Security Policy
1. Introduction
1.1. Purpose
This Security Policy document is aimed to define the security requirements for the proper and secure use of the Information Technology services in the Organisation. Its goal is to protect the Organisation and users to the maximum extent possible against security threats that could jeopardize their integrity, privacy, reputation and business outcomes.
1.2. Scope
This document applies to all the users in the Organisation, including temporary users, visitors with temporary access to services and partners with limited or unlimited access time to services. Compliance with policies in this document is mandatory for this constituency.
1.3. History
1.4. Responsibilities
Chief Information Officer
Accountable for all aspects of the Organisation’s information security.
Information Security Officer
Responsible for the security of the IT infrastructure.
- Plan against security threats, vulnerabilities, and risks.
- Implement and maintain Security Policy documents.
- Ensure security training programs.
- Ensure IT infrastructure supports Security Policies.
- Respond to information security incidents.
- Help in disaster recovery plans.
Information Owners
Help with the security requirements for their specific area.
- Determine the privileges and access rights to the resources within their areas.
IT Security Team
Implements and operates IT security.
- Implements the privileges and access rights to the resources.
- Supports Security Policies.
Users
Meet Security Policies.
- Report any attempted security breaches.
1.5. General Policy Definitions
Exceptions to the policies defined in any part of this document may only be authorised by the Information Security Officer. In those cases, specific procedures may be put in place to handle request and authorisation for exceptions.
Every time a policy exception is invoked, an entry must be made into a security log specifying the date and time, description, reason for the exception and how the risk was managed.
All the IT services should be used in compliance with the technical and security requirements defined in the design of the services.
Infractions of the policies in this document may lead to disciplinary actions. In some serious cases, they could even lead to prosecution.
2. IT Assets Policy
2.1. Purpose
The IT Assets Policy section defines the requirements for the proper and secure handling of all the IT assets in the Organisation.
2.2. Scope
The policy applies to desktops, laptops, printers and other equipment, to applications and software, to anyone using those assets including internal users, temporary workers and visitors, and in general to any resource and capabilities involved in the provision of the IT services.
2.3. Policy Definitions
- IT assets must only be used in connection with the business activities they are assigned and/or authorised.
- All the IT assets must be classified into one of the categories in the Organisation’s security categories; according to the current business function they are assigned to.
- Every user is responsible for the preservation and correct use of the IT assets they have been assigned.
- All the IT assets must be in locations with security access restrictions, environmental conditions and layout according to the security classification and technical specifications of the aforementioned assets.
- Active desktops and laptops must be secured if left unattended. Whenever possible, this policy should be automatically enforced.
- Access to assets is forbidden for non-authorised personnel. Granting access to the assets involved in the provision of a service must be done through the approved Service Request Management and Access Management processes.
- All personnel interacting with the IT assets must have the proper training.
- Users shall maintain the assets assigned to them clean and free of accidents or improper use.
- Access to assets in the Organisation location must be restricted and properly authorised, including those accessing remotely. Company’s laptops, PDAs and other equipment used at external locations must be periodically checked and maintained.
- The IT Technical Teams are the sole responsible for maintaining and upgrading configurations. No other users are authorised to change or upgrade the configuration of the IT assets.
- Special care must be taken for protecting laptops, PDAs and other portable assets from theft.
- When travelling by plane, portable equipment like laptops and PDAs must remain in possession of the user as hand luggage.
- Whenever possible, encryption and erasing technologies should be implemented in portable assets in case they were stolen.
- Losses, theft, damages, tampering or other incidents related to assets that compromise security must be reported as soon as possible to the Information Security Officer.
- Disposal of the assets must be done according to the specific procedures for the protection of the information.
3. Access Control Policy
3.1. Purpose
The Access Control Policy section defines the requirements for the proper and secure control of access to IT services and infrastructure in the Organisation.
3.2. Scope
This policy applies to all the users in the Organisation, including temporary users, visitors with temporary access to services and partners with limited or unlimited access time to services.
3.3. Policy Definitions
- Any system that handles valuable information must be protected with a password-based access control system.
- Systems that handle confidential information should be protected by two-factor-based access control systems.
- Discretionary access control lists must be in place to control access to resources for different groups of users.
- Mandatory access controls should be in place to regulate access by processes operating on behalf of users.
- Access to resources should be granted on a per-group basis rather than on a per-user basis.
- Access shall be granted under the principle of “less privilege”.
4. Password Control Policy
4.1. Purpose
The Password Control Policy section defines the requirements for the proper and secure handling of passwords in the Organisation.
4.2. Scope
4.3. Policy Definitions
- Every user must have a separate, private identity for accessing IT network services.
- Identities should be centrally created and managed.
- Each identity must have a strong, private, alphanumeric password of at least 8 characters long.
- Sharing of passwords is forbidden.
5. Email Policy
5.1. Purpose
The Email Policy section defines the requirements for the proper and secure use of electronic mail in the Organisation.
5.2. Scope
5.3. Policy Definitions
- All assigned email addresses must be used only for business purposes.
- Use of the Organisation resources for non-authorised advertising, spam, or political campaigns is strictly forbidden.
- Users must have private identities to access their emails.
- Security incidents must be reported and handled promptly.
6. Internet Policy
6.1. Purpose
The Internet Policy section defines the requirements for the proper and secure access to the Internet.
6.2. Scope
This policy applies to all the users in the Organisation.
6.3. Policy Definitions
- Limited access to the Internet is permitted for all users.
- Access to risky sites is strongly discouraged.
- Internet access should primarily be for business purposes.
7. Antivirus Policy
7.1. Purpose
The Antivirus Policy section defines the requirements for the proper implementation of antivirus and other forms of protection in the Organisation.
7.2. Scope
This policy applies to servers, workstations and equipment in the Organisation.
7.3. Policy Definitions
- All computers with access to the Organisation network must have an antivirus client installed.
- All servers and workstations must have a centrally managed antivirus.
8. Information Classification Policy
8.1. Purpose
The Information Classification Policy section defines a framework for the classification of the information according to its importance and risks involved.
8.2. Scope
This policy applies to all the information created, owned or managed by the Organisation.
8.3. Policy Definitions
- Information owners must ensure the security of their information.
- Information is classified according to its security impact into categories: confidential, sensitive, shareable, public, and private.
9. Remote Access Policy
9.1. Purpose
The Remote Access Policy section defines the requirements for the secure remote access to the Organisation’s internal resources.
9.2. Scope
This policy applies to the users and devices needing access to the Organisation’s internal resources from remote locations.
9.3. Policy Definitions
- Users must have the required authorisation for remote access.
- Only secure channels with mutual authentication must be available for remote access.
10. Outsourcing Policy
10.1. Purpose
The Outsourcing Policy section defines the requirements needed to minimize the risks associated with outsourcing IT services, functions, and processes.
10.2. Scope
This policy applies to the Organisation and the service providers involved in outsourcing.
10.3. Policy Definitions
- A careful strategy must be followed to evaluate the risk and financial implications before outsourcing.
11. Glossary
Access Management
The process responsible for allowing users to make use of IT services.
Asset
Any resource or capability.
Audit
Formal verification to check whether guidelines are being followed.
Confidentiality
Requires that data only be accessed by authorised personnel.
External Service Provider
An IT service provider that is part of a different organisation.
Identity
A unique name to identify a user or role.
Information Security Policy
The policy governing the organisation’s approach to information security management.
Outsourcing
Using an external service contractor to manage IT services.
Policy
Formally documented management expectations and intentions.
Risk
A possible event causing harm or loss.
Service Level
Measured achievement against service level targets.
Warranty
Assurance that a product/service will meet agreed requirements.