| |
Information Security Policy Development
Introduction
Organizational Policy is a document that outlines overall intention and direction, as formally expressed by the management of an organization. It prescribes the requirements or rules that must be adhered to, by all concerned. An information security policy outlines organization’s approach to managing information security to achieve its information security goals and objectives in terms of protecting confidentiality, integrity and availability of information.
Management should set a clear policy direction in line with business objectives and demonstrate support for, and commitment to, information security through the issue and maintenance of an information security policy across the organization.
Benefits
By creating information security policies specific to your environment, you are building a solid foundation, which would help you to:
- Protect your information, network and processing systems
- Set information security goals and responsibilities for your organization
- Guide and control the users of information and information processing assets
- Increase the availability of your information processing systems
- Reduce the risk of unplanned downtime
- Prevent unauthorized access / disclosure
- Prevent and manage the information security incidents.
Why Sify?
Sify has vast experience in developing information security policies for organizations of all sizes, across multiple business verticals. Sify uses ISO 27001 International Standard for Information Security as the benchmark for developing comprehensive information security policies for an organization. All the policies that are developed by Sify are compliant with ISO 27001 standard.
Sify’s Information Security Policy Development Services ensure that information security goals are identified for your organization, which meet the organizational requirements, and are integrated in relevant processes. Taking into account your business needs, Sify’s security consultants evaluate your technical and security requirements, existing security practices and analyze potential risks associated with your information, data and processing resources. Our consultants develop security policies that cover every aspect of information security relevant to your business and technical environment, covering confidentiality, integrity, availability, accountability and non-repudiation.
Policies Across Various Domains
Sify’s information security policies cover multiple domains of business and information security. These domains, which are finalized as per organization’s requirement, include:
- High level information security policy
- Asset management
- Human Resources Security (Pre-employment, During and Post-employment)
- Physical and Environmental Security)
- Communications and Operations Management (Network security, Back-up, Third party services, Anti-virus, etc)
- Access control (User access, OS access, Network access, etc)
- Information Systems Acquisition, Development and Maintenance
- Information Security Incident Management
- Compliance (Intellectual Property Rights).
In addition to the above, Sify can also develop security policies to protect any other areas of concern of the client organization.
|
|