Standards, Guidelines & Best Practices

As servers, workstations and personal computers are added to the network, the follow articles should be consulted to help guide
| What is the difference between Policies, Procedures, Guidelines, Standards, Principles, Best Practices and Frameworks? Tell me. |
|
What follows are resources promoted by management as a recommendation. Guidelines are developed by subject matter experts either locally or through external groups, vendors, or a combination. These best practices may develop into standards as they mature.
By following good security practices we can help others in the university community benefit from decreased risk. "Good neighbor" security practices help others for the common good. Technology should be reviewed for conformance to industry and university policies, practices, and guidelines prior to deployment rather than after a problem or incident. Members of the university community can help themselves and others by increasing the visibility and support for security within their department or workgroup.
UC Information Security Plan
Users
- Information Security in the Workplace
- Disabling Windows Messenger Service
- Email Attachments to Filter
- How To... Avoid Getting Hooked (Avoid Phishing)
- How To... Avoid Spyware
- How To... Choose a password
- How To... Fight Identity Theft
- How To... Fight Spam
- How To... Hacker-Proof your Computer
- How To... Lock Your Computer Account
- How To... Protect Your Laptop
- How To... Safely Trade In (Throw Away) Your Cell Phone
- How To... Sanitize Data or a Full Hard Disk
- How To... Shop (or conduct other business) online more safely
- Key Loggers
- Music, Video and Peer-to-Peer File Sharing
- Protecting Your Home Computer
- Protect yourself from security holes in old Java releases
- 10 Tips for Wireless Users
- Top Social Security Number Don'ts
Workstation
- CERT's Guideline: Windows 95/98
- Computer Compromise Remediation Checklist
- Email Attachments to Filter
- Guideline for Securing Windows XP Systems
- How To... Sanitize Data or a Full Hard Disk
- Protect yourself from security holes in old Java releases
- Remedies for Backdoor Programs
- Securing your Email Server agianst Spam (Spam Links)
- Securing your Email Server agianst Spam (Maps)
- Workstation Protection
- Windows Workstation Security: Problems, Solutions & Resources
Servers / Systems
- Securing Microsoft IIS WebServer
- CERT's Guideline: UNIX Configuration
- Credit Card Processing
- Guidelines for Securing Web-based Communications
- HIPAA Standards and Procedures Checklist
- How To... Sanitize Data or a Full Hard Disk
- Protect yourself from security holes in old Java releases
- SANS Top 20 Vulnerabilities
- Securing Linux Systems
- Securing Microsoft IIS Web Server
- Task Schedule for IT/InfoSec Administrators
- The W3 Security FAQ
Programmers
- Open Web Application Security Project (OWASP) - A worldwide free and open community focused on improving the security of application software. A very worthwhile reference for programmers. - OWASP local Chapter
Resources & References
For more information
Please review the InfoSec Standards Recommended by Governing Bodies |
|
|