Files
nexus/wiki/concepts/Global-Information-Security-Policy-GISP.md

33 lines
1.1 KiB
Markdown
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
title: "Global Information Security Policy (GISP)"
type: concept
tags:
- OpenText
- Security-Policy
- Governance
last_updated: 2026-04-14
---
# Global Information Security Policy (GISP)
## Definition
OpenText 的最高纲领性安全政策是所有其他安全政策的根基。GISP 由全球信息安全团队GIS制定和支持定期每季度接受领导层审查。
## Scope
- 定义企业"需要做什么"what同时为"如何实施"how提供灵活性
- 支持性政策Supporting Policies围绕 GISP 构建
- 鼓励反馈以实现持续改进
## Relationship to Other Concepts
- 基于 [[ISO-27001]] 姿态框架
- 与 [[Security-Awareness-Training]] 配合提升全员安全意识
- 与 [[Third-Party-Penetration-Testing]] 配合验证政策有效性
## Key Quote
> "Policies define what needs to be done, while providing flexibility for how it is implemented." — GIS Policy Framework
## Connections
- [[Global Information Security Team (GIS)]]:制定与维护团队
- [[ISO-27001]]:框架基础
- [[OpenText]]:所属组织