only employees of [Company] and contractors who have been briefed on the acceptable use policy of [Company] will be given access to the network. Managers shall decide the level of access for each employee. Final permission to access the network will be the responsibility of the Security Committee. Individuals will be issued a unique username. When an employee terminates employment, Personnel will notify the Security Committee and IT, and steps will be taken to disable that user’s accounts and access to internal and external networks. Account logon and logoff information will be recorded for security audits.”

My advise to company's is to read various sample policies and then adapt them to suit your own individual requirements.

Related Posts

Developing Information Security Policies
Concept of Digital Signatures
Simple Steps for Information Asset Protection
How to Manage Application Change Control


Permalink 04/02/06 10:15:54 pm , by big4guy Email , 564 views, Information Security, Leave a comment »

Feedback awaiting moderation

This post has 17 feedbacks awaiting moderation...

Leave a comment


Your email address will not be revealed on this site.

Your URL will be displayed.
(Line breaks become <br />)
(Name, email & website)
(Allow users to contact you through a message form (your email will not be revealed.)