  |
Incident Response Policy - http://www.yale.edu/ppdev/policy/5143/5143.pdf
Yale University's policy regarding assessing IT security incidents, forming response teams and responding. |
  |
Information Security Policy - http://www.obfs.uillinois.edu/manual/central_p/sec19-5.html
An information security policy from the University of Illinois. |
  |
Password Policy - http://www.umflint.edu/its/units/initiatives/publicity/password.htm
A password policy presented in the form of a series of security awareness posters. "Passwords are like underwear ..." |
  |
Use of Electronic Mail - https://www.cusys.edu/policies/policies/IT_Email.html
Policy from the University of Colorado on the use of, access to, and disclosure of electronic mail. |
  |
Backup Policy - http://its.uncg.edu/Policy_Manual/Computer_Backup/
Sample policy from the University of North Carolina requires daily, weekly and monthly backups (sometimes known as 'grandfather, father, son'). |
  |
Information Security Policy - http://www.ccrg.ox.ac.uk/datasets/policystatement.htm
High-level information security policy statement for the Childhood Cancer Research Group at Oxford University. |
  |
HSPD-12 Privacy Policy - http://www.whitehouse.gov/omb/memoranda/fy2006/m06-06_att.doc
Sample privacy policy including Privacy Act systems of records notices, Privacy Act statements and a privacy impact assessment, designed to satisfy the requirements of HSPD-12 “Policy for a Common Identification Standard for Federal Employees and Contractors” |
  |
IT Security Policy - http://www.enterprise-ireland.com/ebusinesssite/guides/internal_security/internal_security_index.asp
IT security policy example/how-to guide from Enterprise Ireland. |
  |
Network Security Policy Guide - http://www.watchguard.com/docs/whitepaper/securitypolicy_wp.pdf
Watchguard's guide to creating an overarching network information security policy, supported by subsidiary policies. |
  |
Disaster Recovery Policy - http://www.templatezone.com/pdfs/Disaster-Recovery-policy.pdf
Basic DR policy in just over one side. |
  |
Holistic Operational Security Readiness Evaluation - http://www.lazarusalliance.com/horsewiki/index.php/Documents
Collaborative open project building a library of sample information security policies, supporting standards and other documents through a wiki. |
  |
Personnel Security Policy - http://www.datasecuritypolicies.com/wp-content/uploads/2007/04/generic-personnel-security-policy.pdf
Example policy covering pre-employment screening, security policy training etc. |
  |
Information Security Policy - http://www.pdfku.com/download-pdf-828.html
High level security policy/guideline from the Department of Health and Human Resources. |
  |
CSPO Tools Inc. - http://www.cspotools.com
Information security policies, some of which are available without charge as PDF files or for an annual subscription as MS Word files, along with additional content. |
  |
ISMS Policy - http://www.ricoh.ca/pdfs/ISMS%20Policy%20Statement.pdf
A high level (single page) policy statement from Ricoh, supporting their Information Security Management System. |
 |
Privacy Policy - http://www.graduate.norwich.edu/privacy_policy.php
Concise policy (just 3 paragraphs) published by the School of Graduate Studies at Norwich University. |
 |
Ethics Policy - http://www.spirent.com/about/technology.cfm?media=7&ws=324&ss=177
Ethical behavior underpins all procedural security controls. This ethics policy from Spirent is a useful model. |
 |
Resource Utilization Policy - http://www.tess-llc.com/Resource Utilization PolicyV4.pdf
Policy template by Walt Kobus defines requirements for resilience, redundancy and fault tolerance in information systems. |
 |
Information Security Policies - http://www.gcio.nsw.gov.au/products-and-services/policies-guidelines/InformationSecurityGuidelineV1.1.pdf/at_download/file
111-page security policy manual from the Australian New South Wales Department of Commerce, based on ISO/IEC 27001. |
 |
Government Security Policy - http://www.security.govt.nz/sigs/sigs.zip
The New Zealand Government's information security policy, based on the 2000 version of ISO/IEC 17799. [ZIP file containing PDF and MS Word versions] |