|
During the month of June the primary focus of the Security Work Group was on development of the SDC Security Architecture. This document underwent considerable review by various CNIC work groups, the state Information Security Council, and others closely tied to the state of Oregon security community. A component of the architecture is a proposed list of information security services to be provided by the SDC. The architecture also includes the processes, a basis for standards and policies around each service, organizational recommendations, and roles and responsibilities of the security staff. Some of these services are planned to spread across the organization and some are planned for a security office within the SDC. The basis of the services recommendations were the ISO 17799, industry best practices, and the best security work being done within the agencies currently.
|