Principles of Information Security...

6th Edition
Michael E. Whitman + 1 other
Publisher: Cengage Learning
ISBN: 9781337102063
Chapter 4, Problem 9RQ
Textbook Problem

What are the differences between a policy, a standard, and a practice? What are the three types of security policies? Where would each be used? What type of policy would be needed to guide use of the Web? E-mail.? Office equipment for personal use?

Explanation of Solution

Difference between policy, standard and practice:

Policy Standard Practice
Policy is a plan used by an organization to transfer the commands from higher management to respective section. Standard is dissimilar from policy, these are further detailed than policies and are conformed by explanation of each step for an organization. Practices efficiently explain how to conform to policy.
It is a written document that contains all the exact rules or requirements that must be met by the workers. It is a systematic statement that gives information of needs of the members of an organization to do stick on to a policy. Practices are processes or methods used by an organization to achieve its objectives.
Policies are used to support the vision, mission and strategic planning. It is in the form of procedural-specific requirements or system-specific requirement. It is driven by standards and includes the detailed steps that are needed to meet the requirements of standards...

