The goal is to find any relevant material across the whole project scope using AndersenÕs Knowledge Exchange databases and tools, to which only Andersen personnel have access. Literature Survey
The goal is to find any relevant material across the whole project scope as long as it originates from impartial sources. Industry Pre-survey
The goal is to find any material on security policies published by companies who apply those policies in their own operations. The material will be biased by nature and will have to be treated as such. Depending on the amount of information available from various sources, it may need to be categorised. An ideal goal would be to gain an understanding of the current state of the art, but the pre-survey is most likely going to leave a lot of that for the development phase. Vendor Research
The goal is to come up with the following in a tangible document (to be placed on the Web server or to be printed on paper)
- classification of available products into two categories:
- risk assessment tools
- policy enforcement tools
(decision support tools were explicitly descoped on Thu June 10th)
Then subdividing these categories further if applicable and characterising the kind of tool support available, giving an opinion about their general maturity and value in practice, even if no specific products are then mentioned in the end deliverables.
- market information on specific products, such as their relative strengths, who are the market leaders, how widely adopted these products are (naming important reference users, if possible),
- Justify need for the project
- Gather information on current state of affairs in companies.
- Creating new information/statistics in the area of security policy management in the eCommerce context would be the ultimate goal, but most likely we will have to settle with an analysis produced by Gartner/CSI upon request, or with an external vendorÕs help in finding relevant existing information.
- Justify need for the project
- Gather information on current state of affairs in companies.
- Assess the readiness of AC projects to adopt the security policy frameworks to be developed in this project (will it be easy/hard to sell in each case, are they concerned with the same problems?)

