QUESTION POSED ON: 07 June 2002
As part of a security team, we have developed a suite of information
security policies for the corporation. We are now in process of
developing standards for some of our platforms. What is
the real difference between policies and standards, and how detailed
should standards be? Are you able to provide any examples?
|