Non-profit, international research initiative dedicated to defining standards in security testing and business integrity testing. http://www.isecom.org
An excellent guide to computer & network security with a strong focus on writing and implementing security policy. This is primarily for security managers and system administrators. http://www.boran.com/security/
Provides general information about PKI policy, the role that policy plays in a PKI and how that policy applies to both traditional and PKI-enabled business environments. http://www.pkiforum.org/pdfs/pki_policy.pdf
Objective analysis reveals that many breaches are linked to common weaknesses in the security policy...accidents waiting to happen. This article focuses on strategic and systematic weaknesses that can slowly degrade security operations. http://downloads.securityfocus.com/library/Why_Security_Policies_Fail.pdf