5. Appendix B: Example of securing an internal IS and a hybrid IS
Securing an information system hosted in-house must take into account the risk analysis, which assesses the level of threat to the entity, and the resulting security requirements for each component of the IS (business applications, data, industrial processes, etc.).
In concrete terms, this means implementing several technical and organizational security functions, with the aim of protecting the information system at the "right level":
ISSP. The definition of an information systems security policy makes it possible to clearly formalize the entity's main security principles and rules, grouped by theme (IS operations, identity management, role definitions, etc.). It is generally accompanied by the drafting of charters for users and IS administrators, and by IS awareness campaigns for all the entity's players;
...
Exclusive to subscribers. 97% yet to be discovered!
Already subscribed? Log in!
Appendix B: Example of securing an internal IS and a hybrid IS
Article included in this offer
"Security of information systems"
(
86 articles
)
Updated and enriched with articles validated by our scientific committees
A set of exclusive tools to complement the resources
Bibliography
- (1) - Secrétariat général de la défense nationale - La défense en profondeur appliquée aux systèmes d'information. - Guide Version 1.1, ANSSI, juillet 2004. https://www.ssi.gouv.fr/defense-profondeur
- (2)...
Exclusive to subscribers. 97% yet to be discovered!
Already subscribed? Log in!