IT Security Policy

profilejessiebear932
p2_local_policy_sample_with_template.docx

Data Center Local Policy

Policy Document

Access Control Policy

Enter your Name:

_____________________________________

Professor Last Name: Landreville

Document Control

[CSIA 413, Today’s Date]

Organization

[Name of your chosen organization]

Title

[Name of the Local Policy ]

Author

[Your Name ]

Owner

Data Center Manager

Subject

IT Local Access Policy

Review date

Date of Completion of Policy

Revision History

Revision Date

Reviser

Previous Version

Description of Revision

Changes to your draft are provided here

Document Approvals

This document requires the following approvals:

Sponsor Approval

Name

Date

Approved

[CEO, CISO, etc.]

Enter date of submission to folder

Document Distribution

This document will be distributed to:

Name

Job Title

Email Address

All Data Center Staff

Technicians

Enter your email address

Contributors

Development of this policy was assisted through information provided by the following organization:

· Enter your organization

Contents

List the contents of the policy

Table of Contents

1

2

3

4

5

Policy Statement

[ ] will establish specific requirements for protecting information and information systems against unauthorized access.

[ ] will effectively communicate the need for information and information system access control.

Purpose

Information security is the protection of information against accidental or malicious disclosure, modification or destruction. Information is an important, valuable asset of [ name of your chosen organization ] which must be secured from threats and vulnerabilities must be identified and patched. All information has a value to the organization. Access controls are essential to protect information by controlling user rights for information resources and by guarding against unauthorized use. Formal procedures must control how access to information is granted and how such access is changed.

This policy includes the following access control measures [enter 5 local policy protections for your chosen organization based on a brief risk assessment using FIPS 199 and FIPS 200].

Scope

This policy applies to all [ BE THOROUGH IN SCOPE ] (including system support staff, contractual third parties and agents with any form of access to the data center information and information systems.

Definition

Access control rules and procedures are required to regulate who can access information resources or systems and the associated access privileges. This policy applies at all times and should be adhered to whenever accessing information in any format, and on any device.

Risks

On occasion business information may be disclosed or accessed prematurely, accidentally or unlawfully. Individuals or companies, without the correct authorization and clearance may intentionally or accidentally gain unauthorized access to business information which may adversely affect day to day business. This policy is intended to mitigate that risk.

Non-compliance with this policy could have a significant effect on the efficient operation of the data center and may result in financial loss and an inability to provide necessary services to our customers.

Risk Assessment and level of risk

Identify weaknesses in the system.

Identify possible threats and vulnerabilities in the system.

SIGNATORY AUTHORITY (Enter CISO Name)

Include the following information in your local policy

Applying the Policy – Employee Access

User Access Management

Formal user access control procedures must be documented, implemented and kept up to date for each application and information system to ensure authorized user access and to prevent unauthorized access. They must cover all stages of the lifecycle of user access, from the initial registration of new users to the final de-registration of users who no longer require access. These must be agreed by the system administrator. Each user must be allocated access rights and permissions to computer systems and data that:

· List constraints on what the user in the data center is allowed to view, read, change

User access rights must be reviewed at regular intervals to ensure that the appropriate rights are still allocated. System administration accounts must only be provided to users that are required to perform system administration tasks.

User Registration

A request for access to the computer systems must first be submitted to the [Name a department – e.g. Information Services Helpdesk] for approval. Applications for access must only be submitted if approval has been gained from [Name a role – e.g. your line manager].

When an employee leaves access to computer systems and data must be suspended at the close of business on the employee’s last working day. It is the responsibility of the [Name a role – e.g. your line manager] to request the suspension of the access rights via the [Name a department – e.g. Information Services Helpdesk].

User Responsibilities

It is a user’s responsibility to prevent their userID and password being used to gain unauthorized access to systems by:

· Following the Password Policy Statements outlined above in Section 6.

· Add three more user responsibilities

Network Access Control

The use of modems on non-owned PC’s connected to the network can seriously compromise the security of the network. The normal operation of the network must not be interfered with. Specific approval must be obtained from [Name a department – e.g. Information Services] before connecting any equipment to the network.

User Authentication for External Connections

Where remote access to the [ Name] network is required, an application must be made via the [Name a department – e.g. IT Helpdesk]. Remote access to the network must be secured by two factor authentication consisting of a username and one other component, for example a [Name a relevant authentication token]. For further information please refer to [name a relevant policy -likely to be Remote Working Policy].

Supplier’s Remote Access to the Network

Partner agencies or 3rd party suppliers must not be given details of how to access the network without permission from [Name a department – e.g. IT Helpdesk]. Any changes to supplier’s connections must be immediately sent to the [Name a department – e.g. IT Helpdesk] so that access can be updated or ceased. All permissions and access methods must be controlled by [Name a department – e.g. IT Helpdesk].

Partners or 3rd party suppliers must contact the [Name a department – e.g. IT Helpdesk] before connecting to the [ Name] network and a log of activity must be maintained. Remote access software must be disabled when not in use.

Operating System Access Control

Access to operating systems is controlled by a secure login process. The access control defined in the User Access Management section (section 7.1) and the Password section (section 6) above must be applied. The login procedure must also be protected by:

· Provide security controls to protect unauthorized access from the table below

All access to operating systems is via a unique login id that will be audited and can be traced back to each individual user. The login id must not give any indication of the level of access that it provides to the system (e.g. administration rights).

System administrators must have individual administrator accounts that will be logged and audited. The administrator account must not be used by individuals for normal day to day activities.

Application and Information Access

Access within software applications must be restricted using the security features built into the individual product. The [Name a department – e.g. IT Helpdesk or ‘business owner’] of the software application is responsible for granting access to the information within the system. The access must [amend list as appropriate]:

· Provide compliance instructions (list 3).

Policy Compliance

If any user is found to have breached this policy, they may be subject to [Name’s] disciplinary procedure. If a criminal offence is considered to have been committed further action may be taken to assist in the prosecution of the offender(s).

If you do not understand the implications of this policy or how it may apply to you, seek advice from [name appropriate department].

Review and Revision

This policy will be reviewed as it is deemed appropriate, but no less frequently than every 12 months.

Policy review will be undertaken by [Name an appropriate role].

References

The following [Name] policy documents are directly relevant to this policy, and are referenced within this document [amend list as appropriate]:

· Remote Working Policy.

The following [Name] policy documents are indirectly relevant to this policy [amend list as appropriate]:

List three other policies that may be necessary for the technicians to read as background (i.e.: Local email use; Acceptable use, etc.)

Key Messages

Summarize the most important points of the policy for Access