Security
Security Policy
CONTENTS
Revision History
1. NETWORK ACCESS POLICY
1.1. User Identification and Passwords
1.2. Access to company Information
1.3. Personal use of computer systems
2. SERVERS, NOTEBOOK and PC SECURITY POLICY
2.1. General
2.2. Software
2.3. Confidentiality
2.4. Portable devices—Notebooks, iPhones and Tablets (iPad)
2.5. Computer Viruses
2.6. Wireless Access
2.7. Ethernet Ports
2.8. Remote/VPN Access
2.9. Remote Machines
3. INTERNET AND EMAIL POLICY
3.1. Internet
3.2. Email
5. THIRD PARTY ACCESS POLICY
6. SOFTWARE LICENCE POLICY
7. DATA BACKUP POLICY
8. IT DEPARTMENT RESPONSIBILITIES
8.1. User Identification and Passwords
8.2. Network Monitoring
8.3. Security Logs
8.4. Incident Mitigation and Data Breaches
9. APPENDIX
9.1. Security Notice—External Email Disclaimer
9.2. Security Notice—Logon Notice
10. ACCEPTANCE AND ACKNOWLEDGEMENT
Revision History
|
Name |
Date |
Version |
Comments |
|
|
Eric Cain |
6/1/2011 |
1 |
|
|
|
Data Protection Officer |
4/11/2012 |
2 |
|
|
|
Phillip Hanegan |
4/12/2012 |
3 |
|
|
|
Alex Mirza |
9/2/2020 |
4 |
Added Client Access Details, and Asset Management |
|
|
Brad Mandell |
10/7/2020 |
5 |
Added Requirements concerning personally identifiable data and general edits |
|
Please Note – Non-compliance may lead to disciplinary action being taken.
The Dot Net Factory, LLC, IT SECURITY POLICY
1. NETWORK ACCESS POLICY
1.1. User Identification and Passwords
Each user is allocated an individual user name and password. Logon passwords must not be written down or disclosed to another individual. The owner of a particular user name will be held responsible for all actions performed using this user name.
Requests for new computer accounts and for termination of existing computer accounts must be formally authorized to the IT Help Desk/relevant IT resource by the relevant manager. Requests for additional access to specific business applications, e.g. Financial Accounts must be authorized in writing to the IT Dept. /resource by the relevant application owner.
Staff must notify the IT Help Desk/relevant IT resource when moving to a new position or location within The Dot Net Factory, LLC. This ensures that the necessary setups to provide fast access to the most appropriate mail and file servers can be put in place. The Staff are not permitted to take IT equipment such as PCs or notebook computers when moving to another position within The Dot Net Factory, LLC.
Line management must notify IT of staff changes that might affect security. An example of this would be an individual who has access to restricted confidential client information and moves to another role where this access is not required.
All user accounts have the following password settings:
o User account cannot be in the domain admins or administrators group
o Minimum password length of 8 characters;
o A combination of alpha, numeric and punctuation should be used;
o Users are forced to change their passwords every 60 days;
o Users cannot use the previous 2 passwords;
o For users that need elevated privileges a separate user account is given admin rights must be used for administrative tasks only.
o Accounts are locked out after 3 three unsuccessful logon attempts to any resource on the network.
Passwords must not be easily guessed (i.e. names, months of the year, days of the week, usernames, etc. must not be used as passwords).
1.2. Access to company Information
All information held on the networks including email, file systems and databases are the property of The Dot Net Factory, LLC, LLC and staff should have no expectation of privacy for this data.
Although it is not the general practice of The Dot Net Factory, LLC, to monitor stored files, email messages and Internet access for their general content, The Dot Net Factory, LLC reserves the right to do so for the protection of staff, for system performance, maintenance,
auditing, security or investigative functions (including evidence of unlawful activity, improper data access or breaches of The Dot Net Factory, LLC policy) and to protect itself from potential corporate liability.
Requests to access the computer account of a member of staff who is absent from the office must be directed to the IT Help Desk/relevant IT resource in writing by the "Relevant Manager". The access is given effect by changing the user's password and allowing the "Relevant Manager" or a colleague to access the account directly. Where this access is granted it must be used for enquiry purposes only.
Staff must not issue any information to third parties unless they have authorization to do so.
Users are only permitted to access electronic information and data that they require to perform their duties.
If confidential information is lost, either through loss of a notebook computer, backup media or other security breach, the IT Help Desk/relevant IT resource must be notified
immediately.
1.3. Personal use of computer systems
While The Dot Net Factory, LLC PCs and notebook computers are provided for business use, it is acceptable to use them for a limited amount of personal use. This limited personal use
of PCs is permitted provided such use does not a) interfere with the user's job commitments;
or b) have a detrimental effect on the computer or network's performance.
Staff must not use The Dot Net Factory, LLC systems or the Internet for commercial activities that are not related to the business of The Dot Net Factory, LLC.
2. SERVERS, NOTEBOOK and PC SECURITY POLICY
2.1. General
PCs and notebook computers must not be left unattended for long periods while signed-on e.g. during lunch, coffee breaks etc. Users must either logoff or activate a password- controlled screensaver if they are leaving their PC. The screensaver should be set to activate by default after 10 minutes of inactivity.
IT equipment must not be removed from The Dot Ney Factory premises unless written approval has been received from the IT Department/relevant IT resource. An exception is made for authorized off-site back-ups providing they are adequately protected against unauthorized access. All notebooks must be signed for before being removed from The Dot Net Factory, LLC premises.
Employees may request equipment as needed to complete their work, requests should be put in writing to the Office Manager and the IT department. All equipment provisioned to employees is tracked in the EmpowerID asset management system. If a request is granted, the item is to be documented and tracked within the asset management system.
If equipment is broken, non-working, or does not perform adequately to the requirements of the work an employee has been given, the employee should report this to his manager immediately so that this situation can be corrected in a timely manner.
2.2. Software
Software must not be copied, removed or transferred to any third party or non- organizational equipment such as home PCs without written authorization from the IT Department.
Only software that has been authorized by the IT Department may be used on PCs and notebook computers connected to The Dot Net Factory, LLC IT network.
Downloading of any executable files (.exe) or software from the Internet is forbidden without written authorization from the IT Department/relevant IT resource. Staff may be given this authorization based on their specific job requirements (Developers, etc).
Regular reviews of desktop software are undertaken, and the presence of unauthorized software will be investigated. The Dot Net Factory, LLC reserves the right to remove any files or data from IT systems including any information it views as offensive or illegal.
2.3. Confidentiality
Confidential data held on computer media (e.g. USB drives) must be stored securely when not in use.
PCs and notebooks for disposal must have the hard disk Removed and destroyed before they are distributed outside The Dot Net Factory, LLC
All confidential information that employees have access to for specific job requirements
such as client information, client databases for development etc, users will only access when required to for specific business purposes (Such as development, or support). Employees will not remove, copy, export, or transmit any confidential information from The Dot Net
Factory, LLC networks or premises without the express written approval of Management.
The Dot Net Factory, LLC is accountable under numerous privacy initiatives across the global markets it serves, including HIPAA, GDPR, CCPA, and many others. Employees of the The Dot Net Factory, LLC are also individually liable under many of these laws and it is therefore imperative that employees responsibly handle all client data. This imposes specific responsibilities on all employees, including:
i. When providing support, technical assistance or consulting, do not copy, record or transmit the identifiable personal information recorded in client systems that you may observe, except as minimally required to resolve a problem.
ii. Never bulk transport data outside of a client jurisdiction in which it resides (i.e. if the data is located in Switzerland, do not copy it outside of Switzerland, even if copying it from one client system to another). Do not advise clients to bulk transfer data to us. We cannot keep, store or process live client data on our systems. Any exceptions to this must always be in writing from our VP of Engineering and Data Protection Officer, the Data Protection Officer
iii. Never share personally identifiable information with anyone except for the sole and narrowly defined business purpose of providing technical support. This includes all information, including phone numbers, corporate extensions and other data that you may not consider private or important, but can still be subject to privacy protections
iv. Never discuss or post any information regarding any personally identifiable information that you observe in the performance of your work
v. Never post information outside of corporate systems that identify our customers, or any individual that you may observe information about in the course of performing your work.
2.4. Portable devices—Notebooks, iPhones and Tablets (iPad)
All reasonable precautions must be taken to protect equipment against damage, loss and theft. The equipment must not be left unattended in any public place. Damage, loss or theft must be immediately reported to the relevant IT resource
Anti-virus software is installed on all notebook computers.
Data must be backed-up to the network on a regular basis and notebook users must ensure that the data on their notebook computers is adequately backed up.
Devices such as iPhones and Tablets must be set with a switch-on pin number and must not be used to store sensitive information.
Staff must not leave a portable device unattended at any time when not secured.
2.5. Computer Viruses
Corruption of PC's or notebook's data or software by malicious software (e.g. a computer virus or a worm) must be reported to the IT Help Desk/relevant IT resource.
Users are not permitted to disable or remove antivirus software under any circumstances.
Users are not permitted to access corporate or client systems with systems that are not approved by the company. Any system used for company work must be protected by an approved and up to date anti-virus program.
Unauthorized screen savers are not permitted, as they are a potential source of computer virus. If in doubt, please contact the IT Help Desk/relevant IT resource for advice.
2.6. Wireless Access
Wireless access is secured by a WPA2 key and is given out only on an as needed basis as determined by the network administrator.
All approved devices must have their MAC addresses documented for auditing purposes.
All non-employees must use The Dot Net Factory, LLC DMZ wireless.
All non-production devices including test and demo computers and network devices are prohibited from using wireless.
2.7. Ethernet Ports
Only Ethernet ports that are consistently used are patched to a switch to prevent unauthorized access.
2.8. Remote/VPN Access
Remote Access can be defined as "Access to The Dot Net Factory, LLC IT resources or data from a location external to The Dot Net Factory, LLC". This access may be by a third party or an employee who is located off-site.
All notebook computer users must ensure they have remote access software to connect securely to The Dot Net Factory, LLC IT systems.
For cost and other security reasons remote connections must be closed as soon as a search is completed.
Telephone numbers that are used to access The Dot Net Factory, LLC computers must not be listed in public telephone directories and must not be disclosed to unauthorized personnel.
All computers connecting to the corporate office must have antivirus software installed and up to date.
All connections are logged and monitored. These logs must conform to the log policy for auditing and retention.
Users needing remote access must do so by use of the corporate Remote Desktop Gateway or via Privileged Session Manager (PSM). You may never use alternate remote access facilities without the express written permission of the the Data Protection Officer, the Data Protection Officer.
No ports will be forwarded into the production or test networks.
The VPN uses two-factor authentication by use of VPN group username and password as well as a local database of users on the firewall.
Passwords are updated by the user and must conform to corporate complexity standards.
Remote desktop access is given to customers who wish to demo the EID software. These servers are in The Dot Net Factory, LLC DMZ isolated from other machines and listen on nonstandard ports. The servers are constantly monitored and restored after each use.
2.9. Remote Machines
Machines outside the test and development networks are joined to the corporate domain to apply standard security group policies.
Sensitive information must not be kept on the local machines, but on a network share which is secured to the authenticated user only.
Demo and client development systems are not joined as a matter of policy to The Dot Net Factory, LLC production network. These are either running standalone or joined to a demo domain, do not join them to other domains, including client domains, without the express written permission of the Data Protection Officer, the Data Protection Officer.
3. INTERNET AND EMAIL POLICY
3.1. Internet
All staff has a responsibility to use the Internet in a professional, ethical and lawful manner.
Users must regard Internet access as a privilege, which can be revoked.
Users should exercise caution when making payments over the Internet, as the security of credit card details cannot be guaranteed. The Dot Net Factory, LLC will accept no liability for losses arising through the transmission of personal or financial information (e.g. Credit Card numbers) over the Internet.
Users must not use The Dot Net Factory, LLC Internet facilities to download, display, generate and/or pass on to others material whether in text, pictures or any other form, which would be regarded as offensive. It is important to note that what constitutes offensive material is not one for the sender to determine - it is the effect on anyone viewing the material that is considered important. In law, possession of some material may be deemed
to be a serious criminal offence, whether in the workplace or otherwise.
All access to the Internet from The Dot Net Factory, LLC network will be via an approved channel that will be secured by a firewall.
Users must not deliberately perform acts that waste computer resources or unfairly monopolize resources to the exclusion of others. These acts include, but are not limited to, sending mass mailings or chain letters, spending excessive amounts of time on the Internet, failing to exit from websites, engaging in online chat groups, uploading or downloading large files, accessing streaming audio and/or video files, or otherwise creating unnecessary loads on network traffic associated with non-business-related uses of the Internet.
Users must not use the same passwords for login to Internet websites as they do internally for The Dot Net Factory, LLC systems.
The Dot Net Factory, LLC reserves the right to review, audit, intercept, access and disclose all access to the Internet. This includes emails sent and received in addition to websites visited and files downloaded from the Internet.
3.2. Email
Email users must exercise caution with any external attachments other than those received from a trusted source, as these attachments may contain a computer virus.
Users must not represent themselves as another individual in electronic communications.
Email users must be aware of the risks associated using email to send confidential or commercially sensitive information.
Users must ensure that documents attached to emails are not copyright protected.
Email messages must be appropriate and professional.
As email is a form of publishing and covered by relevant publishing Acts, libelous and defamatory material is not permitted.
Users must not use email for transmitting data of a personal nature related to a third party.
If any person receives email, which they deem to be inappropriate, offensive or illegal, they must inform their "Relevant Manager". Immediate reporting of incidents facilitates more successful identification of the source and other details.
All emails that are sent externally may optionally carry a standard company disclaimer. Users must not attach their own disclaimers to emails.
Software is in place to monitor incoming and outgoing external email messages. Messages that contain text which indicate that they may have come from an unsolicited source are
'quarantined' by the software and an automatic email is sent to The Dot Net Factory, LLC sender or recipient to inform them that a message has been stopped. Please contact the IT Help Desk/relevant IT resource if you receive a quarantine message.
4. Client Environment Access
Depending on your role within the organization you may have business requirements that require you to have access to client environments (IE, Client Machines, Servers, DB, etc.). Employees may only access client’s environments with the documented consent of the client. Employees while accessing client environments may only access client systems as
designated by the client for the express purpose of completing work as designated by the client and The Dot Net Factory, LLC.
Employees must adhere to all aspects of the EmpowerID Data Access and Security Policies,
as they pertain to client environments, including rules surrounding the removal of protected data from the client environment. Protected data includes such thing as Personal
Identifiable information (IE, EmpowerID DB Backups), client configurations, client documentation, etc.
Employees will under no circumstances connect to client systems from personal machines that are not the property of The Dot Net Factory, LLC. Employees are only allowed to access client environments from their work computers that have been provisioned and configured by the EmpowerID IT Department. Remote Employees or Employees that are Work from Home (WFH) employees are required to access their Office workstations via one of the supported remote access methods and use their office workstation to access client environments.
Employees will not under any circumstances commit actions that puts the security of the client environment as risk, including: connecting to client environments from machines that may be compromised, sharing access information to employees that are not authorized to access client environments, download malicious or unsecured software onto client environments, attempting to circumvent security policies or procedures that the client have put in place or any other action that risks the security of the client environment.
5. THIRD PARTY ACCESS POLICY
Third Party Access can be defined as "The granting of access to The Dot Net Factory, LLC IT
resources or data to an individual who is not an employee of The Dot Net Factory, LLC".
Examples of third parties include:
o Software vendor who is providing technical support;
o Contractor or consultant;
o Service provider; and
o An individual providing outsourced services to The Dot Net Factory, LLC requiring access to applications or data.
Third Party Access can only be provided after the Third Party has signed a confidentiality agreement that must be included in their formal contract with “The Dot Net Factory, LLC”. The Dot Net Factory, LLC staff must never permit another individual to utilize their user name to access The Dot Net Factory, LLC network.
Further requirements for granting Third Party Access are:
o Risk analysis process;
o Approval by Data Owner;
o Approval by the Head of IT/relevant IT resource;
Third party access will only be permitted to facilities and data which are required to perform specific agreed tasks as identified by “The Dot Net Factory, LLC”.
6. SOFTWARE LICENCE POLICY
Copyright stipulations governing vendor-supplied software must always be observed.
The IT Department/relevant IT resource is responsible for maintaining records of software licenses. Software that is acquired on a trial basis must be used in accordance with the vendor's copyright instructions.
All software developed within The Dot Net Factory, LLC is the property of The Dot Net Factory, LLC and must not be copied or distributed without prior written authorization from the IT Department.
7. DATA BACKUP POLICY
The IT Department must ensure regular backups of the main servers for which they are responsible for managing.
Users must always save important data and files on the network as opposed to the local hard disk for recovery purposes. All users’ computers are also deployed with secondary drives for back and archival purposes as well. This ensures that regular backups are taken and are available for recovery purposes. Users should be aware that data saved on the local hard disk is not backed up by the IT Department/relevant IT resource
8. IT DEPARTMENT RESPONSIBILITIES
This section contains policy guidelines, which are the responsibility of the IT Department.
8.1. User Identification and Passwords
All unused usernames must be deleted following an initial period when they are disabled.
Line managers must inform the IT Help Desk/relevant IT resource when staff leave The Dot
Net Factory, LLC to ensure that their usernames are promptly removed.
Staff transferring sections within The Dot Net Factory, LLC must have their access privileges reviewed and altered based on their new responsibilities, following notification to the IT Help Desk/relevant IT resource by the person moving location.
Usernames must conform to the standard The Dot Net Factory, LLC naming convention. The convention must be used consistently across all applications and platforms.
When the IT Help Desk/relevant IT resource are unsure of the identity of the user requesting a password change, then authorization must be received from relevant manager before the request is auctioned.
The Dot Net Factory, LLC hardware and software must have the vendor-supplied default passwords changed on installation. This applies to test as well as live environments.
8.2. Network Monitoring
All inbound and outbound traffic from the firewall is mirrored to a network monitoring server.
The monitoring server acts as an IDS and NSM.
If an anomaly is found, the network security team is alerted to investigate the issue.
If an issue is not a false positive it must be reported to the relevant manager in the security team so that corrective action is taken immediately.
Vulnerability scanning software is used to scan all networks on a regular schedule.
8.3. Security Logs
Logs from the network devices and servers must be kept and archived for auditing purposes.
Each device must implement full logging to ensure that all activity is captured.
Security logs must be kept for a minimum of 1 year.
Logs are to be backed up daily and archived monthly.
All security incidents must be reviewed and reported immediately to IT management staff.
Incidents must be investigated, and corrective measures must be taken as needed.
Audits of all logs will be performed on a schedule to ensure compliance.
8.4. Incident Mitigation and Data Breaches
In the event of a device compromise, it must be immediately taken off the network or isolated.
After the machine is taken off the network or isolated the issue must be brought to the attention of the security manager.
An audit of all the logs on the device and any other devices involved, such as the firewall, will take place.
The configuration of these other devices must be reviewed for any possible problems, and if problems are discovered they must be remedied.
The logs on the targeted device must be reviewed to isolate the root cause. After the incident is cleared, the target machine must be reinstalled and the vulnerability fixed.
DATA BREACH: If you suspect that a) the conditions for a data breach (involving client or company information or data) have occurred, or b) data has been accessed or removed by an unknown party, you must notify the Data Protection Officer, the Data Protection Officer within 8 hours, no exceptions. At that time a Data Protection Team will begin an investigation to determine if a breach has occurred and if any client notifications must be issued.
9. APPENDIX
9.1. Security Notice—External Email Disclaimer
This email may contain information, which is confidential and/or privileged. The information is intended solely for the use of the individual or entity named above. If you are not the intended recipient, be aware that any disclosure, copying, distribution or use of the contents is prohibited. If you have received this electronic transmission in error, please notify the sender by telephone or return email and delete the material from your computer.
The Dot Net Factory, LLC
Web: www.empowerid.com
*********************************************************************
This email message has been scanned for viruses.
*********************************************************************
9.2. Security Notice—Logon Notice
Unauthorized access to The Dot Net Factory, LLC computer systems is prohibited.
You are reminded that your PC user name and password are for your use only and it is your duty to ensure that they are never made available to others. Actions carried out on The Dot Net Factory, LLC systems will be deemed to be the responsibility of the user name holder. The Dot Net Factory, LLC reserves the right to monitor user activity.
The Dot Net Factory, LLC IT security policy covers issues relating to use of the internet, email, confidentiality of information, personal use of the systems, Irish legislation, physical security of IT assets and software licensing.
By logging on you are accepting that you understand and will adhere to the IT Security Policy while logged on to The Dot Net Factory, LLC network.
Please contact the IT Department/relevant IT resource if you have any queries regarding this policy.
10. Acceptance and Acknowledgment
I agree to have read and understood this document and if anything is not understood or contradictory to me, I will ask my manager to explain it to my satisfaction. I agree to follow the stated procedures and policies at all times.
I understand that any violation of this agreement will result in disciplinary action which may include but is not limited to the following: written discipline, revocation of the user's accounts, termination of employment, and/or legal action for the mishandling and/or misuse of client or company information. Permanent revocations may result from recommendations by the Information Technology department of The Dot Net Factory, LLC or other authorities which may be called upon to investigate computer and/or network abuse. Disciplinary action as related to employment, as documented in The Dot Net Factory, LLC Policies and Procedures, will be determined solely by The Dot Net Factory, LLC according to the nature of the violation.
By signing this agreement, I acknowledge the responsibility to protect client and corporate data according to the policies stated herein, and to recognize my personal responsibility to not record, not save and to not disclose client or corporate data in any manner in conflict with these policies.
I also agree to report any data breach, or suspected data breach to an officer of the company immediately upon its discovery, but no later than 8 hours upon becoming aware of such an event.
|
|