Skip to content
BOL Conferences
Thread Options
#82578 - 05/23/03 07:00 PM Information Security Program/Policy
jjjeepman2003 Offline
New Poster
jjjeepman2003
Joined: Apr 2003
Posts: 21
Louisiana
Who in the bank should be responsible for writing the Information Security Program/Policy? I have received conflicting viewpoints as to whom should write it and keep it updated.

Return to Top
Security - PUBLIC
#82579 - 05/23/03 07:28 PM Re: Information Security Program/Policy
Anonymous
Unregistered

I think this will be different depending on the size and complexity of your Bank. Here are a couple of things to keep in mind.

Within the Information Security Program (ISP), the Bank will designate an Information Security Officer(ISO).

The ISO should be most closely attached to the ISP as the ISO is responsible for enforcing the policies and procedures of the ISP, as well as reviewing changes, additions, deletions to the ISP (among many other things).

The ISO could be the lead person in creating the ISP, but the ISO will probably need help from other areas.

There may be technical issues involved in authoring the ISP where the IT folks need to get involved.

There may be legal issues involved in authoring the ISP where counsel needs to be involved.

The internal auditor should not author, but should have input to the creation of the ISP.

Hope that helps.


Return to Top
#82580 - 05/24/03 02:34 PM Re: Information Security Program/Policy
Lawrence T. Levine Offline
Junior Member
Lawrence T. Levine
Joined: May 2003
Posts: 37
Troy, VA
For what it's worth - Once you figure out who's going to have ownership have them have a look at...

http://www.sans.org/resources/policies/#template
_________________________
Lawrence T. Levine Managing Director SecurePipe, Inc. Direct: 4342932454 www.SecurePipe.com

Return to Top
#82581 - 05/26/03 12:46 PM Re: Information Security Program/Policy
Dana Turner Offline

Platinum Poster
Dana Turner
Joined: Dec 2000
Posts: 543
Pipe Creek TX - U.S.
jjjeepman2003:

Please remember that -- regardless of who authors the program -- it should be tightly integrated with the institution's main Security Program. The Security Officer should be responsible for conducting all investigations and he/she will likely need considerable assistance if IT issues are involved.

Because evidence of a crime or a policy violation is crucial, also please insure that your Information Security Program contains appropriate techniques for identifying, collecting and preserving both physical and electronic evidence items.
_________________________
Celebrating 42 entertaining years of crime . . .
danaturner@email.com

Return to Top
#82582 - 05/27/03 03:13 PM Re: Information Security Program/Policy
MackenzieS Offline
Diamond Poster
MackenzieS
Joined: Jul 2002
Posts: 1,722
Oklahoma
We are a small bank ($130M) and we designated a lender as the ISO. At the time he was knowledgeable on many of the aspects of security througout the bank, he sits on the IT committee, and he excels at writing policies. It may seem like an unlikely candidate but he was best suited for us. He does work closely with all departments of the bank to perform risk assessments, perfom training, and monitor any changes that may require an update to the policy.

Return to Top

Moderator:  Andy_Z