HostedDB - Dedicated UNIX Servers

-->
IT Baseline Protection Manual S 2.192 Drawing up an Information Security Policy

S 2.192 Drawing up an Information Security Policy

Initiation responsibility: Agency/company management

Implementation responsibility: Agency/company management; IT Security Management Team

The Information Security Policy defines the level of IT security to which the organisation aspires. The Information Security Policy contains the IT security objectives which the organisation has set itself and the IT security strategy it pursues. In this way it constitutes both an aspiration and a statement that the IT security level specified is to be achieved at all levels of the organisation. Preparation of the Information Security Policy should be considered under the following headings:

  1. Responsibility of Management for the Information Security Policy
  1. Convening of a team responsible for development of the Information Security Policy
  1. Determination of the IT security objectives
  1. Content of the Information Security Policy
  1. Distribution of the Information Security Policy
  1. Drawing up of additional IT system security policy documents

An example of an Information Security Policy is enclosed as an aid on the CD-ROM at word20\hilfsmi\13policy.docVerweis.

The preparation of the Information Security Policy requires the following stages:

  1. Responsibility of Management for the Information Security Policy
  1. Convening of a team responsible for development of the Information Security Policy
  1. Determination of the IT security objectives

  1. Content of the Information Security Policy
  1. Distribution of the Information Security Policy
  1. Drawing up additional IT system security policy documents

Additional controls:


© Copyright by
Bundesamt für Sicherheit in der Informationstechnik
last update:
October 2000
home