Curriculum development related to information security policies and procedures

  • Authors:
  • Allyson Mader;S. Srinivasan

  • Affiliations:
  • University of Louisville, Louisville, KY;University of Louisville, Louisville, KY

  • Venue:
  • InfoSecCD '05 Proceedings of the 2nd annual conference on Information security curriculum development
  • Year:
  • 2005

Quantified Score

Hi-index 0.00

Visualization

Abstract

Policies and procedures communicate and control access to information assets and other resources. Developing effective policies and procedures involves understanding the environment within which one is working. They should encompass multiple layers. The level of trust needed for various levels of the organization must be determined. Policies are developed for accomplishing the business objectives and the procedures then support how they will be enforced. Internal control is established through design of sound policies and procedures. Also discussed are concepts such as risk assessment, risk control, disaster recovery and business continuity. This paper describes these important topics that would be covered in an information security policies course.