The following is an example security policy for the Global Personal Marketplace (GPM), a Web-based auction and sales application intended for private individuals and small businesses.
The frontmatter of this security policy includes the following:
TBD
TBD
The introduction of this security policy has the following subsections:
This document contains the security policy for the Global Personal Marketplace (GPM) application.
The objectives of this security policy document are to:
The intended audiences for this security policy include all internal stakeholders of the GPM application:
The security policy for the GPM application references the following documents:
The overview of this security policy has the following subsections:
The services provided by the Global Personal Marketplace (GPM) application are very valuable and the primary source of our income. The information that GPM controls, whether belonging to the company or held in trust for and on behalf of our customers and our personnel, is also a valuable asset. These services and information must be protected to an extent corresponding to their value and the extent of the damage that could result from their unautorized use or misuse including disclosure, modification, destruction, or intentional lack of availability.
The following are the security goals for the Global Personal Marketplace application:
The following are general security principles for the Global Personal Marketplace (GPM) application:
The scope of this security policy includes the security of the Global Personal Marketplace (GPM) application including its:
The security policies for the GPM application fall into the following categories:
The GPM will identify all buyers, sellers, and employees before allowing them to perform their associated tasks.
The GPM will verify the identity of all buyers, sellers, and employees before allowing them to perform their associated tasks.
Each user and employee shall be granted only sufficient access required to perform the tasks for which they have explicitally been authorized.
The GPM application will include sufficient mechanisms to ensure immunity from infection by malicious programs such as viruses, worms, Trojan horses, and logic bombs.
TBD
TBD
TBD
TBD
TBD
TBD
TBD
The following organizations, teams, and roles are responsibile for the security policy:
The security policy has the following appendices:
Applicable Regulations, Laws, Certifications and Standards
(e.g., HIPPA, FDIC, ISO 9000, CPA WebTrust, and
Truste)
The following major issues need to be resolved prior to the approval and publication of this security policy:
The following section of this security policy are to be determined:
The contents of this security policy are based on the following assumptions: