Template

Security Tools, Templates, Policies

Sample policies with expert commentary; templates and checklists for security, business continuity, risk assessment and more.

CSO — CSOonline's Security Tools, Templates & Policies page provides sample documents contributed by the security community. Feel free to use or adapt them for your own organization.*

Want to provide a policy or checklist? Contributions are welcome, as is expert commentary on any of the articles here. We will add materials on an ongoing basis. Send your thoughts to Senior Editor Joan Goodchild at jgoodchild@cxo.com.

*Though not for re-publication or for-profit use.


Sample Policies - Computers and Internet

Computer and E-Mail Acceptable Use Policy
Manufacturing company, <50 employees

Internet Acceptable Use Policy
Manufacturing company, <50 employees

Password Protection Policy
Large financial services company, more than 5,000 employees

Sample Policies - Physical Security and Emergency Management

A 10-Question Guide for Pandemic Planning

Clean Desk Policy
Service company, 2000 employees

Cell Phone Use While Driving Policy
Company has many employees who travel frequently

Workplace Violence Prevention Policy
Detailed policy of mid-sized company. Includes harassment, stalking, domestic violence concerns

Concealed Weapon Policy
Hospital, 10,000 employees. Makes allowance for security personnel.

Bomb threat procedures
Includes good checklist of questions to ask caller.

Sample Policies - Privacy

Personnel Access/Changes Policy
Large, private university

Other Security Tools and Worksheets

Sample Employee Termination Checklist
An employee termination checklist from security expert Tim Giles' book "How to Develop and Implement a Security Master Plan"

Comparison of two actual data breach disclosure letters
Links to actual letters; includes expert commentary

Sample diagnostic questions for finding information security weaknesses
Book excerpt

Risk assessment questions for loading docks in multitenant buildings

Risk assessment questions for call centers

Risk assessment tool for use of USB drives

Three sample scenarios for tabletop exercises
Covering digital and physical business interruptions and threats

security policies

RESOURCE CENTER
Loading...
VIRTUAL CONFERENCE
Security Directions: A Virtual Conference

Security Directions Available On Demand Sept. 30 - Dec. 30

Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.

» Register Now

WEBCAST
Protecting PII: How to Work with IT to Manage Risk

Compuware Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.

» View this Webcast

Featured Sponsors