Example Security Policy


Contents:  Front Matter Introduction Overview Security Policies Responsibilities Appendices

The following is an example security policy for the Global Personal Marketplace (GPM), a Web-based auction and sales application intended for private individuals and small businesses.

Front Matter

The frontmatter of this security policy includes the following:

Title Page

TBD

Revision History

TBD

Introduction

The introduction of this security policy has the following subsections:

Document Definition

This document contains the security policy for the Global Personal Marketplace (GPM) application.

Document Objectives

The objectives of this security policy document are to:

Intended Audiences

The intended audiences for this security policy include all internal stakeholders of the GPM application:

References

The security policy for the GPM application references the following documents:

Overview

The overview of this security policy has the following subsections:

Importance Of Security

The services provided by the Global Personal Marketplace (GPM) application are very valuable and the primary source of our income. The information that GPM controls, whether belonging to the company or held in trust for and on behalf of our customers and our personnel, is also a valuable asset. These services and information must be protected to an extent corresponding to their value and the extent of the damage that could result from their unautorized use or misuse including disclosure, modification, destruction, or intentional lack of availability.

Security Goals

The following are the security goals for the Global Personal Marketplace application:

Security Principles

The following are general security principles for the Global Personal Marketplace (GPM) application:

Security Policy Scope

The scope of this security policy includes the security of the Global Personal Marketplace (GPM) application including its:

Security Policies

The security policies for the GPM application fall into the following categories:

Identification

The GPM will identify all buyers, sellers, and employees before allowing them to perform their associated tasks.

Authentication

The GPM will verify the identity of all buyers, sellers, and employees before allowing them to perform their associated tasks.

Authorization

Each user and employee shall be granted only sufficient access required to perform the tasks for which they have explicitally been authorized.

Immunity

The GPM application will include sufficient mechanisms to ensure immunity from infection by malicious programs such as viruses, worms, Trojan horses, and logic bombs.

Integrity

TBD

Intrusion Detection

TBD

Nonrepudiation

TBD

Privacy

TBD

Security Auditing

TBD

Physical Protection

TBD

SystemMaintenanceSecurity

TBD

Responsibilities

The following organizations, teams, and roles are responsibile for the security policy:

Appendices

The security policy has the following appendices:

Applicable Regulations

Applicable Regulations, Laws, Certifications and Standards
(e.g., HIPPA, FDIC, ISO 9000, CPA WebTrust, and Truste)

Major Issues

The following major issues need to be resolved prior to the approval and publication of this security policy:

TBDs

The following section of this security policy are to be determined:

Assumptions

The contents of this security policy are based on the following assumptions: