Simon,

The site security policy that I wrote for my last place of employment was
borrowed from mainly from "NIST's Special Publication:Internet Security
Policy: A Technical Guide" (http://csrc.nist.gov/isptg/html/), but also from
cert.org and RFC1244.

You might also look at:
http://secinf.net/

http://fw4.iti.salford.ac.uk/ice-tel/firewall/policy.html

http://www.reeusda.gov/issp/98planguide.htm

I have run across an book and CD-ROM that claims to include everything you
need.  It looks like it could be useful, but I haven't seen it myself and it
is pricey ($495.00):

Information Security Policies Made Easy, Version 7, By Charles Cresson Wood,
CISA, CISSP.  More information on it is available at:
http://www.baselinesoft.com/

Bob Gerrish
Unix Systems Administrator
Trim Systems, LLC
Seattle, WA
[EMAIL PROTECTED]

> -----Original Message-----
> From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]
> Sent: Tuesday, May 09, 2000 7:04 AM
> To: [EMAIL PROTECTED]
> Subject: Security Policy
> 
> 
> Sorry, I know this has already been talked to death about, 
> but can anyone
> point me in the right direction when it comes to writing a 
> decent security
> policy that encorporates firewalls, proxies etc...
> 
> Regards
> 
> Simon
> 
> 
> 
> **********************************************************************
> If you are not the intended recipient of this e-mail and have 
> received it
> in error, you are on notice that the e-mail and any attached files are
> confidential. Please notify us immediately by reply e-mail 
> and then delete
> this message from your system.  Please do not use, distribute, copy or
> take any action in reliance on it as to do so could be a breach
> of confidence.  The sender does not accept any responsibility for any
> loss, disruption or damage to your data or computer system 
> which may occur
> whilst using data contained in, or transmitted with, this 
> e-mail.  Thank
> you for your co-operation.  If you need assistance, please contact
> Maritz Ltd -  tel.:  +44 (0)1628 486011 or e-mail: 
> [EMAIL PROTECTED]
> **********************************************************************
> -
> [To unsubscribe, send mail to [EMAIL PROTECTED] with
> "unsubscribe firewalls" in the body of the message.]
> 
-
[To unsubscribe, send mail to [EMAIL PROTECTED] with
"unsubscribe firewalls" in the body of the message.]

Reply via email to