Home > Ask the Security Channel Experts > Security Management Questions & Answers > Creating security policies for an enterprise customer
Ask The Security Channel Expert: Questions & Answers
EMAIL THIS

Creating security policies for an enterprise customer

Felicia Wetter EXPERT RESPONSE FROM: Felicia Wetter

Pose a Question
Other Security Channel Categories
Meet all Security Channel Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 20 October 2006
I'm a security consultant with an enterprise customer in dire need of security policies. What is the best way to approach this situation? Should I present a template policy to them and, with their input, tweak it to suit their environment? Or should I start from scratch?

>
EXPERT RESPONSE

There are a plethora of resources available to assist you and your customer in creating security policies that meet their needs and requirements. The best way to approach the situation is to first assess the situation; do they have any policies in place today? If so, can they be leveraged to create a more well-rounded set of security policies? If they do not, then what policies are they looking to create, and is there a standard or set of policies they are specifically interested in? Two approaches at this point are possible. You can either begin with the common security policies, such as Internet Use, Password Management, Remote Access, etc., or you can start with a standard, such as ISO17799 and develop the policies based on this.

Once you have determined where to begin and have developed a preliminary set of policy topics, it is time to add the content. Determine what they have in place, for example, on password requirements, and create a policy based on what they are practicing today. Once you have the baseline policy, if they feel they can add more stringent requirements, they should then be added, but only if the customer is willing to increase the level of security practices. The security policies must be 'achievable' by your customer. Do not recommend security policies that they can never comply with.

The next part will be getting the policies approved and implemented. This can often times be the most difficult part. Make sure that a security policy committee is created, and use that committee for the creation of the security policies. Members should be comprised of all departments within the organization. The committee should be ultimately responsible for approving the policies, as they will ensure employees are complying with them after they are implemented.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Security Management
Hardening Linux as part of your client's network security policy
Implementing wireless LAN security policies for mobile users
Should hotfix testing be performed by the QA department or by support?
Complying with the Federal Information Security Management Act (FISMA)
Automated patch management for SMB customers
Understanding ISO 27001 and ISO 17799
Maintaining HIPAA compliance
How do I create a repeatable patch testing methodology?
Implementing third-party patches on customer systems
Patch management system post-deployment considerations for VARs and consultants

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice

HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersBlogsEvents
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2006 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts