menu
QAmmunity.org
Login
Register
My account
Edit my Profile
Private messages
My favorites
Register
Ask a Question
Questions
Unanswered
Tags
Categories
Ask a Question
What are the differences between a policy, a standard, and a practice? What are the three types of security policies? Where would each be used? What type of policy would be needed to guide use of the Web?
asked
Dec 2, 2021
81.0k
views
1
vote
What are the differences between a policy, a standard, and a practice? What are the three types of security policies? Where would each be used? What type of policy would be needed to guide use of the Web? E-mail? Office equipment for personal use?
Computers and Technology
college
Tuwanda
asked
by
Tuwanda
5.2k
points
answer
comment
share this
share
0 Comments
Please
log in
or
register
to add a comment.
Please
log in
or
register
to answer this question.
1
Answer
5
votes
Answer:
The difference between a policy, a standard and a practice is as follow:
Policy:
It can be defined as the written instructions that describe proper behavior.
Standard:
It can be defined as the detailed statement of what must be done to comply with policy.
Practice:
It can be defined as the examples of actions that would comply with policy.
The three types of security policies are:
Enterprise Information Sec. Policy (EISP) :
High level policy that sets the strategic direction, scope, and tone for the organization's security efforts.
Use:
It is used to support the mission, vision and direction of the organization and sets the strategic direction, scope and tone for all security efforts
Issue Specific Sec. Policy (ISSP) :
An organizational policy that provides detailed, targeted guidance to instruct all members of the organization in the use of a resource, such as one of its processes or technologies.
Use:
It is used to support routine operations and instructs employees on the proper use of these technologies and processes
System Specific Sec. Policy (SysSP):
Organizational policies that often function as standards or procedures to be used wen configuring or maintaining systems. SysSPs can be separated into two general groups-managerial guidance and technical specifications- but may be written as a single unified document.
Use:
It is used as a standard when configuring or maintaining systems.
ISSP policy would be needed to guide the use of the web, email and use of personal use of office equipment.
Yoano
answered
Dec 7, 2021
by
Yoano
5.3k
points
ask related question
comment
share this
0 Comments
Please
log in
or
register
to add a comment.
Ask a Question
Welcome to QAmmunity.org, where you can ask questions and receive answers from other members of our community.
5.8m
questions
7.5m
answers
Other Questions
A new information system is not considered in production until conversion is complete
a. STOP: What is a technology habit you practice today that you now realize will not help you to be successful? Explain why it’s important to STOP doing this right now.
Why might the government censor what its citizens see on the internet?
Flash drives cds external disks are all examples of storage (memory) devices
What is a spreadsheet program? A spreadsheet program is a computerized version of _________
Twitter
WhatsApp
Facebook
Reddit
LinkedIn
Email
Link Copied!
Copy
Search QAmmunity.org