Security: Policies, Plans, and Procedures - Paiet/Tech-Journal-for-Everything GitHub Wiki
Standard operating procedure
Agreement types
BPA
Sets the terms and conditions for the partnership
Establishes the responsibilities of each business partners
Can define
Duration of the partnership
Decision-making process
Liability
SLA
Contract between a service provider and an end user or business
Defines what the acceptable level of performance is
Can define
Quality of service
Availability
Responsibilities
Usage statistics
Plans for addressing downtime
Outages
Service Credits
Compensation
ISA
NIST SP 800-47
Defines technical and security requirements (VPN, authentication mechanisms, encryption) for establishing, operating and maintaining a connection between two organizations
MOU/MOA
Defines responsibilities of two parties or what the parties will contribute to a partnership. It defines the details of cooperation between two companies that have a common goal.
Not legal binding
Personnel management
Mandatory vacations
Seek to uncover malicious activities of employees
Five consecutive workdays
Job rotation
Gives employees a larger skill set
Helps with cross-training
Ensures that not a single employee retains
Separation of duties
Having more than one person to complete a task
Restricting the power a single person has
Clean desk
A clean desk policy can be an import tool to ensure that all sensitive/confidential materials removed from an end user workspace and locked away