Any organization depending on a network has a security policy in place. A security policy basically contains the following:
- The organization's objectives
- Rules and regulations for the network's users and administrators
- Requirements for the system and management that collectively ensure network security
A security policy also lays down the guidelines, standards, and procedures for the functioning of a network. The main components of a security policy are the governing policy, the end-user policy, and the technical policy:
- Governing policy: This policy contains the answers to the
"what needs a security policy"
question. It contains high-level categorization of the security elements that are important for the organization. People at the managerial or technical level are responsible for this policy. - End-user policy: This policy...