This Cyber Security Policy is a formal set of rules by which those people who are given access to company technology and information assets must abide. The policy outlines our commitment to protecting company and client data from cyber threats.
The use of the term "company" is in reverence to the organization: INFORMATION TECHNOLOGY EXPERTS.
This Cyber Security Policy is a formal set of rules by which those people who are given access to company technology and information assets must abide.
The Cyber Security Policy serves several purposes. The main purpose is to inform company users — employees, contractors and other authorized users — of their obligatory requirements for protecting the technology and information assets of the company. The Cyber Security Policy describes the technology and information assets that we must protect and identifies many of the threats to those assets.
The Cyber Security Policy also describes the user's responsibilities and privileges, acceptable use, rules regarding Internet access, user limitations, and penalties for violation of the policy.
It is the obligation of all users of the company systems to protect the technology and information assets of the company. The technology and information assets are made up of:
| Security Level | Description | Example |
|---|---|---|
| RED | Contains confidential information. Access on a "need to know" basis. Mission-critical services — failure may have financial impact. | Server containing confidential data; Network routers and firewalls. |
| GREEN | Does not contain confidential info, but provides ability to access RED systems through the network. | User department PCs; Management workstations. |
| WHITE | Not externally accessible. Isolated LAN segment, unable to access RED or GREEN systems. | Test systems used by programmers to develop new systems. |
| BLACK | Externally accessible. Isolated from RED/GREEN by a firewall. Does not contain confidential information. | Public Web server with non-sensitive information. |
A LAN will be classified by the systems directly connected to it. If a LAN contains just one RED system, all network users will be subject to the same restrictions as RED system users. A LAN will assume the Security Classification of the highest-level system attached to it.
One of the biggest security threats is employees — through incompetence or intent. Mitigations include:
The most common type of attackers. These are usually crimes of opportunity — scanning the Internet for well-known security holes that have not been plugged.
The probability of this type of attack is low, but not entirely unlikely given the amount of sensitive information contained in databases. Skill level is medium to high.
User accounts on company computer systems are to be used only for business of the company and not for personal activities. Users are personally responsible for protecting all confidential information, including their logon IDs and passwords.
Users shall not:
The Internet is a business tool for the company. It is to be used for business-related purposes such as communicating via electronic mail with suppliers and business partners, obtaining useful business information, and relevant technical and business topics.
| User Category | Privileges & Responsibilities |
|---|---|
| Department Users (Employees) | Access to application and databases as required for job function. (RED and/or GREEN cleared) |
| System Administrators | Access to computer systems, routers, hubs, and other infrastructure as required. Access to confidential information on a "need to know" basis only. |
| Security Administrator | Highest level of security clearance. Allowed access to all computer systems, databases, firewalls, and network devices as required. |
| Systems Analyst/Programmer | Access to applications and databases as required. Not authorized to access routers, firewalls, or other network devices. |
| Contractors/Consultants | Access as required for specific job functions. Must be approved in writing by the company director/CEO. |
| General Public | Access limited to applications running on public Web servers only. |
The company has the right and capability to monitor electronic information created and/or communicated by persons using company computer systems and networks, including e-mail messages and usage of the Internet.
System Administrators, network administrators, and security administrators will have full access to host systems, routers, hubs, and firewalls as required. All system administrator passwords will be DELETED immediately after any employee who has access to such passwords leaves the company.
Special access accounts for temporary administrator privileges expire in 1 day and will not be automatically renewed without written permission from the IT Manager.
Those who use the technology and information resources of company must be aware that they can be disciplined if they violate this policy. Upon violation, an employee may be subject to discipline up to and including discharge.
A "security incident" is defined as any irregular or adverse event that threatens the security, integrity, or availability of information resources on any part of the company network. Examples include:
Important: Employees who believe their computer systems have been subjected to a security incident should report the situation to their Information Officer immediately. Do not turn off the computer or delete suspicious files.