Home / Policies / Cyber Security Policy
Back to Policies

Cyber Security Policy

This Cyber Security Policy is a formal set of rules by which those people who are given access to company technology and information assets must abide. The policy outlines our commitment to protecting company and client data from cyber threats.

1. Definition

The use of the term "company" is in reverence to the organization: INFORMATION TECHNOLOGY EXPERTS.

2. Introduction

This Cyber Security Policy is a formal set of rules by which those people who are given access to company technology and information assets must abide.

The Cyber Security Policy serves several purposes. The main purpose is to inform company users — employees, contractors and other authorized users — of their obligatory requirements for protecting the technology and information assets of the company. The Cyber Security Policy describes the technology and information assets that we must protect and identifies many of the threats to those assets.

The Cyber Security Policy also describes the user's responsibilities and privileges, acceptable use, rules regarding Internet access, user limitations, and penalties for violation of the policy.

3. What Are We Protecting

It is the obligation of all users of the company systems to protect the technology and information assets of the company. The technology and information assets are made up of:

  • Computer hardware, CPU, disc, Email, web, application servers, PC systems, application software, system software, etc.
  • System Software including: operating systems, database management systems, backup and restore software, communications protocols.
  • Application Software used by the various departments within the company.
  • Communications Network hardware and software including: routers, routing tables, hubs, modems, multiplexers, switches, firewalls, and associated network management tools.

3.1 Classification of Computer Systems

Security Level Description Example
RED Contains confidential information. Access on a "need to know" basis. Mission-critical services — failure may have financial impact. Server containing confidential data; Network routers and firewalls.
GREEN Does not contain confidential info, but provides ability to access RED systems through the network. User department PCs; Management workstations.
WHITE Not externally accessible. Isolated LAN segment, unable to access RED or GREEN systems. Test systems used by programmers to develop new systems.
BLACK Externally accessible. Isolated from RED/GREEN by a firewall. Does not contain confidential information. Public Web server with non-sensitive information.

3.2 Local Area Network (LAN) Classifications

A LAN will be classified by the systems directly connected to it. If a LAN contains just one RED system, all network users will be subject to the same restrictions as RED system users. A LAN will assume the Security Classification of the highest-level system attached to it.

4. Definitions

  • Externally accessible to public: The system may be accessed via the Internet without a logon id or password.
  • Non-Public, externally accessible: Users must have a valid logon id and password. At least one level of firewall protection.
  • Internally accessible only: Valid logon id and password required. At least two levels of firewall protection.
  • Chief Information Officer: The Director of the Department of Information Technology (IT).
  • Security Administrator: An employee of IT designated as the Security Administrator for the company.

5. Threats to Security

5.1 Employees

One of the biggest security threats is employees — through incompetence or intent. Mitigations include:

  • Only give out appropriate rights to systems. Limit access to only business hours.
  • Never share accounts to access systems. Don't share your login info with co-workers.
  • When employees are separated or disciplined, remove or limit access to systems.
  • Keep detailed system logs on all computer activity.
  • Physically secure computer assets so that only staff with appropriate need can access.

5.2 Amateur Hackers and Vandals

The most common type of attackers. These are usually crimes of opportunity — scanning the Internet for well-known security holes that have not been plugged.

5.3 Criminal Hackers and Saboteurs

The probability of this type of attack is low, but not entirely unlikely given the amount of sensitive information contained in databases. Skill level is medium to high.

6. User Responsibilities

6.1 Acceptable Use

User accounts on company computer systems are to be used only for business of the company and not for personal activities. Users are personally responsible for protecting all confidential information, including their logon IDs and passwords.

Users shall not:

  • Purposely engage in activity with the intent to harass other users or degrade system performance
  • Attach unauthorized devices on their PCs or workstations without authorization
  • Download unauthorized software from the Internet onto their PCs or workstations

6.2 Use of the Internet

The Internet is a business tool for the company. It is to be used for business-related purposes such as communicating via electronic mail with suppliers and business partners, obtaining useful business information, and relevant technical and business topics.

6.3 User Classification

User Category Privileges & Responsibilities
Department Users (Employees)Access to application and databases as required for job function. (RED and/or GREEN cleared)
System AdministratorsAccess to computer systems, routers, hubs, and other infrastructure as required. Access to confidential information on a "need to know" basis only.
Security AdministratorHighest level of security clearance. Allowed access to all computer systems, databases, firewalls, and network devices as required.
Systems Analyst/ProgrammerAccess to applications and databases as required. Not authorized to access routers, firewalls, or other network devices.
Contractors/ConsultantsAccess as required for specific job functions. Must be approved in writing by the company director/CEO.
General PublicAccess limited to applications running on public Web servers only.

6.4 Monitoring Use of Computer Systems

The company has the right and capability to monitor electronic information created and/or communicated by persons using company computer systems and networks, including e-mail messages and usage of the Internet.

7. Access Control

7.1 Password Requirements

  • Password must not be found in any English or foreign dictionary
  • Passwords should not be posted on or near computer terminals
  • Password must be changed every 60 days
  • User accounts will be frozen after 3 failed logon attempts
  • Logon IDs and passwords will be suspended after 90 days without use
  • Users are not allowed to access password files on any network infrastructure component

7.2 System Administrator Access

System Administrators, network administrators, and security administrators will have full access to host systems, routers, hubs, and firewalls as required. All system administrator passwords will be DELETED immediately after any employee who has access to such passwords leaves the company.

7.3 Special Access

Special access accounts for temporary administrator privileges expire in 1 day and will not be automatically renewed without written permission from the IT Manager.

8. Penalty for Security Violation

Those who use the technology and information resources of company must be aware that they can be disciplined if they violate this policy. Upon violation, an employee may be subject to discipline up to and including discharge.

9. Security Incident Handling

A "security incident" is defined as any irregular or adverse event that threatens the security, integrity, or availability of information resources on any part of the company network. Examples include:

  • Illegal access of a company computer system
  • Damage to a company computer system or network caused by illegal access
  • Denial of service attack against a company web server
  • Malicious use of system resources to launch an attack against other computers

Important: Employees who believe their computer systems have been subjected to a security incident should report the situation to their Information Officer immediately. Do not turn off the computer or delete suspicious files.

Back to All Policies