{"id":112100,"date":"2021-03-16T16:23:53","date_gmt":"2021-03-16T10:53:53","guid":{"rendered":"https:\/\/www.vskills.in\/certification\/tutorial\/?page_id=112100"},"modified":"2024-04-12T14:31:45","modified_gmt":"2024-04-12T09:01:45","slug":"security-policy-and-isms","status":"publish","type":"page","link":"https:\/\/www.vskills.in\/certification\/tutorial\/security-policy-and-isms\/","title":{"rendered":"Security Policy and ISMS"},"content":{"rendered":"\n<p>A security policy is a document which lists plans to protect the physical and information technology (IT) assets and is continuously updated as technology and requirements change. It may include an acceptable use policy, a description of how to educate employees, security measurements to enforce and a procedure for evaluating the effectiveness of the security policy to ensure that necessary corrections will be made.<\/p>\n\n\n\n<p>An information security management system (ISMS) is a collection of policies and procedures for management of crucial data. The aim is to minimize risk and ensure business continuity by pro-actively limiting the impact of a security and data breach. An ISMS is usually focused on employee behavior and processes as well as particular type of data, such as customer data. ISO 27001 is a specification for creating an ISMS which does not mandate specific actions, but includes suggestions for documentation, internal audits, continual improvement, and corrective and preventive action.<\/p>\n\n\n\n<p>Any good system of governance should be resilient to attacks by frauds, inadvertent virus, and a variety of motivated cyber crimes through unauthorized access and even to a nation-sponsored cyber war and in the scenarios of disaster and warfare.<\/p>\n\n\n\n<p>With every new application, newer vulnerabilities crop up, posing immense challenges to those who are mandated to protect the IT assets. E-Government security requirements can be studied by examining the overall process, beginning with the citizens end and ending with the e-Gov server. The assets that must be protected to ensure secure e-Gov include client computers, the messages traveling on the communication channel, and the Web and e-Government servers \u2013 including any hardware attached to the servers.<\/p>\n\n\n\n<p><strong>Need<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Adversaries are capable of launching harmful attacks on IT systems, networks, and information assets.<\/li><li>Enterprise concerns have been heightened by increasingly sophisticated hacker attacks and identity thefts, warnings of cyber terrorism, and the pervasiveness of IT uses.<\/li><li>A breach of security could lead to lost opportunities, defamation, loss of goodwill, repudiation loss, financial loss , transactional loss , loss of citizens confidence and many others<\/li><li>A defacement \/ hacking of a public website can cause loss of reputation<\/li><li>Vital data i.e. databases can be lost if unauthorized entry is not checked properly<\/li><li>A e-procurement website stops functioning all of a sudden<\/li><li>A disaster strikes and the processes gets standstill<\/li><li>Repudiation loss &#8211; One party of a transaction denies having received a transaction nor can the other party deny having sent a transaction.<\/li><\/ul>\n\n\n\n<p><strong>Security Measures<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Data Center Security &#8211; Use Firewalls<\/li><li>Web-site Security \u2013 Use Anti-virus and Anti-phishing tools<\/li><li>Physical Office Security \u2013 Implement restricted accessibility and do regular checks &amp; reviews<\/li><li>Secured Working Processes &#8211; Planning long-term solutions and implementing the process-Cycle to be followed (PDCA Cycle \u2013 Plan, Do, Check &amp; Assess Cycle )<\/li><\/ul>\n\n\n\n<p><strong>Issues in implementing security<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Letting vendors define \u201cgood security\u201d<\/li><li>Underestimating the required security expertise<\/li><li>Assigning untrained people to maintain security<\/li><li>Relying primarily on a firewall.<\/li><li>Firstly think of budget concerns, neglecting the value of their information and organizational reputations.<\/li><li>Authorizing reactive, short-term fixes so problems re-emerge rapidly.<\/li><li>Lack of internal Technical capacities<\/li><li>Loopholes in the applications and databases<\/li><li>Exit management<\/li><li>Complex e-Governance Projects<\/li><li>High performance &amp; response time<\/li><li>High Security desired on operations but not a top priority to start with<\/li><li>Multiple Legacy Environments<\/li><li>Low priority for implementation of Security Standards<\/li><li>Low priority for implementation of suitable access controls and authorization<\/li><li>Inadequate preparation of RFPs which captures all the security requirements<\/li><\/ul>\n","protected":false},"excerpt":{"rendered":"<p>A security policy is a document which lists plans to protect the physical and information technology (IT) assets and is continuously updated as technology and requirements change. It may include an acceptable use policy, a description of how to educate employees, security measurements to enforce and a procedure for evaluating the effectiveness of the security&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-112100","page","type-page","status-publish","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Security Policy and ISMS - Tutorial<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.vskills.in\/certification\/tutorial\/security-policy-and-isms\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Security Policy and ISMS - Tutorial\" \/>\n<meta property=\"og:description\" content=\"A security policy is a document which lists plans to protect the physical and information technology (IT) assets and is continuously updated as technology and requirements change. It may include an acceptable use policy, a description of how to educate employees, security measurements to enforce and a procedure for evaluating the effectiveness of the security...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.vskills.in\/certification\/tutorial\/security-policy-and-isms\/\" \/>\n<meta property=\"og:site_name\" content=\"Tutorial\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/vskills.in\/\" \/>\n<meta property=\"article:modified_time\" content=\"2024-04-12T09:01:45+00:00\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.vskills.in\/certification\/tutorial\/security-policy-and-isms\/\",\"url\":\"https:\/\/www.vskills.in\/certification\/tutorial\/security-policy-and-isms\/\",\"name\":\"Security Policy and ISMS - Tutorial\",\"isPartOf\":{\"@id\":\"https:\/\/www.vskills.in\/certification\/tutorial\/#website\"},\"datePublished\":\"2021-03-16T10:53:53+00:00\",\"dateModified\":\"2024-04-12T09:01:45+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.vskills.in\/certification\/tutorial\/security-policy-and-isms\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.vskills.in\/certification\/tutorial\/security-policy-and-isms\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.vskills.in\/certification\/tutorial\/security-policy-and-isms\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.vskills.in\/certification\/tutorial\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security Policy and ISMS\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.vskills.in\/certification\/tutorial\/#website\",\"url\":\"https:\/\/www.vskills.in\/certification\/tutorial\/\",\"name\":\"Tutorial\",\"description\":\"Vskills - A initiative in elearning and certification\",\"publisher\":{\"@id\":\"https:\/\/www.vskills.in\/certification\/tutorial\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.vskills.in\/certification\/tutorial\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.vskills.in\/certification\/tutorial\/#organization\",\"name\":\"Vskills\",\"url\":\"https:\/\/www.vskills.in\/certification\/tutorial\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.vskills.in\/certification\/tutorial\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.vskills.in\/certification\/tutorial\/wp-content\/uploads\/2017\/07\/vskills-min-logo.jpg\",\"contentUrl\":\"https:\/\/www.vskills.in\/certification\/tutorial\/wp-content\/uploads\/2017\/07\/vskills-min-logo.jpg\",\"width\":73,\"height\":55,\"caption\":\"Vskills\"},\"image\":{\"@id\":\"https:\/\/www.vskills.in\/certification\/tutorial\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/vskills.in\/\",\"https:\/\/x.com\/vskills_in\",\"https:\/\/www.linkedin.com\/company-beta\/1371554\/\",\"https:\/\/www.youtube.com\/channel\/UCMWnscxPwRF_PqXo9B7q_Tw\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Security Policy and ISMS - Tutorial","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.vskills.in\/certification\/tutorial\/security-policy-and-isms\/","og_locale":"en_US","og_type":"article","og_title":"Security Policy and ISMS - Tutorial","og_description":"A security policy is a document which lists plans to protect the physical and information technology (IT) assets and is continuously updated as technology and requirements change. It may include an acceptable use policy, a description of how to educate employees, security measurements to enforce and a procedure for evaluating the effectiveness of the security...","og_url":"https:\/\/www.vskills.in\/certification\/tutorial\/security-policy-and-isms\/","og_site_name":"Tutorial","article_publisher":"https:\/\/www.facebook.com\/vskills.in\/","article_modified_time":"2024-04-12T09:01:45+00:00","twitter_misc":{"Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.vskills.in\/certification\/tutorial\/security-policy-and-isms\/","url":"https:\/\/www.vskills.in\/certification\/tutorial\/security-policy-and-isms\/","name":"Security Policy and ISMS - Tutorial","isPartOf":{"@id":"https:\/\/www.vskills.in\/certification\/tutorial\/#website"},"datePublished":"2021-03-16T10:53:53+00:00","dateModified":"2024-04-12T09:01:45+00:00","breadcrumb":{"@id":"https:\/\/www.vskills.in\/certification\/tutorial\/security-policy-and-isms\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.vskills.in\/certification\/tutorial\/security-policy-and-isms\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.vskills.in\/certification\/tutorial\/security-policy-and-isms\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.vskills.in\/certification\/tutorial\/"},{"@type":"ListItem","position":2,"name":"Security Policy and ISMS"}]},{"@type":"WebSite","@id":"https:\/\/www.vskills.in\/certification\/tutorial\/#website","url":"https:\/\/www.vskills.in\/certification\/tutorial\/","name":"Tutorial","description":"Vskills - A initiative in elearning and certification","publisher":{"@id":"https:\/\/www.vskills.in\/certification\/tutorial\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.vskills.in\/certification\/tutorial\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.vskills.in\/certification\/tutorial\/#organization","name":"Vskills","url":"https:\/\/www.vskills.in\/certification\/tutorial\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.vskills.in\/certification\/tutorial\/#\/schema\/logo\/image\/","url":"https:\/\/www.vskills.in\/certification\/tutorial\/wp-content\/uploads\/2017\/07\/vskills-min-logo.jpg","contentUrl":"https:\/\/www.vskills.in\/certification\/tutorial\/wp-content\/uploads\/2017\/07\/vskills-min-logo.jpg","width":73,"height":55,"caption":"Vskills"},"image":{"@id":"https:\/\/www.vskills.in\/certification\/tutorial\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/vskills.in\/","https:\/\/x.com\/vskills_in","https:\/\/www.linkedin.com\/company-beta\/1371554\/","https:\/\/www.youtube.com\/channel\/UCMWnscxPwRF_PqXo9B7q_Tw"]}]}},"_links":{"self":[{"href":"https:\/\/www.vskills.in\/certification\/tutorial\/wp-json\/wp\/v2\/pages\/112100","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.vskills.in\/certification\/tutorial\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.vskills.in\/certification\/tutorial\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.vskills.in\/certification\/tutorial\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.vskills.in\/certification\/tutorial\/wp-json\/wp\/v2\/comments?post=112100"}],"version-history":[{"count":1,"href":"https:\/\/www.vskills.in\/certification\/tutorial\/wp-json\/wp\/v2\/pages\/112100\/revisions"}],"predecessor-version":[{"id":112101,"href":"https:\/\/www.vskills.in\/certification\/tutorial\/wp-json\/wp\/v2\/pages\/112100\/revisions\/112101"}],"wp:attachment":[{"href":"https:\/\/www.vskills.in\/certification\/tutorial\/wp-json\/wp\/v2\/media?parent=112100"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.vskills.in\/certification\/tutorial\/wp-json\/wp\/v2\/categories?post=112100"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.vskills.in\/certification\/tutorial\/wp-json\/wp\/v2\/tags?post=112100"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}