According to RFC 2196, “Site Security Handbook:”A security policy is a formal statement of the rules by which people who are givenaccess to an organization’s technology and information assets must abide.A security policy informs users, managers, and technical staff of their obligations for protectingtechnology and information assets. The policy should specify the mechanisms bywhich these obligations can be met. As was the case with the security plan, the securitypolicy should have buy-in from employees, managers, executives, and technical personnel.Developing a security policy is the job of senior management, with help from securityand network administrators. The administrators get input from managers, users, networkdesigners and engineers, and possibly legal counsel. As a network designer, you shouldwork closely with the security administrators to understand how policies might affect thenetwork design.
đang được dịch, vui lòng đợi..
