Security
Policy
SANS InfoSec Reading RoomArticles on security policy and other information security topics.
Make Your Web Site P3P Compliant
How to Create and Publish Your Company's P3P Policy
P3P Guiding Principles
This document is part of the Platform for Privacy Preferences
Project Activity. This document describes the intent of P3P development
and recommends guidelines regarding the responsible use of P3P technology.
It is one section of the P3P Implementation Guide.
Canada's Export Controls
Unofficial / unverified article describing Canada's export controls on cryptographic software.
CERT Practice Modules: Responding to Intrusions
Establish policies and procedures for responding to intrusions.
U.S. Department of Health and Human Services
Administrative Simplification in the Health Care Industry
CERT Practice Modules: Securing Desktop Workstations
Develop and promulgate an acceptable use policy for workstations.
Common Criteria Evaluation and Validation Scheme
This program is being implemented to help consumers select
commercial off-the-shelf information technology (IT) products that meet
their security requirements and to help manufacturers of those products
gain acceptance in the global marketplace.
SecureZone
The SecureZone site is currently undergoing a face lift.
All the section will shortly be opened, creating a substantial portal. Please
bear with is whilst the re-vamp is completed.
Institute for Security and Open Methodologies (ISECOM)
ISECOM is an open, collaborative, security research community
The Information Security Forum
the Information Security Forum (ISF) is the world's leading
independent authority on information security. By harnessing our world-renowned
expertise and the collective knowledge and experience of our members - including
50% of Fortune 100 companies - the ISF delivers practical guidance and solutions
to overcome wide-ranging security challenges impacting business information
today.
