information security program
infoturbekava
olemus
ISACA Glossary:
tegevusnõuetel ja riskianalüüsil põhinev
kõigi tehniliste, käituslike ja protseduuriliste
meetmete ja haldusstruktuuride kombinatsioon,
mida rakendatakse teabe
konfidentsiaalsuse, tervikluse ja käideldavuse tagamiseks
=
the overall combination of technical, operational and procedural measures and management structures implemented to provide for the confidentiality, integrity and availability of information based on business requirements and riskanalysis
ülevaateid
https://terranovasecurity.com/defining-an-information-security-program/
https://iparchitects.com/wp-content/uploads/2016/07/Key-Elements-of-an-Information-Security-Program-ISACA-Member-Journal-January-2005.pdf
https://www.inkit.com/blog/information-security-lifecycle
https://www.sciencedirect.com/book/9780128020425/building-a-practical-information-security-program
https://identitymanagementinstitute.org/information-security-program-implementation-guide/
näiteid
http://www.gcada.org/pdf/Sample%20Information%20Security%20Procedure%20(safeguard%20policy).pdf
https://uncw.edu/itsd/documents/informationsecurityprogram.pdf
https://strakecyber.com/wp-content/uploads/2018/12/Example-Information-Security-Plan-ISP.pdf