  |
Internet DMZ Equipment Policy - http://www.sans.org/resources/policies/Internet_DMZ_Equipment_Policy.pdf
Sample policy defining the minimum requirement for all equipment located outside the corporate firewall. |
  |
Information Sensitivity Policy - http://www.sans.org/resources/policies/Information_Sensitivity_Policy.pdf
Sample policy defining the assignment of sensitivity levels to information. |
  |
Information Security Policies - http://www.ucisa.ac.uk/publications/ist.aspx
The Information Security Toolkit from UCISA (University Colleges and Information Systems Association) contains a suite of security policy and guidance documents reflecting and cross-referenced against BS7799, intended for use in universities. [PDF documents] |
  |
Database Password Policy - http://www.sans.org/resources/policies/DB_Credentials_Policy.doc
Defines requirements for securely storing and retrieving database usernames and passwords. [MS Word] |
  |
Risk Assessment Policy - http://www.sans.org/resources/policies/Risk_Assessment_Policy.doc
Defines requirements and authorizes the information security team to identify, assess and remediate risks to the organization's information infrastructure. [MS Word] |
  |
Acquisition Assessment Policy - http://www.sans.org/resources/policies/Aquisition_Assessment_Policy.doc
Defines responsibilities regarding corporate acquisitions and the minimum requirements of an acquisition assessment to be completed by the information security group. [MS Word] |
  |
Anti-Virus Policy - http://www.sans.org/resources/policies/Lab_Anti-Virus_Policy.doc
Requirements for effective virus detection and prevention. Written for a laboratory environment but easy to adapt for other settings. [MS Word] |
  |
Analog/ISDN Line Policy - http://www.sans.org/resources/policies/Analog_Line_Policy.doc
Defines policy for analog/ISDN lines used for FAXing and data connections. |
  |
Acceptable Use Policy - http://www.sans.org/resources/policies/Acceptable_Use_Policy.doc
Defines acceptable use of IT equipment and computing services, and the appropriate employee security measures to protect the organization's corporate resources and proprietary information. [MS Word] |
  |
Encryption Policy - http://www.sans.org/resources/policies/Acceptable_Encryption_Policy.doc
Defines encryption algorithms that are suitable for use within the organization. [MS Word] |
  |
HSPD-12 Privacy Policy - http://www.whitehouse.gov/omb/memoranda/fy2006/m06-06_att.doc
Sample privacy policy including Privacy Act systems of records notices, Privacy Act statements and a privacy impact assessment, designed to satisfy the requirements of HSPD-12 “Policy for a Common Identification Standard for Federal Employees and Contractors” |
  |
Information Security Policy - http://www.obfs.uillinois.edu/manual/central_p/sec19-5.html
An information security policy from the University of Illinois. |
  |
Backup Policy - http://its.uncg.edu/Policy_Manual/Computer_Backup/
Sample policy from the University of North Carolina requires daily, weekly and monthly backups (sometimes known as 'grandfather, father, son'). |
  |
Password Policy - http://www.umflint.edu/its/units/initiatives/publicity/password.htm
A password policy presented in the form of a series of security awareness posters. "Passwords are like underwear ..." |
  |
IT Security Policy - http://www.murdoch.edu.au/admin/policies/itsecurity/policy.html
Information technology security policy at Murdoch University, complete wth supporting standards and guidelines. |
  |
Law Enforcement Data Security Standards - http://www.cleds.vic.gov.au/retrievemedia.asp?Media_ID=20338
IT security policy applicable to the Victoria Police in Australia. 93 pages based on ISO/IEC 27002 and related standards. |
  |
Information Security Policies - http://www.tess-llc.com/TESS-DOR-EXAMPLES.htm
Templates for information security policies, guidelines, checklists and procedures by Walt Kobus. |
  |
Privacy Policy - http://www.cbe.uidaho.edu/wegman/404/PRIVACY%20POLICY%20IVI%20Generic.htm
Generic policy for websites offering goods and services, with an important warning to seek qualified legal advice in this area. |
  |
Personnel Security Policy - http://www.datasecuritypolicies.com/wp-content/uploads/2007/04/generic-personnel-security-policy.pdf
Example policy covering pre-employment screening, security policy training etc. |
  |
Physical Security Policy - http://www.tess-llc.com/Physical%20Security%20PolicyV4.pdf
Policy template by Walt Kobus defines requirements for physical access control to sensitive facilities and use of ID badges. |
  |
Data Classification Policy - http://www.tess-llc.com/Data%20Classification%20PolicyV4.pdf
Policy template by Walt Kobus describes the classification of information according to sensitivity (primarily confidentiality). |
  |
Resource Utilization Policy - http://www.tess-llc.com/Resource Utilization PolicyV4.pdf
Policy template by Walt Kobus defines requirements for resilience, redundancy and fault tolerance in information systems. |
  |
Information Data Ownership Policy - http://www.tess-llc.com/Information%20Data-Ownership%20PolicyV4.pdf
Policy template by Walt Kobus defines the roles and responsibilities of owners, custodians and users of information systems. |
  |
User Data Protection Policy - http://www.tess-llc.com/User%20Data%20Protection%20PolicyV4.pdf
Policy template by Walt Kobus defines requirements for access controls, least privilege, integrity etc. to secure personal data. |
  |
Cryptography Policy - http://www.tess-llc.com/Cryptography%20PolicyV4.pdf
Cryptographic policy template by Walt Kobus. |