New and Updated Sample Security Policy Templates
Information Security Policies Made Easy, Version 14 contains these updates:
Security Policy Template Library Update for the Common Policy Library (CPL)
ISPME Version 14 includes over 60 new security policy samples mapped to the Common Policy Library (CPL). The CPL is a set of common information security policies that enable organizations to comply with multiple data protection laws including ISO 27002, PCI-DSS and HIPAA/HiTECH.
Areas of focus for this update include Privileged Account Management, Third Party Security and Data Privacy Governance for the General Data Protection Regulation (GDPR). All sample security policies are mapped to common frameworks such as ISO 27002, HIPAA, PCI-DSS and HIPAA/HiTECH.
Updated Security Policy Mappings
Version 14 contains updated mappings between the ISPME policy documents and leading regulatory frameworks. Mappings include:
- ISO 27002:2013
- NIST 800-53 Revision 5
- PCI-DSS 3.2
- US Cyber Security Framework V 1.1
- HIPAA/HiTECH
- FFIEC (Financial Services)
- New York State DFS
40 Updated “Ready-to-Go” Sample Security Policy Templates
Version 14 now contains 40 complete, pre-written sample information policy documents in MS-Word format, including:
- Sample High-Level Information Security Policy
- Sample IT Risk Management Security Policy
- Sample Information Security Program Policy
- Sample Information Security Organization Policy
- Sample Audit and Compliance Assessment Policy
- Sample Asset Management Policy
- Sample Acceptable Use of Assets Policy
- Sample Acceptable Use of Social Networking Policy
- Sample Cloud Computing Security Policy
- Sample Mobile Computing Security Policy
- Sample Remote Working (Telecommuting) Security Policy
- Sample Personally Owned Devices (BYOD) Security Policy
- Sample Information Classification Policy
- Sample Information Exchange Policy
- Sample Information Storage and Retention Policy
- Sample Information and Media Disposal Policy
- Sample Third Party Security Management Policy
- Sample Personnel Security Management Policy
- Sample Security Awareness and Training Policy
- Sample Access Control Security Policy
- Sample Account and Privilege Management Policy
- Sample Remote Access Security Policy
- Sample Network Security Management Policy
- Sample Firewall Security Policy
- Sample Wireless Network Security Policy
- Sample Physical Access Security Policy
- Sample Data Center Security Policy
- Sample IT Operations Security Policy
- Sample System Configuration Management Policy
- Sample Change Management Policy
- Sample Malicious Software Management Policy
- Sample Encryption and Key Management Policy
- Sample Application Development Security Policy
- Sample Security Incident Response Policy
- Sample Data Breach Response Policy
- Sample Backup and Recovery Policy
- Sample IT Business Continuity Policy
- Sample Log Management and Monitoring Policy
- Sample Customer Data Privacy Policy
- Sample Privacy Governance Policy
New Policy Compliance Tools
The updated Master Policy List allows easy gap-analysis for your existing policies. A newly-added Best Practices Policy Template enables your organization to easily reference existing policies to compliance frameworks such as HIPAA, COBIT or PCI-DSS.
- Information Security Policy Compliance Agreement
- Management Risk Acceptance Memo
- Two-Page Simple Non-Disclosure Agreement
- Sample Data Classification Quick Reference Table
- Sample Identity Token Responsibility Statement
- Sample Employment Termination Procedure
- Sample Security Incident Reporting Form
- Sample Information Security Policy Glossary
60+ New Information Security Policy Sample Statements
Version 14 contains 60+ additional pre-written information security policy statements with expert commentary covering the latest security threats and technologies, including:
- Audit Logging
- BYOD (Bring Your Own Device)
- Cloud Computing
- Corporate governance
- Data Breaches Response
- Disposal of equipment
- Email security including phishing
- Instant messaging
- Information Security Coordination
- USB storage
- Mobile device security
- Personnel Security
- Physical Security
- Risk Management
- Social Networking
- Supply Chain Security
- Security Department coordination
- Remote Access and Teleworking
- FAX and office machine security
- Third-Party Software Development
- Third-Party Service Management
- Third-Party Information Disclosure
- And much more…
Easy Policy Subscription Updates
Upgrade easily from previous versions to the new ComplianceShield Subscription Service and keep your security policies updated against the latest threats.