Security Policy
The first rule of security is basically whatever you did not expressly say I could not do I am allowed to do.
A good security policy should start by denying all access and then expressly add back access for specific needs.
Consider the goals and the mission of your site
- A military site will have different requirements than an educational site, as well as departments within each site