Security Policy Paper
Temporary Grading Comments Page
We need formal writing, but not APA layout and format. You will need a minimum of two new sources each time you submit a new chapter. You will need to cite and reference all paraphrased and quoted material using APA 6th ed. standards – 5th ed. is not acceptable.
Some titles give guidance regarding the anticipated length of quality content. Please remove this detail as you progress through the document.
You will submit this file with the new content due for the first week.
I will add grading comments and return it to you.
You will make corrections in your copy for the NEXT deadline and add you new content.
[You would *not* return a document that has any comments]
We will repeat this cycle to the end of the Capstone Project.
Complete all improvements by the next deadline to recover points. A lack of improvements will mean no point recovery and imply future penalties (.
Security Operational Policies for (insert company)
Your name
St. Petersburg College
Date
Table of Contents
1I. Executive Summary
II. Policy Objectives 2
A. Firm Overview 2
B. Statement of Purpose 3
C. Policy Statement 3
D. Policy Audience 3
E. Policy Exceptions 4
F. Disciplinary Actions 4
G. Statement of Authority 4
III. Asset Classification Policies and Procedures 5
A. Information Classification/Sensitivity Levels 5
B. System Impact Levels 5
C. Information Systems Inventory and Criticality Ratings 6
IV. Personnel Policies and Procedures 9
A. Recruitment 9
B. Background Checks/Screening 9
C. Employment Agreements 10
D. Training 10
E. Acceptable Use/Prohibited Use Policy 10
F. E-mail Use Policy 10
V. Physical and Environmental Security Policies and Procedures 12
A. Physical Entry Controls Policy 12
B. Securing Offices, Rooms, and Facilities Policy 12
C. Working in Secure Areas Policy 12
D. Equipment Location and Protection Policy 13
E. Power Supply Policy 13
F. Secure Disposal and Reuse of Equipment Policy 13
G. Clear Desk and Clear Screen Policy 13
H. Removal of Property Policy 14
VI. Communications and Operations Management Policies and Procedures 15
A. Standard Operating Procedures Documentation Policy 15
B. Incident Response Program Policy 15
C. Malicious Software Policy 16
D. Information System Backup Policy 16
E. Management of Portable Storage Devices and Removable Media Policy 17
F. Security of Media in Transit Policy 17
G. Publicly Available Systems Policy 17
H. E-mail and E-mail Systems Policy 17
VII. Access Control Policies and Procedures 19
A. User Access Management Policy 19
B. Password Use Policy. 19
C. User Authentication for Remote Connections Policy 19
D. Mobile Computing Policy 20
E. Telecommuting Policy 20
F. Monitoring System Access and Use Policy 20
VIII. Systems Development and Maintenance Policies and Procedures 22
A. Security in Application Systems Policy 22
B. Cryptographic Controls Policy 23
C. Security of System Files, Development, and Support Processes Policy 23
IX. Disaster Recovery and Business Continuity Policies and Procedures 24
A. Business Continuity Assessment Policy 24
B. Business Continuity Plan Policy 24
C. Business Continuity Team Policy 25
D. Major Systems Recovery Policy 26
E. Business Continuity Plan Testing and Maintenance Policy 26
X. Regulatory Policies and Procedures 28
A. Common Threat Policy 28
B. Regulatory Review Policy 28
XI. Reference List 30
XII. Appendix 31
I. Executive Summary
This should be no longer than 1 page. Explain the fundamentals of this plan: What is your company (high level perspective)? Why is this plan important? Summarize the major sections that will be important. Mention what happens next (goes to all employees [and others?]. Then ADD a VALUE STATEMENT with rough $ values.
II. Policy Objectives
This paragraph will be an introduction to this section and what major points you will be discussing, such as: firm overview, statement of purpose, etc. Let the reader know what to expect in this section.
PLEASE NOTE: many of the subsections here and in the other sections are conducive to a format where there is an introduction paragraph followed by several bullet points that actually contain the specific policies (conducive but not mandatory). The introduction paragraph gives an overview on the bullets and may also contain some outside research or citations. The bullets should all be short snippets (usually no more than 1 sentence in length). Also, if you find something missing from this document that is relevant to your firm – feel free to add another subsection into the appropriate chapter.
A. Firm Overview [1 page]
These paragraphs give an overview of your firm. It is important to briefly describe your business, the products or services it provides, size, number of personnel. Explain why security is important, as this will impact the types of policies you create later in this document. For example, a large online bank will have many more security needs and policies (especially regulatory) compared to a small mom-and-pop grocery chain. If possible, it is highly recommended that you choose a firm you have worked for or are currently working for, as you will have a better understanding of a “real-life” environment.
B. Statement of Purpose [1-2 pages]
Include 2-3 sentences that explain the reasons for this policy’s existence. Define the “why” and “how”. This would explain C-I-A for this organization.
C. Policy Statement [2/3 page]
Two to four bullet points which give the purpose of this policy and how it will be implemented. Some things that might be covered include signing confidentiality agreements, how employees access the policy, compliance with laws and regulations, protection of assets, etc.
It is the policy of XYZ company to:
· To protect…. Etc.
· To… etc
D. Policy Audience [1/2 page]
Two to three sentences that explains who the policy is intended for. Some policies are only intended for specific employees. Other policies are intended for the entire firm or anyone (such as vendors) with access to company assets; it will depend upon your type of firm and level of protection needed. For example, if you are doing this project for your Capstone project and using a specific department in your firm as the basis of the policy, the audience would only be the stakeholders in that specific department.
E. Policy Exceptions [1/3 to 2 pages]
Review any policy exceptions. If this is not applicable to your situation, please just indicate “Not applicable”.
F. Disciplinary Actions [1/3 to 2 pages]
One to two sentences that explain the actions that may happen if a person does not follow the rules.
G. Statement of Authority [1/3 page]
One paragraph that states the authority who issued this document.
III. Asset Classification Policies and Procedures
This paragraph will be an introduction to this section and what major points you will be discussing, such as: information classification levels, system impact, etc. Again remember that most subsections may be conducive to an introduction paragraph along with specific bullets on each policy.
H. Information Classification/Sensitivity Levels [2/3 page + ]
This paragraph(s) describes the classification levels for your firm. For example, if your firm works in the defense industry, you would apply the D.O.D. levels such as “secret”, “classified”, etc. A university has records that fall under FERPA laws, so they may want classification levels of “public data”, “sensitive data”, “restricted data” (see http://rusecure.rutgers.edu/draft-policies-and-standards/draft-information-security-classification-policy/ for an example of a university or http://www.obfs.uillinois.edu/manual/central_p/sec19-5.html of examples of other firms). The SANS Institute also has some examples at http://www.sans.org/resources/policies/ . You MUST include outside research and at least one citation and reference (in the reference section below) for this paragraph.
I. System Impact Levels [1 page]
Three paragraphs that describe the system impact levels, information protection levels and criticality ratings. System impacts refers to how important the asset is to the firm (usually “high”, “medium” and “low”). However, some firms may decide they need a greater number of levels. Information protection levels refer to how to safeguard the confidentiality, integrity and availability of the information. A good place to start the research for this is to do a google search of “FIPS 199”. The final paragraph will be a discussion of how you divide the criticality rating for the asset in order to prioritize and allocate your security resources.
J. Information Systems Inventory and Criticality Ratings [1.5 pages or more]
This section will contain at least 5 paragraphs. The first will refer directly to the table (see you APA manual on how to correctly label tables and refer to them in the text) and explain the function of the table, columns and rows. For example, explain that the system impact column is ranking at the low end of a 1, with a 5 being the most critical.
The next paragraphs will offer an in-depth description of each of the tiers. Explain your reasoning for choosing the ranking for each of your systems. For example, if SPC has installed Peoplesoft, running the student administration module is critical to the specific success of an education institution. The system impact of this system is a “5” (which is vital to the successful running of the firm). Because of confidential student information such as grades and social security numbers, as well as FERPA laws, information protection of this data is of vital criticality, thus a ranking of a 5 of information protection, and the highest criticality rating of a 10.
NOTE: Students in the Information Policy class must have at least 1 system for each tier. Students in Capstone must have at least 3 systems for each tier unless alternate permission obtained from your instructor. You can obviously have a greater number if needed.
For Capstone – you must have AT LEAST 2 systems for each tier (although based on your firms needs – you might have more). For the Policy Class, you must have at least ONE system under each tier.
Table 1: Inventory and Criticality Ratings
|
Information System |
Description |
System Impact (1 – 5) |
Information Protection (1- 5) |
Criticality Rating (1 – 10) |
|
Tier 1 Critical Systems |
|
|
|
|
|
PeopleSoft SR |
Peoplesoft Student Registration System |
5 |
5 |
10 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Tier 2 High Priority Systems |
|
|
|
|
|
PBX |
Telephone System |
5 |
3.5 |
8.5 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Tier 3 Medium Priority Systems |
|
|
|
|
|
Peoplesoft PR |
Peoplesoft Payroll System |
3 |
4 |
5 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Tier 4 Low Priority Systems |
|
|
|
|
|
Peoplesoft RC |
Peoplesoft Recruitment |
1 |
3 |
1 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
IV. Personnel Policies and Procedures
This paragraph will be an introduction to this section and what major points you will be discussing, such as recruitment, background checks, etc. Review the topic at a high level and let the reader know what to expect in this section.
K. Recruitment [1/2 page or more]
Indicate what recruiting policies your firm adheres to. For example, when interviewing at the National Security Agency (NSA), candidates must be given a specific badge and accompanied by NSA employees outside the HR area. Or, your firm may have a policy that no sensitive or technical related information be included in job postings because of the ability of hackers to derive your architecture from posted technical information.
L. Background Checks/Screening [more than ½ a page]
Does your firm perform any background checks or screening? Which sort of checks/screens does it perform and are there different checks for different levels of employees? Some kinds of checks are: employment verification, licenses, credit history, criminal history, polygraph, references, etc. Some industries may legally require some checks (such as schools doing fingerprint checks). For this section, you MUST include at least one outside research, citation and reference regarding either the various checks and/or if your firm is legally required to perform some check.
M. Employment Agreements [More than ½ a page]
Does your firm require employees to sign a confidentiality agreement or security affirmation agreement? What are the major components of this agreement (bullet points are fine)? How often does the employee have to sign the agreement (yearly, or just when they are hired)? Also, some forms of employment agreements (such as non-competes) may be illegal in some states, so indicate this if applicable.
N. Training [1 page +]
Explain the firm’s training and education on security policies. How often and what sort of training is provided? This includes not only initial security overview training, but also any incident awareness and reporting training. For example, help desk employees may be required to take a special class in “social engineering” attacks.
O. Acceptable Use/Prohibited Use Policy [1/2 page +]
These paragraphs will describe acceptable and non-acceptable usage of firm’s computers and Internet usage. You may divide this into the two major sections and list bullets of each. A good place to start your research here is with SANS Institute at http://www.sans.org/resources/policies/ .
P. E-mail Use Policy [1/2 page +]
Review expected behavior with the use of email. SANS has some samples to start your research under “E-mail Policy” Section at http://www.sans.org/resources/policies/ . Remember that this is for individual usage, corporate-wide system e-mail policy will be reviewed in another section.
V. Physical and Environmental Security Policies and Procedures
This paragraph will be an introduction to this section and what major points you will be discussing, such as securing offices/rooms, equipment sitting, power supply, etc. Review the topic at a high level and let the reader know what to expect in this section.
If any of the sections below will not be applicable to your firm, simply indicate that the section is not applicable and give a short statement why it is not.
Q. Physical Entry Controls Policy
These paragraphs discuss access controls to your facility. For example, you may require all visitors sign a log located in the reception area, or all employees wear ID badges that allow access to specific areas of the building.
R. Securing Offices, Rooms, and Facilities Policy
These paragraphs discuss the physical protection (not access) of the facility. For example, a bank may decide to have intrusion detection alarms on all doors, windows and the main vault, along with security cameras in specific areas.
S. Working in Secure Areas Policy
If your firm has “secure” areas (such as the CIA or NSA), you may need a policy that ensures protection of assets in these designated areas. For example, the NSA requires all guests be accompanied by an employee when visiting “secure” areas of the facility.
Consider *all* sensitive information and data locations. [Typicaly over ½ a page]
T. Equipment Location and Protection Policy
These paragraphs discuss how the firm will secure physical assets from potential environmental hazards. For example, in the event of a potential hurricane or flooding, all personal computers should be encased in plastic and raised off the floor.
U. Power Supply Policy
These paragraphs discuss how the firm prevents power loss or damage to its equipment. Discuss the use of UPS, back-up generators, routine maintenance, etc.
V. Secure Disposal and Reuse of Equipment Policy
These paragraphs discuss how you dispose of physical assets that contain data and information to prevent unauthorized access to that data. For example, forensics experts can often retrieve data from computers that have not thorough data wiping. If you want to reuse a computer, even overwriting the data does not guarantee the original data removal. For this section, you MUST include at least one outside research, citation and reference regarding wiping your computers/data.
Also, discuss the physical disposal of your equipment. Many dumps no longer accept computers. A good place to start research for this section is Montana’s Disposal of Computers Policy at http://itsd.mt.gov/policy/policies/entsec141.asp .
W. Clear Desk and Clear Screen Policy
Does your firm require a clear desk/screen policy when employees leave for a specific time-frame? More secure government agencies (like the CIA, NSA) may require this. Or, some departments with sensitive information (like HR) may require it for your firm, while other departments do not.
X. Removal of Property Policy
Even in small firms, it is often difficult to accurately keep track of physical assets. The firm should have a policy of the process to follow when removing property, such as written authorization for anything over $400, or log form, etc.
VI. Communications and Operations Management Policies and Procedures
This paragraph will be an introduction to this section and what major points you will be discussing, such as standard operating procedures documentation, operational change control, etc. Review the topic at a high level and let the reader know what to expect in this section.
Y. Standard Operating Procedures Documentation Policy
These paragraphs discuss the standard operating procedures policy to ensure standard written documentation. What mechanisms are in place to ensure the integrity of business documents and procedures and negate tampering?
Z. Incident Response Program Policy
Divide the type of incidents into severity level and offer an explanation and example. Refer directly to the table and explain each column. Then explain each level in line with the needs of your firm. A good place to start research is http://www.securityhorizon.com/whitepapersTechnical/IncidentResponsepart2.pdf
Also explain the response and handling procedures for this policy.
Table 2: Incident Severity Level Matrix
|
Severity Level |
Explanation |
Examples |
|
Tier 1: Immediate Response |
Critical incidents which can have a negative long-term effect on the firm if not immediately fixed. |
· Unauthorized access to sensitive data · Property destruction > $10,000 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
AA. Malicious Software Policy
What is the firm’s effort to protect against malicious software? For example, the IT department may be responsible for implementing software controls against unauthorized software installation. Employees are responsible for not installing non-firm software on computer unless obtaining written management authorization, etc.
AB. Information System Backup Policy
Explain the backup and restore policies of your firm. For example, some firms may only perform nightly incremental backups with a full backup once a week. Also discuss how often you are going to test the backup and restore procedure. Give you reasoning for these policies based on your firms needs. A bank with high volume of daily sensitive data may need daily full backups versus a mom-and-pop store with few transaction changes throughout the week.
AC. Management of Portable Storage Devices and Removable Media Policy
These paragraphs discuss how to regulate the use of portable storage devices. SANS Removable Media Policy at http://www.sans.org/resources/policies/ is a good place to start your research.
AD. Security of Media in Transit Policy
If your firm has transfers media from one site to another, you will need to develop this policy. An example of this case might be if the firm makes tape backups in one facility and transfers them to another facility for off-site backup. There must be a secure method for couriers to handle this transfer. Not all firms may have this need.
AE. Publicly Available Systems Policy
What policies do you have to prevent authorized data from being erroneously published to the public? For example, Coca-Cola would want to prevent the recipe for its soft drink being accidently put on the web site. Also, you need to ensure that all laws and regulations on data publications are followed. For example, a school cannot post student grades on the public internet in line with FERPA laws.
AF. E-mail and E-mail Systems Policy
This is different than the e-mail usage policies found in section IV. This is the firm’s overall e-mail systems policy (as opposed to individual usage). Here, you assign e-mail monitoring control and system maintenance. You will also required company-wide training and use of security technology to maintain confidentiality.
VII. Access Control Policies and Procedures
This paragraph will be an introduction to this section and what major points you will be discussing, such as user access management, password use, etc. Review the topic at a high level and let the reader know what to expect in this section.
AG. User Access Management Policy
These paragraphs establish the firm-wide framework for user and administrator privileges. It explains who creates accounts, how account access is logged, when privileges and accounts are revoked (such as a person leaving the firm), etc.
AH. Password Use Policy.
These paragraphs discuss the firm’s requirements for secure passwords. SANS Password Protection Policy at http://www.sans.org/resources/policies/ is a good place to start research. Your first paragraph should explain the level of protection needed based on your firm and its business. After that, you may use bullet points to list the policy points. For example, if you are working for the CIA, you will need to change passwords more frequently than a small mom-and-pop shop with limited sensitive data.
AI. User Authentication for Remote Connections Policy
These paragraphs discuss the risks associated with remote connections such as an employee dialing into the firm’s system when they are working from home and validating that user. What sort of protection are you going to use (such as Challenge/Response Protocol, private lines, dial-back-controls, etc)? SANS has some information in their “Remote Access – Mobile Computing and Storage Devices” policy that you can review for this section and the next.
AJ. Mobile Computing Policy
These paragraphs describe the types of mobile computing devices that your firm uses and the policies for each. For example, you may specify that all remote access must be done through an authorized ISP. Or, no wireless transmissions may be made unless the device is secured first through firm technicians.
AK. Telecommuting Policy
These paragraphs discuss the telecommuting environment including access, authorization, adequate resources and controls. For example, under the category “adequate resources”, the firm may require that the employee’s home have adequate and secure hardware and software including up-to-date virus scanning software or mandatory firewall protection or secure routers, etc.
AL. Monitoring System Access and Use Policy
These paragraphs describe what systems your firm will monitor and how you will notify employees. For example, in most states it is not illegal not to notify the employees their e-mail or Internet surfing is being monitored. However, your firm may decide to have a policy where a monitoring message is displayed when an employee logs into the system, or perhaps the monitoring is explained in the yearly security training program. This policy will tie into your “acceptable use” policy in the Personnel Section above.
VIII. Systems Development and Maintenance Policies and Procedures
This paragraph will be an introduction to this section and what major points you will be discussing, such as applications policy, cryptographic policy, etc. Review the topic at a high level and let the reader know what to expect in this section.
If any of the sections below will not be applicable to your firm, simply indicate that the section is not applicable and give a short statement why it is not. If you are a small mom-and-pop shop and use all canned software without modifications, your firm may not have the need to address cryptography, etc.
AM. Security in Application Systems Policy
These paragraphs define for programmers and systems analysts what is expected of the application code developed for use of the firm (or if selling your software product). If your firm is a software consulting firm and only goes out to client sites to work on the client’s systems, then your employees would be subjected to the policies of your client’s firm. Some things to consider in this section are: how is the code to be tested (there are several different testing methodologies that can be used), who is responsible for which phase of testing, what is done to validate data, separation of duties between coder/tester etc.
If your organization buys solutions – what considerations are important [for security]? How do you decide what and when to upgrade? What safety measures when you upgrade?
AN. Cryptographic Controls Policy
These paragraphs discuss the firm’s requirements for security cryptography controls. Also list acceptable encryption algorithms for your firm: Blowfish, RC5, RSA, DES, etc. SANS Acceptable Encryption Policy at http://www.sans.org/resources/policies/ is a good place to start research.
[Note that SANS has a good item in this areas, but you will need to update the encryption algorithms.]
AO. Security of System Files, Development, and Support Processes Policy
These paragraphs discuss the policies dealing with operating system and application software stability. For example, with operating systems, your firm may have a policy not to be on the “bleeding-edge” of a new operating system, and will wait for a specific number of months before it stabilizes. An example would be waiting at least six months after the initial release of Vista before switching from XP. Another issue is checking for vulnerabilities before upgrading software or patches. Also discuss who is responsible for applying the updates. Finally, how is your testing environment separate from the production environment?
IX. Disaster Recovery and Business Continuity Policies and Procedures
This paragraph will be an introduction to this section and what major points you will be discussing, such as business continuity assessment, etc. Review the topic at a high level and let the reader know what to expect in this section. Please note in this section that we are not building an entire Business Continuity Plan – we are creating a policy for having the Plan!
This is an important and LONG chapters. Make sure that you cover all the details.
AP. Business Continuity Assessment Policy
These paragraphs discuss the risk assessment and business impact analysis (BIA) events that are used to determine the levels of risk to your firm and systems. What will be accomplished, who is responsible and what are the objectives? For example, one aspect of business impact analysis is to determine the tolerance of downtime on a system-to-system basis. An example for the risk assessment is to determine the likelihood for specific security threats. The easiest approach is to include an introduction paragraph that describes the overall needs of a risk assessment and BIA for your firm (why does it need them). Then, divide into a section for each and include bullet points on the policies for each area. You may start with http://www.dir.state.tx.us/IRAPC/bcpg/bcpg-pt1.rtf for some initial research.
AQ. Business Continuity Plan Policy
These paragraphs discuss the various parts of a business continuity plan for your firm and who approves each part of the plan. For example, you may have only 1 phase or may divide the planning into phases like: disaster preparation, response, contingency, recovery. Compile a strategy table (see page 29 of http://www.dir.state.tx.us/IRAPC/bcpg/bcpg-pt1.rtf or page 365 of the Security Policies and Procedures text) to describe which types of preparation you are going to use in case of a disaster. Your firm may decide to use one or all of these options for various departments or groups. For example, if you are the size of IBM, you may use a hot site for your division in the northeast US, and may decide to use a reciprocal agreement for the small division in Atlanta. Alternatively, your firm may decide the only option is to use a cold site.
Table 3: Recovery Strategy Table
|
Strategy |
Recovery Time Frame |
Advantages/ Disadvantages |
Firm Use |
|
Hot Site |
1 day |
Fast recovery, but expensive |
Will use for the northeast region division |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
AR. Business Continuity Team Policy
These paragraphs discuss the roles and responsibilities of various team members. For example, http://www.dir.state.tx.us/IRAPC/bcpg/bcpg-pt1.rtf has a good list of various team members you might consider (base the team members on YOUR firm’s needs), as well as general duties. For this section, include a paragraph reviewing the overall team structure based on your firms needs. Then, follow with specific bullets on each team member along with high-level duties.
AS. Major Systems Recovery Policy
These paragraphs describe the major systems that will be recovered along with a description of recovery needs. I have included a few in the table below, but customize for your own firm. A good place to start reviewing is http://news.zdnet.com/2100-1009_22-6179861.html
Table 4: Recovery Categories
|
Category |
Description |
|
Mainframe |
System will hold all enterprise-wide applications and databases including Peoplesoft software and Oracle database. Recovery is critical to rebuild hardware, software and operating system. Hardware must be recovered first followed by OS, then enterprise databases and software. |
|
Network |
|
|
Communications |
|
|
Infrastructure |
|
|
Facilities |
|
|
|
|
|
Stand-alone computer systems |
|
|
|
|
|
|
|
AT. Business Continuity Plan Testing and Maintenance Policy
These paragraphs describe the testing that will be performed. There are several methods of testing methodologies, and depending upon your firms needs, you should choose the ones that make sense for your firm’s recovery efforts. Some places to start your research on testing are http://quality-assurance-software-testing.blogspot.com/2005/07/testing-methodologies.html and http://en.wikipedia.org/wiki/Software_testing
X. Regulatory Policies and Procedures
This paragraph will be an introduction to this section and what major points you will be discussing. Review the topic at a high level and let the reader know what to expect in this section.
AU. Common Threat Policy
These paragraphs will describe your firm’s industry and then review the common security threats in that industry as well as successful means of safeguarding against these methods. For example, many electronic commerce firms, especially in the banking industry suffer from phishing threats, which are not common to mom-and-pop grocery firms. Insurance and medical industry firms are more susceptible to dumpster diving attacks, so a shredding policy should be implemented. This section MUST also contain at least 1 research article/citation listing an example of a specific security breach in your firm’s industry.
AV. Regulatory Review Policy
These paragraphs discuss the mandated regulatory safeguards for firms in your industry. For example, if you are in the medical industry, you must research security rules related to HIPPA’s safeguarding of patient information. FERPA regulations deal with the educational industry. Ecommerce firms should review laws such as COPPA and CIPPA, along with mandatory VISA’s mandatory Cardholder Information Security Program. Banks and credit unions will review GLB Act and SOX. These are only a few examples, but your must research your industry and provide citations and references here.
XI. Reference List
Adkinson, W., Eisenach, J., & Lenard, T. (2002, March). Privacy online: A report on the information practices and policies of commercial Web sites. The Progress & Freedom Foundation. Retrieved January 11, 2004 from http://www.pff.org/issues-pubs/books/020301privacyonlinereport.pdf
XII. Appendix
Include any needed pictures, graphs, etc. If not needed – delete this page
PAGE