• Access Rights & Permissions Matrix
    • Data Breach Notification Log
    • Data Classification Register
    • Data Loss Prevention (DLP) Incident Log
    • Document Retention & Disposal Tracker
    • Security KPI Dashboard
    • Asymmetric-Key Cryptography
    • Combined Security Model: Digital Signature + Digital Envelope
    • Database Encryption Techniques (API, Plug-in, TDE)
    • Diffie-Hellman Key Exchange
    • Digital Envelope
    • Digital Signature
    • Hash Function
    • Homomorphic Encryption
    • Hybrid Cryptography
    • PKI (Public Key Infrastructure)
    • Post-Quantum Cryptography (PQC)
    • Quantum Security
    • RSA Encryption
    • Sign-then-Encrypt
    • Symmetric-Key Cryptography
    • CIA Triad
    • Endpoint Security
    • Systematic Server Defense Strategy
    • DDoS Attack Mitigation Plan Tracker
    • IP Whitelist–Blacklist Tracker
    • Network Access Control Log
    • Network Device Inventory
    • Network Security Risk Mitigation
    • Network Traffic Monitoring Dashboard
    • DDoS (Distributed Denial of Service)
    • DRDoS (Distributed Reflective Denial of Service)
    • Network Separation & Integration
    • SASE (Secure Access Service Edge)
    • SDP (Software Defined Perimeter)
    • Spoofing
    • Zero Trust
    • IPSec
    • OSI 7-Layer Security
    • OSI 7-Layer Security Threats
    • TLS (Transport Layer Security)
    • Cloud Access Control Matrix
    • Cloud Asset Inventory Tracker
    • Cloud Backup & Recovery Testing Tracker
    • Cloud Incident Response Log
    • Cloud Security Configuration Baseline
    • CASB (Cloud Access Security Broker)
    • CNAPP (Cloud Native Application Protection Platform)
    • The Two Pillars of Cloud Security (CSPM and CWPP)
    • DSPM (Data Security Posture Management)
    • Integrated Cloud-Native Security Architecture
    • Shadow IT
    • Kubernetes Security
    • Amdahl's Law
    • Patch & Update Tracker
    • Secure Coding Checklist
    • Secure Mobile App Testing Tracker
    • Security Misconfiguration Log
    • Static Code Analysis Log
    • Web Application Vulnerability Tracker
    • Application Threat Modeling
    • CSRF (Cross-Site Request Forgery)
    • SQL Injection
    • XSS (Cross-Site Scripting)
    • API Security (OWASP API Top 10 and BOLA)
    • Code Security (SAST, DAST, and Secure Coding)
    • DevSecOps Pipeline
    • DevSecOps
    • Software Supply Chain Security (SBOM and SLSA)
    • Acceptable Use of Assets Policy
    • Password Policy
    • Backup and Recovery Policy
    • Compliance Management
    • Disposal and Destruction Policy
    • Information Classification Policy
    • Information Transfer Policy
    • ISMS Policy
    • COBIT-Based Security Governance
    • ISMS-P
    • ISO 27001
    • Privacy Impact Assessment (PIA)
    • Korea's Data 3 Acts
    • Differential Privacy
    • EU AI Act
    • 5 Pseudonymization Techniques
    • CSAP Tiered Certification
    • Incident Management Policy
    • Incident Management Process
    • Intern Incident Report
    • Major Incident Report Template
    • Structural Damage Incident Report
    • Workplace Violence Report
    • The Core of Endpoint Visibility, EDR
    • The Integrated Control Tower for Threat Detection and Analysis, SIEM
    • Digital Forensics
    • Known Error (KE) Record Template
    • Major Problem Report Template
    • Problem Management Process
    • Problem Record Template
    • DR Approach Document
    • DR Asset Register
    • DR Closure Report
    • DR Communications Plan
    • DR Plan Template
    • MAC vs. DAC vs. RBAC: Access Control Models Compared
    • Access Control
    • Authentication vs. Authorization
    • FIDO (Fast IDentity Online)
    • Identity Provider (IdP)
    • JWT (JSON Web Token)
    • Kerberos
    • OAuth 2.0
    • OAuth 2.0 and OIDC
    • OpenID Connect (OIDC)
    • Passkey
    • SAML (Security Assertion Markup Language)
    • Single Sign-On (SSO)
    • Active Directory (AD)
    • LDAP (Lightweight Directory Access Protocol)
    • Systematic Classification of Attack Techniques
    • Penetration Testing Methodology
    • OSINT (Open Source Intelligence)
    • OSSTMM (Open Source Security Testing Methodology Manual)
    • PTES (Penetration Testing Execution Standard)
    • RAV (Risk Assessment Value)
    • Fuzzing
    • CTF Categories
    • Red Teaming
    • AI System Security
    • Deepfake
    • LLM Security (OWASP Top 10 for LLM)
    • OT/ICS Security and the Purdue Model
    • Blockchain
    • GitHub
  • to navigate
  • to select
  • to close
    • Home
    • Security Management
    On this page
    policy

    Security Management

    Governance policies that formalize how an organization protects, classifies, transfers, and disposes of information assets.

    gavel

    Acceptable Use of Assets Policy

    Defines permitted and prohibited use of company-owned devices, accounts, and network resources by employees and contractors.

    password

    Password Policy

    Sets enforceable minimum standards for password strength, rotation, storage, and multi-factor authentication across systems.

    backup

    Backup and Recovery Policy

    Establishes requirements for data backup frequency, retention, testing, and restoration to protect against data loss.

    verified

    Compliance Management

    Coordinates how the organization tracks, evidences, and reports adherence to security regulations, standards, and contractual obligations.

    delete_forever

    Disposal and Destruction Policy

    Specifies how data-bearing media and physical records must be sanitized or destroyed at end of life to prevent data exposure.

    label

    Information Classification Policy

    Defines sensitivity tiers for organizational data and the handling requirements attached to each tier.

    send

    Information Transfer Policy

    Governs how classified data may be exchanged internally, with partners, and with third parties, across physical and digital channels.

    account_balance

    ISMS Policy

    The top-level charter that establishes scope, objectives, and governance structure for the organization's information security management …

    account_tree

    COBIT-Based Security Governance

    How COBIT separates security governance from security management to align security controls with business value.

    verified_user

    ISMS-P

    Korea's integrated Information Security and Personal Information Management System certification, combining ISMS and PIMS.

    public

    ISO 27001

    The international standard for an information security management system, built on a continuous PDCA improvement cycle.

    privacy_tip

    Privacy Impact Assessment (PIA)

    A procedure for analyzing and remediating personal-information risk before a system that handles personal data is built or changed.

    gavel

    Korea's Data 3 Acts

    The legal basis for using pseudonymized and anonymized data in Korea, and the procedure for combining pseudonymized data across data …

    blur_on

    Differential Privacy

    A mathematically provable privacy mechanism that injects statistical noise so results barely change whether or not any one individual's data …

    balance

    EU AI Act

    The EU's risk-based legal framework that sets tiered obligations for AI systems to protect human safety, health, and fundamental rights.

    visibility_off

    5 Pseudonymization Techniques

    The five core techniques for processing personal information into pseudonymized data that balances data utility with privacy.

    cloud_lock

    CSAP Tiered Certification

    Korea's Cloud Security Assurance Program restructured into 3 tiers by data sensitivity, and what it requires of public agencies adopting …


    © 2026 Cybersecurity Knowledge Base. Built with Lotus Docs