Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

GASSP 1

Status
Not open for further replies.

schofs

IS-IT--Management
Mar 9, 2005
70
GB
can any one briefly explain what are the principles of Generally Accepted System Security Principles actually are???

regards
 
Listen, just a word of advice, use Google, I just did and found a whole slew of information on your subject. Stop being lazy and learn to use the tools at hand (search engines). We don't mind helping out but when you can do a search on it and find a load of information on it it makes it kinda hard to want to help those who don't want to help themselves.
 
emm abit steep that bearing in mind i dont take offence easily lets do this step by step

first came across a qustion in cccure.org on GASSP
thought that was new so guess what yep i did google search spent an hour just trying to get basics
most links sent me to the MIT web site which is gone did search at MIT no hits on GASSP..
Other links wanted registration subscription or buy the book...
Thought I know ill put a post on tek-tips while i keep looking perhaps some friendly professional might know a good link to save time or maybea some pointers.

Bearing in mind that i am studying two hours a day for this the CISSP on top of a proffesional 14 at Enterprise levelhour work day you might have thought that and given me a hand instead of bad unhelpful comments...

Thanks anyway

regards

Simon

o well never mind.....
 
Then I apologise, I happen to subscribe to this forum and whilst I am not studying for the CISSP I have tried to help out here.

Now let me ask you a question, did you google on the word GASSP or on Generally Accepted System Security Principles??

 
Yes I tried both but I have since found what i wanted.. for all others who may be interested:

Generally Accepted System Security Principles are summarised as follows..

Support Mission of Organization

Cost effective

Data owner's have responsibility outside of their organization

Explicit policies naming responsibilities and accountability that is coherent with all the other organizations policies and should be integrated with thes policies

All users should receive awareness training

Security professionals should bind to code of ethics


Breaches should be reported in timely manner

systems should be assessed regulaly

principle of least privilege, separation of duties,BCP, simple safeguards.





 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top