This paper describes a general framework for developing an organization's Internet security policy. A model of Internet security risks for an Internet user organization is proposed; the framework utilizes this model, as well as considering important holistic issues, in order to develop the user organization's Internet security policy. A hierarchy of subpolicies for the Internet security policy is also suggested. This paper presents the results of one phase of a wider investigation into Internet security policy.
Citation:
Sharman Lichtenstein, "Developing Internet Security Policy for Organizations," hicss, vol. 4, pp.350, 30th Hawaii International Conference on System Sciences (HICSS) Volume 4: Information Systems Track - Internet and the Digital Economy, 1997