<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>DataSecurityPolicies.com &#187; Authentication Policy</title>
	<atom:link href="http://www.datasecuritypolicies.com/category/security-policies/authentication-policy/feed" rel="self" type="application/rss+xml" />
	<link>http://www.datasecuritypolicies.com</link>
	<description></description>
	<lastBuildDate>Fri, 07 Nov 2008 03:21:37 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Identification and Authentication Policy</title>
		<link>http://www.datasecuritypolicies.com/identification-and-authentication-policy</link>
		<comments>http://www.datasecuritypolicies.com/identification-and-authentication-policy#comments</comments>
		<pubDate>Tue, 20 Nov 2007 00:12:54 +0000</pubDate>
		<dc:creator>Marc</dc:creator>
				<category><![CDATA[Authentication Policy]]></category>
		<category><![CDATA[Security Policies]]></category>
		<category><![CDATA[Data Security Policy]]></category>
		<category><![CDATA[Security Policy]]></category>

		<guid isPermaLink="false">http://www.datasecuritypolicies.com/identification-and-authentication-policy</guid>
		<description><![CDATA[Walter Kobus at TESS (http://www.tess-llc.com/) has made available his Identification and Authentication Policy here. His policy covers the key elements required in any Authentication Policy. Here&#8217;s an excerpt: Policy Access to the [ORGANIZATION]’s information assets will be granted on different levels, based on the business rules established by data owner’s of that information, for an authorized [...]]]></description>
			<content:encoded><![CDATA[<p>Walter Kobus at TESS (<a href="http://www.tess-llc.com/">http://www.tess-llc.com/</a>) has made available his Identification and Authentication Policy <a href="http://www.tess-llc.com/Identification%20&amp;%20Authentication%20PolicyV4.pdf">here</a>.</p>
<p>His policy covers the key elements required in any Authentication Policy. Here&#8217;s an excerpt:</p>
<blockquote><p><strong>Policy<br />
</strong>Access to the [ORGANIZATION]’s information assets will be granted on different levels, based on the business rules established by data owner’s of that information, for an authorized user or entity to create, read, update, delete or transmit that information. Users will be provided access based on the concept of “least privilege.” Access will be managed and controlled  through discretionary access controls, identification and authentication, and audit trails.</p>
<p>Use of the [ORGANIZATION]’s information assets shall be restricted and shall be allowed only as necessary to support authorized business activities. The business rules currently in effect in conjunction with the [ORGANIZATION]’s user-based access controls shall be reviewed for<br />
adequate security level access and protection, and may serve as the foundation for establishing compliance with this policy.</p>
<p>Any effort to circumvent the [ORGANIZATION]’s information security mechanisms to gain access or to exploit any known or unknown vulnerabilities shall be perceived as a security incident, and shall be handled in accordance with established incident reporting guidelines and/or<br />
appropriate human resources policies and procedures.</p>
<p>All of the [ORGANIZATION] information is considered an asset and is protected, in all of its forms, from accidental or intentional but unauthorized, disclosure (confidentiality), modification or destruction (integrity), or the inability to process that information (availability).</p></blockquote>
<p>Walter requires a $5 fee for using or adapting his copyrighted policy. That&#8217;s a bargain in my opinion.</p>
<p>Check it out!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.datasecuritypolicies.com/identification-and-authentication-policy/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Authentication Policy</title>
		<link>http://www.datasecuritypolicies.com/authentication-policy</link>
		<comments>http://www.datasecuritypolicies.com/authentication-policy#comments</comments>
		<pubDate>Thu, 15 Nov 2007 22:28:08 +0000</pubDate>
		<dc:creator>Marc</dc:creator>
				<category><![CDATA[Authentication Policy]]></category>
		<category><![CDATA[Security Policies]]></category>
		<category><![CDATA[Data Security Policy]]></category>
		<category><![CDATA[Security Policy]]></category>

		<guid isPermaLink="false">http://www.datasecuritypolicies.com/authentication-policy</guid>
		<description><![CDATA[If you&#8217;re planning on writing a policy defining the rules of user authentication, here&#8217;s a short and sweet Authentication Policy from Auburn University that might be a helpful reference. Here&#8217;s an excerpt: I. PURPOSE To ensure that only authorized users have access to Auburn University computers. II. POLICY Auburn University computers will be configured to [...]]]></description>
			<content:encoded><![CDATA[<p>If you&#8217;re planning on writing a policy defining the rules of user authentication, <a href="http://www.auburn.edu/oit/it_policies/computer_authentication_policy.php">here&#8217;s</a> a short and sweet Authentication Policy from Auburn University that might be a helpful reference.</p>
<p>Here&#8217;s an excerpt:</p>
<blockquote><p><strong>I. PURPOSE</strong><br />
To ensure that only authorized users have access to Auburn University computers.</p>
<p><strong>II. POLICY</strong><br />
Auburn University computers will be configured to require authentication at startup.  When possible, authentication will be done through official domain facilities, otherwise authentication will be established on each individual machine.</p>
<p>Auburn University computers will be configured to have a screen lock that engages after no more than 30 minutes of inactivity and which requires re-authentication. When possible, the screen lockout will be controlled through official domain.</p></blockquote>
<p>There&#8217;s probably more that you should include but this is a good start.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.datasecuritypolicies.com/authentication-policy/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
