Network security policy
This article needs additional citations for verification. (April 2010) (Learn how and when to remove this template message) |
A network security policy (NSP) is a generic document that outlines rules for computer network access, determines how policies are enforced and lays out some of the basic architecture of the company security/ network security environment.[1] The document itself is usually several pages long and written by a committee.
A security policy is a complex document, meant to govern data access, web-browsing habits, use of passwords, encryption, email attachments and more. It specifies these rules for individuals or groups of individuals throughout the company.[2] The policies could be expressed as a set of instructions that understood by special purpose network hardware dedicated for securing the network.
Security policy should keep the malicious users out and also exert control over potential risky users within an organization.
Understanding what information and services are available and to which users, as well as what the potential is for damage and whether any protection is already in place to prevent misuse are important when writing a network security policy. In addition, the security policy should dictate a hierarchy of access permissions, granting users access only to what is necessary for the completion of their work. The National Institute of Standards and Technology provides an example security-policy guideline.
See also
- Internet security
- Security engineering
- Computer security
- Cybersecurity information technology list
- Network security
- Industrial espionage
- Information security
- Security policy
References
External links
- Computer Security Resource Center at National Institute of Standards and Technology
- Network Security Policy and Procedures document by the City of Madison, Wisconsin
Original source: https://en.wikipedia.org/wiki/Network security policy.
Read more |