 




<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: How Many Information Security Policies Do I Need?</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/itanswers/how-many-information-security-policies-do-i-need/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/itanswers/how-many-information-security-policies-do-i-need/</link>
	<description></description>
	<lastBuildDate>Mon, 20 May 2013 17:27:58 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
	<item>
		<title>By: ntsandy</title>
		<link>http://itknowledgeexchange.techtarget.com/itanswers/how-many-information-security-policies-do-i-need/#comment-86125</link>
		<dc:creator>ntsandy</dc:creator>
		<pubDate>Wed, 05 Jan 2011 13:49:55 +0000</pubDate>
		<guid isPermaLink="false">#comment-86125</guid>
		<description><![CDATA[Unless you have a ironclad contract in place that has acceptable SLAs in place I would make sure that I had IR and DR plans in place. You also need to have plans in place that will guide your company in the event of an issue even if the hosting provider is handling everything else. How will you continue business during their recovery period? 

As for policies it depends on several factors. What industry you are in. What type of business you conduct over the internet. How you interact w/ customers. Is your web site info only or e-commerce. What regulations you are subject to. etc....

As for the SAS70 it is basically useless as a security measure. The hosting provider defines what is measured so it&#039;s pretty hard to not pass.]]></description>
		<content:encoded><![CDATA[<p>Unless you have a ironclad contract in place that has acceptable SLAs in place I would make sure that I had IR and DR plans in place. You also need to have plans in place that will guide your company in the event of an issue even if the hosting provider is handling everything else. How will you continue business during their recovery period? </p>
<p>As for policies it depends on several factors. What industry you are in. What type of business you conduct over the internet. How you interact w/ customers. Is your web site info only or e-commerce. What regulations you are subject to. etc&#8230;.</p>
<p>As for the SAS70 it is basically useless as a security measure. The hosting provider defines what is measured so it&#8217;s pretty hard to not pass.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached
Database Caching 6/9 queries in 0.012 seconds using memcached
Object Caching 268/271 objects using memcached

Served from: itknowledgeexchange.techtarget.com @ 2013-05-20 17:52:26 -->