According to NIST, security policies define the objectives and constraints for the organization’s security program. Policies are created at several levels, ranging from an organization or corporate policy to specific operational constraints. In general, policies provide answers to the questions “what” and “why” without dealing with “how.” Policies are normally stated in terms that are technology-independent. NIST SP 800-82 Rev 2.
Before you begin, be sure to review the following resources: (Files Uploaded below)
Different criteria were defined for evaluating information security management standards such as the scope of application, type of evidence as described in the first article. Other researchers set different criteria such as access control, acquisition, and maintenance, assets management etc.
Select two IS standards, analyze them, and compare how these guidelines are validated and how they can be applied.
Complete this assignment in a Word Document. Your paper should be 2-3 pages in length (not including the Title, Abstract, and Reference List pages), and in APA format. Submit your assignment following the below upload instructions.
Last Completed Projects
| topic title | academic level | Writer | delivered |
|---|
