Book Reviews: Creating Security Policies and Defining Security Roles

Large organizations looking for help on creating security policies and defining security roles and responsibilities need look no further — two titles from Information Shield provide help on just that.
Mitch Tulloch photo

If you missed Mitch Tulloch's other Security Books reviews please read:


Information Security Policies Made Easy, Version 10

Developing security policies has always been a drag for IT departments. That's because developing policies is a management discipline, not a technical one, and IT pros would usually rather rebuild a server than write a page of policy material. That's why Information Security Policies Made Easy (10th edition, Information Shield) can be a really useful addition to IT departments in large companies. While it doesn't come cheap, the huge amount of useful information and accompanying CD-ROM makes this book a worthwhile investment. In addition to explaining what policies are and how they are developed, the book contains over a thousand policy templates you can mix and match to create your own corporate security policies with little effort. Each policy template includes a commentary explaining in detail the purpose of the policy, the target audience for the policy, and the kind of security environment to which the policy applies. These template policies cover organizational security, asset control, personnel issues, physical security, communications and operations, access control, systems development, business continuity, and compliance issues—in short, pretty much everything!

There are also sample policies presented for network security, electronic mail, external communications, Internet use, privacy, and more. Plus more than a dozen appendices with additional helpful information regarding policy use and misuse. Plus there's the CD-ROM included that helps you quickly and easily create a customized policy for every aspect of your organization's information security architecture. Well, perhaps not that quickly since policies need to grow out of your organization's business goals and tolerance for risk, and the process of creating such policies usually involves committee work across multiple business units. Still, what this book does give you is a tool for quickly creating draft policies for further discussion and refinement, plus it provides great help in assuring that you've covered most of the important bases as far as these draft policies are concerned. Plus it helps verbally-challenged IT staff create professional-sounding policies that are expressed clearly and accurately. All in all, not a bad resource if your main spoke language is VBScript or Perl!

Information Security Roles & Responsibilities Made Easy, Version 2

But that's not all. Information Shield also has a second title called Information Security Roles & Responsibilities Made Easy (2nd edition) that helps organizations deal with another important aspect of developing an effective information security program—namely defining the various roles and responsibilities involved in ensuring an organization's business assets are secure. This also means help creating the documents that define these roles and responsibilities, which include mission statements for different departments, job descriptions ranging from CIO to Help Desk personnel, reporting relationships, organizational structures, handbooks, memos, action plans, and more. Plus there's an excellent discussion of common mistakes organizations need to avoid such as failing to obtain executive sponsorship for information security initiatives, failing to match accountability with level of responsibility, initiating major projects before clearly defining roles and responsibilities, creating overly-detailed job descriptions, lack of compliance checking, undefined error reporting process, and so on. Plus, as with the previous title above, this book also includes a CD-ROM that helps you automate a lot of the actual task of creating documents to formally define infosec roles and responsibilities.

Conclusion

I would probably say the target audience for these books would be companies of around 500 or more employees, because that's about the size where written policies become important and roles proliferate. Smaller companies with 100 or more employees may also find these books useful, but should be careful not to create policies that are overly detailed since the work culture in such companies is usually more informal than in larger ones. Overall, I recommend these books to any CIO or CSO who wants to help their department formulate effective security policies, but make sure you use these books not as a crutch (i.e. we need to whip up a few policies so management will get off our back) but as an integral part of a thoughtful exercise that has management buy-in and is supported across your organization. Otherwise any policy, no matter how comprehensive and well-written, will just not be effective.

If you missed Mitch Tulloch's other Security Books reviews please read:

About Mitch Tulloch

Mitch Tulloch photo Mitch Tulloch is a writer, trainer and consultant specializing in Windows server operating systems, IIS administration, network troubleshooting, and security. He is the author of 15 books including the Microsoft Encyclopedia of Networking (Microsoft Press), the Microsoft Encyclopedia of Security (Microsoft Press), Windows Server Hacks (O'Reilly), Windows Server 2003 in a Nutshell (O'Reilly), Windows 2000 Administration in a Nutshell (O'Reilly), and IIS 6 Administration (Osborne/McGraw-Hill). Mitch is based in Winnipeg, Canada, and you can find more information about his books at his website www.mtit.com

Click here for Mitch Tulloch's section.

Receive all the latest articles by email!

Get all articles delivered directly to your mailbox as and when they are released on WindowSecurity.com! Choose between receiving instant updates with the Real-Time Article Update, or a monthly summary with the Monthly Article Update.



Receive all the latest articles by email!

Receive Real-Time & Monthly WindowSecurity.com article updates in your mailbox. Enter your email below!
Click for Real-Time sample & Monthly sample

Become a WindowSecurity.com member!

Discuss your security issues with thousands of other network security experts. Click here to join!

Community Area

Log in | Register

Solution Center

Readers' Choice

Which is your preferred Network Antivirus solution?

Follow TechGenix on Twitter