Skip to main content
T.Z.A.S.P.MANDAL’S<br />PRAGATI COLLEGE OF ARTS, COMMERCE, AND SCIENCE<br />A CASE STUDY REPORT ON<br />Security Policy<br />PRESENTED ON:28th  AUGUST, 2010<br />ABLY GUIDED BY Madam Snehal Borle<br />T.Y.B.Sc. (IT)<br />SUBMITTED BY<br />Ms. Ashwini Vaykole            -       Roll No.04
Ms. Ashwini Godage            -       Roll No. 02T.Z.A.S.P.MANDAL’S<br />PRAGATI COLLEGE OF ARTS, COMMERCE, AND SCIENCE<br />T.Y.B.Sc. (IT)<br />CERTIFICATE<br />This is to certify that Ms. Ashwini Godage (Roll No.02)
Ms. Ashwini Vaykole (Roll No. 04) has completed the case study of Internet Security satisfactorily during academic year 2010-11.
Date: 28th  August, 2010
Professor-in-charge
(B.SC.IT)INDEX<br />Sr. No.ContentsPage No.1.Security42.Need of security63.Security Policy74.Purpose of Security Policy85.Characteristic of Security Policy106Strategies of Security Policy117.Components of Security Policy158.Person involved in framing Security Policy189.Steps in Security Policy1910.Ethics of Security Policy22<br />Security<br />In simple words security means safety and protection. In technical terms security means the protection of data, networks and computing power. The protection of data information security is the most important. The protection of network is important to prevent loss of server resources as well as to protect the network from being used for illegal purposes.<br />Need of security<br />The internet has made a tremendous impact on security. While it has many good aspects, there are many bad things that can come of this powerful communications tool. These problems included concerns about the validity and appropriateness of the material found online .when computer application were developed to handle financial and personal data real need for security came into picture. Two typical example of security mechanism are:<br />Provide a user_id and password to every user, and use that information to authenticate a user<br />Encode information stored in the database in some fashion, so that it is not visible to users who do not have the right permission.<br />We need security for the following purpose<br />To protect our data, files or folders<br />To protect our resources example: hardware, software etc.<br />To protect e-commerce, transaction, information, user id, password, pin<br />To protect website from getting blocked any attack as DOS (Denel Of Service)<br />To protect IP address<br />To protect e-mails<br />To protect incoming packets so that no virus/worms comes in<br />To protect outgoing packets so that secrets does not leak out<br />Security policy<br />In simple words a security policy in terms of computer systems defines what is secure and what is unsecured.
OR
In technical terms a security policy is a set of formal statements of the rules by which people that are given access to organization’s technology and information must abide.OR<br />A Security policy defines the overall security and risk control objectives that an organization endorses.
OR
A security policy is a formal statement of the rules through which people are given access to an organization’s technology, system and information assets. OR<br />The security policy defines what business and security goals and objectives management desires, but not how these solutions are engineered and implemented.
A security policy should be economically feasible, understandable, realistic, consistent, procedurally tolerable, and also provide reasonable protection relative to the stated goals and objectives of management.
OR
A security policy is the primary way in which management’s expectations for security are translated into specific, measurable, and testable goals and objectives. Security Policy Goals<br />The goal of the security policy is to translate, clarify and communicate management’s position on security as defined in high-level security principles. The security policies act as a bridge between these management objectives and specific security requirements.<br />Purposes of a Security Policy<br />The primary purpose of a security policy is to inform users, staff, and managers of those essential requirements for protecting various assets including people, hardware, and software resources, and data assets. The policy should specify the mechanisms through which these requirements can be met. Another purpose is to provide a baseline from which to acquire, configure, and audit computer systems and networks for compliance with the policy. This also allows for the subsequent development of operational procedures, the establishment of access control rules and various application, system, network, and physical controls and parameters.<br />To inform  all of their obligatory(mandatory) requirements for protecting technology and information assets
The policy should specify the mechanism through which these requirements can be met
To provide a baseline from which to acquire, configure and audit computer systems and networks for compliance with the policy.An Appropriate Use Policy (AUP) may also be part of a security policy<br />It should spell out what users shall not do on the various components of the system, including the type of traffic allowed on the networks.
The AUP should be as explicit as possible to avoid ambiguity or misunderstanding. The characteristics of good security policies are<br />They must be implementable through system administration procedures, publishing of acceptable use guidelines, or other appropriate methods.
 They must be enforceable with security tools, where appropriate, and with sanctions, where actual prevention is not technically feasible.
They must clearly define the areas of responsibility for the users, administrators, and management.
They must be documented, distributed, and communicated.Strategies of security policy<br />Before you can decide on how to safeguard your network, you must identify what level of security you require, i.e. whether you want a lower, medium or a very security. (For example, famous personalities will require more life security – Y level, Z level etc than a common man) once this job is done, you are ready to make your strategies to secure your network. The various strategies used further to secure the network will include the following<br />Host securityAuthentication of userChoosing good password & protecting themUsing firewall & proxy serversDMZ’sMaking use of encryption techniquesStrategies of <br />Security<br /> Policy<br />Host security
Securing the prime, host machines by logically isolating them. In most situations, the network is not the resource at risk rather; it is the endpoint of the network that is threatened.
Usually, there are bugs in the program for networks or in the administrator of the system.
It is this way with computer security; the attacker just has to trust them in some fashion. It might be therefore a major risk that the intruder can compromise the entire system.
He will now be able to attack other systems, either by taking over root, and thence the system’s identity, or by taking over some user account. This is called transitive trust.