TaylorMaid Security
|
Information Security Example High Level Policy |
||||
|
come.to/TaylorMaid/ |
Author: Martin Taylor |
10Oct00 |
Ó TaylorMaid Security |
|
1 Purpose
The purpose of this document is to enable the primary leaders of this organisation to discharge their duty of care in respect to Information Security.
2 Scope
This document applies to all employees of this organisation and all other people who are granted access to this organisation's information.
Information includes all information within the organisation regardless of how it is stored, processed or transported e.g. whether in the memory of individuals or in the memory of computers.
3 Contract
This document forms part of the contract of employment for employees and part of the contract of use for all other people granted access to this organisation's information
4 Policy
4.1 Information is Valuable
Information is one of the most important assets of this organisation.
4.2 The Information World is Complex
The world where information is stored, transported and processed is complex. It is likely that information will suffer loss or harm through accident. It is possible that information will suffer loss or harm through deliberate acts.
4.3 Information Protection
Valuable information requires protection. Information shall be protected by controls designed to minimise loss or damage through accident, negligence or deliberate actions.
4.4 Management Responsibility
Managers are responsible and accountable for the information within their areas. They will ensure that appropriate procedures and practises are followed to provide protection for such information, and to protect the means whereby that information is stored, processed or transported.
4.5 Information Ownership
Information shall be assigned an owner who will ensure appropriate levels of protection are applied. Where ownership is not clear, or where there is a dispute, the final decision on allocation of ownership shall rest with the Chief Information Officer.
4.6 Information Risk
Consistent with financial risk and operational risk, information risk shall be considered and afforded a priority in all decisions within an organisation.
4.7 Risk Assessment
A risk assessment process balancing vulnerability to threats against cost shall be used in deciding appropriate controls to be used to protect information.
4.8 Individual Accountability
Each individual shall be accountable for their actions and have a duty of care to ensure due diligence is afforded to information security. Accountability can not be delegated.
4.9 Secure by default
Information assets should be secured unless specifically authorised otherwise. Information assets include information and the means by which that information is stored, transported and processed.
4.10 Individuals are human
We are all fallible. Some individuals will be totally hostile. Some individuals will not take due care. Some will not easily understand instructions. There will be a need to protect information as a result.
4.11 Openness
Information should be made available to enable organisational operations to function.
4.12 Need to Know
Sensitive information shall have additional restrictions applied to ensure access only by those with an authorised ‘need to know’.
5 Policy statements useful to, but not unique to Information Security
5.1 Applicable LawThe organisation will comply with all applicable laws and regulations.
5.2 Disciplinary Action
Individuals involved in unauthorised activity may be subject to disciplinary action. This may extend to dismissal and to legal proceedings.
5.3 Incident Reporting
Individuals that are affected by security relevant incidents must report them following the appropriate process.
6 Essential supporting documentation
6.1 Employment Contract
Each individual must have a contract of employment. The body of policy must form part of that contract.
6.2 Third Party Access Agreement
There must be a contract established with each third party which must ensure that the relevant parts of the Information Security Policy is binding upon the third party and other parties and individuals contracted to it that are storing, transporting or processing the organisation's information.
6.3 Disciplinary Process
This should document the steps that should be followed when disciplinary action is necessary.
6.4 Incident Reporting Process
This should document the steps that should be followed by an individual reporting an incident. It should also document the processes that will be used to evaluate the severity of the incident and the escalation steps that may be necessary to ensure recovery from the incident. It will include appropriate links to the Organisation Continuity Policy and Processes and the Media Contact Policy and Processes.
6.5 Organisation Continuity Policy and Processes
This should document the organisation's approach to continuity of operation in the event of a major disaster.
6.6 Media Contact Policy and Processes
This should document the organisation's approach to the press, TV and other media.
Appendix Z Document History
|
Date |
Change |
By |
|
23Sep00 |
First Internet version |
Martin Taylor |
|
6Oct00 |
'Useful, but not Unique' section |
Martin Taylor |
|
10Oct |
'Related Documentation' section |
Martin Taylor |
|
|
|
|