| submit a site to this category |
| wectar web site suggestions for this odp category |
| Subcategories | |||
|---|---|---|---|
| Companies | HIPAA | Sample Policies | Standards |
|
|
SANS InfoSec Reading RoomURL: http://www.sans.org/rr/ ODP description: Articles on security policy and other information security topics. Page title: SANS Institute - SANS Information Security Reading Room - Security White Papers Page description: The SANS Institute, offering computer security training for system administrators, computer security professionals, and network administrators, is a cooperative research and education organization that has many consensus projects to return computer security information to the community. ![]() |
|
|
Make Your Web Site P3P CompliantURL: http://www.w3.org/P3P/details.html ODP description: How to create and publish your company's platform for privacy performance policy, a W3C initiative, in 6 steps. Page title: More information on using P3P ![]() |
|
|
IT Security CookbookURL: http://www.boran.com/security/ ODP description: A guide to computer and network security with a strong focus on writing and implementing security policy. This is primarily for security managers and system administrators. Page description: Comprehensive online book including: Computer/Network security, Internet, Risk analysis, UNIX, NT, Encryption, ITSEC ![]() |
|
|
Common Criteria Evaluation and Validation SchemeURL: http://www.niap-ccevs.org/cc-scheme/ ODP description: Provides details of this US government scheme. Page title: CCEVS Page description: NIAP CCEVS is managed by the NSA, and is focus on establishing a national program for the evaluation of information technology products for conformance to the International Common Criteria for Information Technology Security Evaluation. ![]() |
|
|
OSSTMM: Open Source Security Testing Methodology ManualURL: http://www.isecom.org/projects/osstmm.shtml ODP description: A widely used, peer-reviewed, methodology for performing security tests. ![]() |
|
|
U.S. Department of Health and Human ServicesURL: http://www.cms.hhs.gov/InformationSecurity/ ODP description: Security standards, transactions and code set standards, identifier standards, mailing lists, implementation guides, and administrative simplification. Page title: Overview ![]() |
|
|
Return on Information Security InvestmentURL: http://www.geocities.com/amz/ ODP description: Assess your company's Return on Information Security Investment Page description: Assess the return of information security inverstment of your organisation. Use the balanced scorecard to evaluate the financial and strategic aspects of your information security programme. ![]() |
|
|
How to Develop Good Security Policies and Tips on Assessment and EnforcementURL: http://www.giac.org/practical/Kerry_McConnell_GSEC.doc ODP description: [Word Document] Invest the time up front to carefully develop sound policies and then identify ways to gauge their effectiveness and assess the level of compliance within your organization. Commit to spending the time and resources required to ensure that the policies are kept current and accurately reflect your company's security posture. Page title: How to Develop Good Security Policies and Tips on Assessment and Enforcement - GIAC Certified Student Practical ![]() |
|
|
P3P Guiding PrinciplesURL: http://www.w3.org/TR/NOTE-P3P10-principles ODP description: Principles behind the W3C Platform for Privacy Preferences initiative. ![]() |
|
|
Canada's Export ControlsURL: http://www.efc.ca/pages/doc/crypto-export.html ODP description: Unofficial / unverified article describing Canada's export controls on cryptographic software. Page title: Canada's export controls ![]() |
|
|
RFC2196 (Site Security Handbook)URL: http://tools.ietf.org/html/rfc2196 ODP description: a guide to developing computer security policies and procedures for sites that have systems on the Internet. Published 1997. Page title: RFC 2196 Site Security Handbook ![]() |
|
|
Information Security PoliciesURL: http://www.neupart.com ODP description: Make and manage security policies. Run awareness programs with audits and e-learning to build a human firewall. Page title: Neupart - Information Security Management & Awareness Page description: Neupart: Information Security Management and Awareness; Solutions and Services; Based on standards. ![]() |
|
|
Understanding the Virus Threat and Developing Effective Anti-Virus PolicyURL: http://www.sans.org/rr/papers/index.php?id=135 ODP description: This paper focuses on providing the reader with an overview of the current virus landscape and aids in developing best practice anti-virus policies. Page title: SANS Institute - Understanding the Virus Threat and Developing Effective Anti-Virus Policy Page description: This paper focuses on providing the reader with an overview of the current virus landscape and aids in developing best practice anti-virus policies. After presenting the threat, we'll introduce you to today's most popular anti-virus tools. ![]() |
|
|
The Information Security ForumURL: http://www.isfsecuritystandard.com ODP description: It has produced the standard to provide guidelines on all aspects of information security including IT, data, and computer controls. Page title: The Information Security Forum - The Standard of Good Practice for Information Security. Page description: The Information Security Forum has produced the Standard to provide guidelines on all aspects of information security including, IT, Data and Computer controls. The Forum's Standard, drawn from best practices, in-depth research and national, European and International standards, helps organisations to manage risk effectively. ![]() |
|
|
SecurityDocsURL: http://www.securitydocs.com/Security_Policies ODP description: A substantial collection of papers and articles on the development and implementation of security policies. Page title: SecurityDocs: Security Policies Page description: Directory of information security articles, white papers, and documents ![]() |
|
|
SecureZoneURL: http://www.securezone.com ODP description: Information portal with focus on policies, protocols and standards Page title: SecureZone: Information Security Directory Page description: The SecureZone Directory. Information, resources, tools and more. ![]() |
|
|
IASEP Data Security ProtocolURL: http://arc.education.purdue.edu/protocol/home_page.htm ODP description: An archive website from the Purdue Research Foundation, containing a range of example security policy sets. Page title: Data Security Protocol ![]() |
|
|
A Structured Approach to Computer SecurityURL: http://citeseer.ist.psu.edu/241365.html ODP description: A security policy is a set of rules written in general terms stating what is permitted and what is not permitted in a system during normal operation. Page title: A Structured Approach to Computer Security - Olovsson (ResearchIndex) Page description: Security and dependability are two closely connected areas. Recently, some attempts have been made to integrate the two concepts by integrating security into the more general topic of dependability. This paper describes security concepts and gives a survey of security terminology. It also establishe ![]() |
|
|
GASSP Home PageURL: http://csrc.nist.gov/publications/nistpubs/800-14/800-14.pdf ODP description: Generally Accepted System Security Principles, developed by The International Information Security Foundation. ![]() |
|
|
Institute for Security and Open Methodologies (ISECOM)URL: http://www.isecom.org ODP description: Non-profit, international research initiative dedicated to defining standards in security testing and business integrity testing. Page title: ISECOM - Institute for Security and Open Methodologies ![]() |
|
| |