You are on page 1of 3

IT Security Policy

Objective:
Provide appropriate guidelines for productively utilizing the SCP resources that protects the employee
and SCP.

Policy

Justification

Use of the Internet by staff is permitted and


encouraged where such use supports the goals
and objectives of the SCP.

Use of the Internet is monitored for legitimate


security and network management reasons.

Users should not visit Internet sites that contain


racist, obscene, hateful or other objectionable
materials or encourage others to do so on their
behalf.

Use of email by employees is permitted and


encouraged where such use is suitable for
institute purposes and supports the goals and
objectives of the company.

Internet Access & Usage

Email Access &Usage

Covers general, financial, corporate


information & some personnel and technical
information
To ensure the scope SCP IT department will monitor,
Information
Sensitivity

The volume of Internet, network traffic and


email traffic.

The domain names and / or IP addresses of


Internet sites visited and domain and / or IP
addresses of email received.

The specific content of any transactions will not


be monitored unless there is a suspicion of
improper use.

Audit

Wireless Communication

Covers user level and/or system level access to


any computing or communications device
monitoring to prevent unauthorized access.
Maintain point to point hardware encryption of
at least 56 bits. Maintain a hardware address
that can be registered and tracked.

Password protection

Establish a standard for creation of strong


passwords the protection of those password.

Approval

Antivirus

Employees are prohibited from disabling antivirus software running on company provided
computer equipment to maximize protection.

You might also like