IT Security Policy
Data Center Local Policy
Policy Document
Access Control Policy
Enter your Name:
_____________________________________
Professor Last Name: Landreville
Document Control
[CSIA 413, Today’s Date]
|
Organization |
[Name of your chosen organization] |
|
Title |
[Name of the Local Policy ] |
|
Author |
[Your Name ] |
|
Owner |
Data Center Manager |
|
Subject |
IT Local Access Policy |
|
Review date |
Date of Completion of Policy |
Revision History
|
Revision Date |
Reviser |
Previous Version |
Description of Revision |
|
|
|
|
Changes to your draft are provided here |
|
|
|
|
|
Document Approvals
This document requires the following approvals:
|
Sponsor Approval |
Name |
Date |
|
Approved |
[CEO, CISO, etc.] |
Enter date of submission to folder |
Document Distribution
This document will be distributed to:
|
Name |
Job Title |
Email Address |
|
All Data Center Staff |
Technicians |
Enter your email address |
|
|
|
|
|
|
|
|
Contributors
Development of this policy was assisted through information provided by the following organization:
|
· Enter your organization |
Contents
List the contents of the policy
Table of Contents
1
2
3
4
5
[ ] will establish specific requirements for protecting information and information systems against unauthorized access.
[ ] will effectively communicate the need for information and information system access control.
Information security is the protection of information against accidental or malicious disclosure, modification or destruction. Information is an important, valuable asset of [ name of your chosen organization ] which must be secured from threats and vulnerabilities must be identified and patched. All information has a value to the organization. Access controls are essential to protect information by controlling user rights for information resources and by guarding against unauthorized use. Formal procedures must control how access to information is granted and how such access is changed.
This policy includes the following access control measures [enter 5 local policy protections for your chosen organization based on a brief risk assessment using FIPS 199 and FIPS 200].
This policy applies to all [ BE THOROUGH IN SCOPE ] (including system support staff, contractual third parties and agents with any form of access to the data center information and information systems.
Access control rules and procedures are required to regulate who can access information resources or systems and the associated access privileges. This policy applies at all times and should be adhered to whenever accessing information in any format, and on any device.
On occasion business information may be disclosed or accessed prematurely, accidentally or unlawfully. Individuals or companies, without the correct authorization and clearance may intentionally or accidentally gain unauthorized access to business information which may adversely affect day to day business. This policy is intended to mitigate that risk.
Non-compliance with this policy could have a significant effect on the efficient operation of the data center and may result in financial loss and an inability to provide necessary services to our customers.
Risk Assessment and level of risk
Identify weaknesses in the system.
Identify possible threats and vulnerabilities in the system.
SIGNATORY AUTHORITY (Enter CISO Name)
Include the following information in your local policy
Applying the Policy – Employee Access
Formal user access control procedures must be documented, implemented and kept up to date for each application and information system to ensure authorized user access and to prevent unauthorized access. They must cover all stages of the lifecycle of user access, from the initial registration of new users to the final de-registration of users who no longer require access. These must be agreed by the system administrator. Each user must be allocated access rights and permissions to computer systems and data that:
· List constraints on what the user in the data center is allowed to view, read, change
User access rights must be reviewed at regular intervals to ensure that the appropriate rights are still allocated. System administration accounts must only be provided to users that are required to perform system administration tasks.
A request for access to the computer systems must first be submitted to the [Name a department – e.g. Information Services Helpdesk] for approval. Applications for access must only be submitted if approval has been gained from [Name a role – e.g. your line manager].
When an employee leaves access to computer systems and data must be suspended at the close of business on the employee’s last working day. It is the responsibility of the [Name a role – e.g. your line manager] to request the suspension of the access rights via the [Name a department – e.g. Information Services Helpdesk].
It is a user’s responsibility to prevent their userID and password being used to gain unauthorized access to systems by:
· Following the Password Policy Statements outlined above in Section 6.
· Add three more user responsibilities
The use of modems on non-owned PC’s connected to the network can seriously compromise the security of the network. The normal operation of the network must not be interfered with. Specific approval must be obtained from [Name a department – e.g. Information Services] before connecting any equipment to the network.
User Authentication for External Connections
Where remote access to the [ Name] network is required, an application must be made via the [Name a department – e.g. IT Helpdesk]. Remote access to the network must be secured by two factor authentication consisting of a username and one other component, for example a [Name a relevant authentication token]. For further information please refer to [name a relevant policy -likely to be Remote Working Policy].
Supplier’s Remote Access to the Network
Partner agencies or 3rd party suppliers must not be given details of how to access the network without permission from [Name a department – e.g. IT Helpdesk]. Any changes to supplier’s connections must be immediately sent to the [Name a department – e.g. IT Helpdesk] so that access can be updated or ceased. All permissions and access methods must be controlled by [Name a department – e.g. IT Helpdesk].
Partners or 3rd party suppliers must contact the [Name a department – e.g. IT Helpdesk] before connecting to the [ Name] network and a log of activity must be maintained. Remote access software must be disabled when not in use.
Operating System Access Control
Access to operating systems is controlled by a secure login process. The access control defined in the User Access Management section (section 7.1) and the Password section (section 6) above must be applied. The login procedure must also be protected by:
· Provide security controls to protect unauthorized access from the table below
All access to operating systems is via a unique login id that will be audited and can be traced back to each individual user. The login id must not give any indication of the level of access that it provides to the system (e.g. administration rights).
System administrators must have individual administrator accounts that will be logged and audited. The administrator account must not be used by individuals for normal day to day activities.
Application and Information Access
Access within software applications must be restricted using the security features built into the individual product. The [Name a department – e.g. IT Helpdesk or ‘business owner’] of the software application is responsible for granting access to the information within the system. The access must [amend list as appropriate]:
· Provide compliance instructions (list 3).
If any user is found to have breached this policy, they may be subject to [Name’s] disciplinary procedure. If a criminal offence is considered to have been committed further action may be taken to assist in the prosecution of the offender(s).
If you do not understand the implications of this policy or how it may apply to you, seek advice from [name appropriate department].
This policy will be reviewed as it is deemed appropriate, but no less frequently than every 12 months.
Policy review will be undertaken by [Name an appropriate role].
The following [Name] policy documents are directly relevant to this policy, and are referenced within this document [amend list as appropriate]:
· Remote Working Policy.
The following [Name] policy documents are indirectly relevant to this policy [amend list as appropriate]:
List three other policies that may be necessary for the technicians to read as background (i.e.: Local email use; Acceptable use, etc.)
Summarize the most important points of the policy for Access