Listen, just a word of advice, use Google, I just did and found a whole slew of information on your subject. Stop being lazy and learn to use the tools at hand (search engines). We don't mind helping out but when you can do a search on it and find a load of information on it it makes it kinda hard to want to help those who don't want to help themselves.
emm abit steep that bearing in mind i dont take offence easily lets do this step by step
first came across a qustion in cccure.org on GASSP
thought that was new so guess what yep i did google search spent an hour just trying to get basics
most links sent me to the MIT web site which is gone did search at MIT no hits on GASSP..
Other links wanted registration subscription or buy the book...
Thought I know ill put a post on tek-tips while i keep looking perhaps some friendly professional might know a good link to save time or maybea some pointers.
Bearing in mind that i am studying two hours a day for this the CISSP on top of a proffesional 14 at Enterprise levelhour work day you might have thought that and given me a hand instead of bad unhelpful comments...
Yes I tried both but I have since found what i wanted.. for all others who may be interested:
Generally Accepted System Security Principles are summarised as follows..
Support Mission of Organization
Cost effective
Data owner's have responsibility outside of their organization
Explicit policies naming responsibilities and accountability that is coherent with all the other organizations policies and should be integrated with thes policies
All users should receive awareness training
Security professionals should bind to code of ethics
Breaches should be reported in timely manner
systems should be assessed regulaly
principle of least privilege, separation of duties,BCP, simple safeguards.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.