Defining a Security Policy?
A security policy can be as simple as an acceptable use policy for the network resources, or it can be several hundred pages in length and detail every element of connectivity and associated policies. According to the Site Security Handbook (RFC 2196), "A security policy is a formal statement of rules by which people who are given access to an organization's technology and information assets must abide." It further states, "A security policy is essentially a document summarizing how the corporation will use and protect its computer and network resources." A security policy is actually the center of the security wheel that is explained in more detail later in this chapter.