Computer Security

Subject are: criminal justice
1.What is the difference between the CIA and the DAD Triad?

2.What is the difference between a security policy and a principle?

3.Review the New Jersey City University Information Technology Policies located at

Please answer the following questions:

•Identify if any policies are missing in your opinion? Is the information security policy communication easy for the user to understand?

•Does policy document make it clear that organizational senior management if firmly committed to information security?

•Does the information security policy describe the organization’s approach to information security?

•Is information security defined in the policy?

•Are information security management responsibilities outlined in the document?

•Does the document refer to other documents that support the information security policy?

•Is the “owner” of the security policy clearly defined?

