Term:Information Security Policy

From FISMApedia
Jump to: navigation, search

CNSSI 4009

Information Security Policy - Aggregate of directives, regulations, rules, and practices that prescribe how an organization manages, protects, and distributes information.

NIST IR 7298

Information Security Policy - Aggregate of directives, regulations, rules, and practices that prescribes how an organization manages, protects, and distributes information. SOURCE: SP 800-53; CNSSI-4009

NIST IR 7328 Draft

Information Security Policy - Aggregate of directives, regulations, rules, and practices that prescribes how an organization manages, protects, and distributes information. [CNSS Inst. 4009]

NIST SP 800-18r1

Information Security Policy - Aggregate of directives, regulations, rules, and practices that prescribes how an organization manages, protects, and distributes information. [CNSS Inst. 4009]

NIST SP 800-37r1 Draft

Information Security Policy - Aggregate of directives, regulations, rules, and practices that prescribes how an organization manages, protects, and distributes information. [CNSS Inst. 4009]

NIST SP 800-37

Information Security Policy - Aggregate of directives, regulations, rules, and practices that prescribes how an organization manages, protects, and distributes information. [CNSS Inst. 4009]

NIST SP 800-39 Draft 2

Information Security Policy - Aggregate of directives, regulations, rules, and practices that prescribes how an organization manages, protects, and distributes information. [CNSS Inst. 4009]

NIST SP 800-53A

Information Security Policy - Aggregate of directives, regulations, rules, and practices that prescribes how an organization manages, protects, and distributes information. [CNSS Inst. 4009]

NIST SP 800-53r1

Information Security Policy - Aggregate of directives, regulations, rules, and practices that prescribes how an organization manages, protects, and distributes information.

NIST SP 800-53r2

Information Security Policy - Aggregate of directives, regulations, rules, and practices that prescribes how an organization manages, protects, and distributes information. [CNSS Inst. 4009]

NIST SP 800-53r3

Information Security Policy - Aggregate of directives, regulations, rules, and practices that prescribes how an organization manages, protects, and distributes information. [CNSSI 4009]

NSTISSI 1000

Information Security Policy - The aggregate of directives, regulations, rules, and practices that regulate how an organization manages, protects, and distributes information. For example, the information security policy for financial data processed on departmental systems can be contained in Public Law, Executive Orders, departmental directives, and local regulations. The information security policy lists all the security requirements applicable to specific information.