Management of Information Security, Fourth Edition 4-1
© 2014 Course Technology, Cengage Learning
Chapter 4
Information Security Policy
At a Glance
Instructor’s Manual Table of Contents
Overview
Objectives
Teaching Tips
Management of Information Security, Fourth Edition 4-2
Lecture Notes
Overview
Chapter 4 introduces students to the concept of information security policies. Students will
effective policy implementations are discussed as well.
Chapter Objectives
After reading this chapter and completing the exercises, the student will be able to:
Define information security policy and understand its central role in a successful
Teaching Tips
Introduction
1. Emphasize the importance of information security policies within an effective
information security program.
Why Policy?
1. Explain that information security policies act as an outline for acceptable behavior and
use of information.
2. Note that policy functions as a low cost form of control for prevention of incidents
involving information.
3. Discuss some of the basic rules that should be followed when creating a policy:
5. Provide students with the guidelines recommended by Bergeron and Berube on the
creation of IT policy:
Management of Information Security, Fourth Edition 4-3
6. Introduce students to the bull’s-eye model for prioritizing complex changes, and list the
four different layers of the model:
7. Explain the role of policy in protecting an organization and its employees, by
Policy, Standards, and Practices
1. Describe policy as a defined plan or course of action, intended to influence and
determine decisions, actions, and other matters. Note that policy represents the formal
statement of the organizations managerial philosophy.
5. Point out that practices, procedures, and guidelines determine how employees are to
comply with policy.
6. Describe the three types of policies that must be defined, according to NIST, and note
that they are often created in this order:
Enterprise Information Security Policy
1. Define an enterprise information security policy (EISP) as a policy that sets the
strategic direction, scope, and tone for all of an organization’s security efforts.
Integrating an Organization’s Mission and Objectives into the EISP
1. Educate students on the role of the EISP in stating the importance of information
EISP Elements
1. Discuss what elements should exist within an EISP document:
Management of Information Security, Fourth Edition 4-4
a. An overview of the corporate philosophy on security
Example EISP Components
1. Discuss the sample of a high-level information security policy provided by Charles
1. Describe an issue-specific security policy (ISSP) as a policy that provides detailed,
targeted guidance to instruct all members of the organization in the use of a resource.
2. Note that an ISSP should begin by introducing the organization’s fundamental
4. Discuss the three characteristics that every ISSP should have:
a. It addresses specific technology-based resources
b. It requires frequent updates
Components of the ISSP
1. Note that the ISSP should begin with a clear statement of purpose that outlines the
scope and applicability of the policy.
2. Explain the authorized uses section of the policy as outlining who can use technology
covered under the policy, and for what purposes.
Management of Information Security, Fourth Edition 4-5
Implementing the ISSP
1. Discuss the three most common approaches for creating and managing ISSPs:
a. Create a number of independent ISSP documents, each specifically tailored for
2. Provide students with some advantages and disadvantages related to each of the three
common approaches.
3. Note that the recommended approach is the modular policy, due to the fact that a
standard template can be used, while allowing for customization on specific issues.
System-Specific Security Policy
1. Define the system-specific security policy (SysSP) as being similar to a set of standards
Managerial Guidance SysSPs
1. Explain how a managerial guidance SysSP document is created by management to
guide implementation of new hardware and to address employee behavior.
Technical Specification SysSPs
1. Explain to students why a system administrator might need to create a different policy
in order to implement a managerial policy, such as with passwords.
2. Make students aware of the two different methods for implementing technical controls:
Teaching
A modular policy’s ability to be customized also makes it more suited for
Management of Information Security, Fourth Edition 4-6
3. Access control lists should be explained as a list that allows or denies access based on
authentication or types of network traffic. Make students aware of the different aspects
of access covered by an ACL:
4. List some of the privileges that can be assigned to a user within an ACL, such as:
a. Read
set.
7. Explain the use of a combination SysSP, which takes the managerial SysSP document
and combines it with the technical specifications SysSP.
Quick Quiz 1
1. Also known as a general security policy, a(n) ____________________ sets the
strategic direction, scope, and tone for an organization’s security efforts.
2. True or False: A system administrator may need to create a different type of policy in
order to implement a managerial policy.
3. Which of the following is NOT a typical permission available for use in ACLs?
A. Read
B. Write
C. Delete
D. Expunge
4. Which of the following is NOT a specific characteristic of ISSP?
A. It addresses specific technology-based resources
B. It requires frequent updates
C. It addresses hardware implementation issues
D. It contains an issue statement
Teaching
Access control lists, when used to control file access, can be tricky to master.
Management of Information Security, Fourth Edition 4-7
5. Which of the following is NOT an InfoSec policy recommended in NIST’s Special
Publication 800-14 document?
A. Enterprise information security policy (EISP)
B. Issue-specific security policies (ISSP)
C. System-specific security policies (SysSP)
D. Task-specific security policies (TSSP)
Guidelines for Effective Policy
1. Educate students on the characteristics of a successful policy:
a. Developed using industry-accepted practices
Developing Information Security Policy
1. Explain the benefits of viewing the development process of a InfoSec policy in two
2. Describe how the systems development life cycle (SDLC) can be used to develop a
policy.
3. List some of the different items that should be attained during the investigation phase of
policy development:
a. Support from senior management
e. A detailed outline of the scope of the policy development
4. Make students aware of what tasks should occur at the analysis phase:
a. A new or recent risk assessment or IT audit
b. The gathering of key reference materials
5. Discuss Wood’s Information Policies Made Easy recommendations on the analysis
phase.
6. Explain that the plan for distribution and verification of distribution of policy occurs at
Management of Information Security, Fourth Edition 4-8
a. The Web
Policy Distribution
1. Provide students with an understanding of the difficulty of policy distribution, and give
some examples of how a policy can be distributed, such as by bulletin board or by
Policy Reading
1. Elaborate on issues that can arise as a result of illiteracy or due to poor understanding
of the native language in which a policy is written.
Policy Comprehension
1. Stress the importance of ensuring that employees will understand a policy, and note that
jargon or technical terms should be kept to a minimum in order to ensure
Policy Compliance
1. Explain that policy compliance means that an employee must agree to a policy, and
discuss Whitman’s comments on compliance.
Policy Enforcement
1. Educate students on how to ensure policy enforcement, either by using punishment
based or reward based systems.
Management of Information Security, Fourth Edition 4-9
Automated Tools
1. Discuss options for automated policy management, such as the VigilEnt Policy Center
(VPC) tool.
The Information Securities Policy Made Easy Approach
1. Provide students with an overview of the checklist of steps in the policy development
process, as recommended by Wood’s Information Security Policies Made Easy book.
SP 800-18 Rev. 1: Guide for Developing Security Plans
for Federal Information Systems
1. Discuss NIST’s Special Publication 800-18, Rev. 1, which describes a business
process-centered approach to policy management.
2. Stress the importance of reviewing existing policies on a schedule, as well as ensuring
any policy revisions are properly dated.
3. Explain the role of a champion and a manager in the creation of policy, and note that
A Final Note On Policy
1. Emphasize that the use of policy is intended to improve employee productivity, and
inform employees of acceptable / unacceptable behavior.
Teaching
Dark Reading article on the creation and enforcement of security policies:
Teaching
To read the actual NIST Special Publication 800-18 Rev. 1 document, visit:
Management of Information Security, Fourth Edition 410
Quick Quiz 2
1. A(n) ____________________ regulates the who, what, when, where, and how aspects
of access to a system or resource.
2. True or False: A policy administrator is the combination of a system administrator and
a champion.
3. __________ are more specific to the operation of a system than ACLs, and consist of
instructional codes that guide execution of a system when information is passing
through it.
4. What is the name of the agreement screen that prompts for user acceptance of fair and
responsible use terms for a particular software package?
A. End-user license agreement
B. End-user fair-use policy
C. End-user terms of use agreement
D. End-user distribution policy
5. All but which of the following occurs during the investigation phase of policy
development?
A. Attaining support from senior management
B. Providing clear articulation of goals
C. Performing a risk assessment
D. Creating a detailed outline of a policy’s scope
Class Discussion Topics
1. Start a class discussion on the typical acceptable use policies that students have
encountered when seeking employment.
2. Get students to discuss the issue of wrongful termination based on policy violations,
Additional Projects
Management of Information Security, Fourth Edition 411
1. Get students to search for policy examples on the Internet, and then task students with
Additional Resources
1. SANS page containing security policy templates: