Internet
& Information Security Policy Manual
(QMS-ISPL-M-IIS)
|
Version
No |
V20 |
Prepared by |
|
|
Date |
30-01-2015 |
Name |
|
|
Signature |
|
||
|
Date |
30-01-2015 |
||
|
Copy No |
|
Approved by |
|
|
Issued
to |
|
Name |
Sai Prasad Koneru |
|
Signature |
|
||
|
Date |
30-01-2015 |
||
Document
Amendment Record
A- Added, M- Modified, D- Deleted
|
Sl.No |
Date |
Version No |
Page No |
Change Mode(A/M/D) |
Brief description of change |
|
1 |
|
V01 |
N/A |
A |
Initial Release |
|
2 |
|
V02 |
N/A |
M |
Modified the name of the antivirus software using in Inooga Solutions
Pvt Ltd in the section 7.1.4.1 and the time of schedule updated from 8hrs to
3hrs. |
|
3 |
06-06-2012 |
V02 |
N/A |
D |
The Company address information is
removed from the Footer |
|
4 |
30-01-2015 |
V20 |
N/A |
N/A |
Reviewed and base lined |
Table of Contents
5. Entry
criteria, Input, Activity, Output, Exit criteria
7.2 Information Sensitivity Policy
To implement
and maintain a policy at Inooga Solutions (Inooga) for
for the users of the Inooga network and hardware/software systems.
The objective of this policies is
to ensure virus free systems, email security, protection of information and
security of internet and controlling unauthorized acces to users thereby
maintaining high uptime and security of the systems.
3.
Scope
This policy will be applicable to
all Inooga computers, but does not include, PC,
Storage Media deployed or used by Inooga staff at their residence or
during the out station duty.
|
Abbreviations/Terms |
|
|
PC |
Personal Computer |
|
MB |
Mega bytes |
5.
Entry
Criteria, Input, Activity, Output, Exit Criteria
|
Sl. No. |
Entry Criteria |
Input |
Activity |
Output |
Exit Criteria |
|
1. |
Understanding the
need of defining and implementing various policies for ensuring network security
and maintenance of Inooga hardware-/ software systems |
Identification
of the required policies for Inooga to ensure network security and
maintenance of hardware-/ software systems. |
Definition
of the policies defined for Inooga for network security and hardware-/
software maintenance. |
Ensuring
implementation of the defined policies for network security and hardware -/
software maintenance |
Verification
of proper maintenance of the defined policies. |
Implementation of the defined
policies – users of the allocated hardware/software systems and system
administrator.
7.1
Antivirus Policy
7.1.1
Purpose
A virus is a piece of self
–replicating code, most often a malicious software program designed to destroy
or damage information on computers. Some viruses cause no damage, but a
significant number are specifically designed to cause data loss. Potential
sources of viruses include shared media such as floppy disk or CDs, e-mail and
documents downloaded from internet. A
virus infection is almost always costly to the organization whether through the loss of data, staff time
to recover a system, or the delay of important work.
The purpose of the Anti-Virus
policy is to prevent infection of Inooga computers and computer systems by
computer viruses and other malicious code. This policy is intended to prevent major
and widespread damage to user applications, files, and hardware.
7.1.2
Objective
The objective of this policy is
to ensure virus free systems, thereby maintaining high uptime of the systems.
7.1.3
Scope
This
policy will be applicable to all Inooga computers, but does not include PC, storage media deployed or used by
the Inooga staff at their residence or during the out station duty.
7.1.4
Description
7.1.4.1
General
·
Inooga has installed Kaspersky Antivirus Corporate
Edition on all the Computers.
7.1.4.2
Recommended processes to prevent
virus problem:
·
NEVER open any files or macros attached to an email
from an unknown, suspicious or untrustworthy source. Delete these attachments
immediately, then "double delete" them by emptying the trash.
·
Delete spam, chain, and other junk email without
forwarding
·
Never download files from unknown or suspicious
sources.
·
Avoid direct disk sharing with read/write access
unless there is absolutely a business requirement to do so.
·
Always scan a floppy diskette from an unknown
source for viruses before using it.
·
Back-up critical data and system configurations on
a regular basis and store the data in a safe place.
·
When the anti-virus software is disabled, do not
run any applications that could transfer a virus, e.g., email or file sharing.
·
New viruses are discovered almost every day.
Periodically check the Anti-Virus Policy and the recommended processes list for
updates.
7.4
Information
Sensitivity Policy
The purpose of the Information
Sensitivity Policy is to provide guidelines to be followed by all Inooga employees
for protecting Inooga’s confidential information. This includes information
about Inooga, Inooga’s business or Inooga’s clients and their business and
covers information on all media as well as information received from all
communication channels..
It should be noted that the
sensitivity keyword is used as a guideline and to emphasize common sense steps
that one can take to protect Inooga confidential information. This policy does not
define the confidential information, but only provides guidelines to be
followed to protect the Inooga confidential information.
The Information Sensitivity Policy is intended to help employees
determine what information can be disclosed to non-employees, as well as the
relative sensitivity of information that should not be disclosed outside of
Inooga without proper authorization.
This policy is applicable to all
the information pertaining to Inooga and its related activities.
To avoid any possible damages to
information security, the following steps are taken where information is
categorized into three classes below.
It is recommended that the
information, which is sensitive and has restricted access, should be clearly
marked as highly sensitive. Inooga personnel are encouraged to use best
judgment in securing Inooga confidential information to the proper extent
All Inooga documents
are marked for sensitivity of information. Marking is at the discretion of the
owner or custodian of the information. If the marking is desired, the words
Inooga Confidential, Inooga Proprietary or any other at the discretion of
individual business unit or department can be used. Also non-disclosure clause
should be used wherever applicable. This marking can be used in hardcopy or
when distributed through Electronic mail.
If no marking is present Inooga
information is presumed to be Inooga confidential unless explicitly determined
to be Inooga Public information by an Inooga employee with authority to do so.
In order to have proper access
and security controls all the Inooga
family members are expected to follow Inooga password, Email and backup policy
in addition to the Inooga non disclosure clause. Highly sensitive information
should be encrypted during transmission over insecure channels. If the
encryption is not available the same should not be transmitted over insecure
channel.
7.5
Password Policy
The purpose of the Password Policy is to establish a
standard for creation of strong passwords, the protection of those passwords,
and the frequency of change of passwords.
The objective of this policy is to ensure that all Inooga family members
including contractors and vendors with access to Inooga systems are responsible
for taking the appropriate steps, as outlined below, to select and secure their
passwords.
The scope of this policy includes all personnel who have or are
responsible for an account or any form of access that
7.3.4.1.
General
7.3.4.2
Guidelines
A. General Password
Construction Guidelines
Passwords are used for various purposes at Inooga.
Some of the more common uses include: user level accounts, web accounts, email
accounts, voicemail password, and local system logins. Everyone should be aware
of how to select strong passwords.
Poor, weak passwords have the following characteristics:
Strong passwords have the following characteristics:
NOTE 1: Do not use either of these examples as passwords!
NOTE 2: All
passwords created by Inooga users who access Inooga systems in any form should
follow the above mentioned characteristics as a policy.
B. Password Protection
Standards
Do not use the same password for Inooga accounts as for other non-Inooga
access (e.g., personal ISP account, option trading, benefits, etc.). Where
possible, don't use the same password for various Inooga access needs. For
example, select a separate password to be used for an NT account and a UNIX
account.
Do not share Inooga passwords with anyone, including administrative
assistants or secretaries. All passwords are to be treated as sensitive,
confidential Inooga information.
Here is a list of "dont's":
If someone demands a password, refer them to this document or have them
call the CTO/CEO.
Do not use the "Remember Password" feature of applications (e.g., Eudora, OutLook, Netscape Messenger).
Again, do not write passwords down and store them anywhere in your
office. Do not store passwords in a file on ANY computer system (including Palm
Pilots or similar devices) without encryption.
Change passwords at least once every 45 days (except system-level
passwords which must be changed quarterly).
If an account or password is suspected to have been compromised, report
the incident to CTO/CEO and change all passwords.
Password cracking or guessing may be performed on a periodic or random
basis by Network administrator/CTO. If a password is guessed or cracked during
one of these scans, the user will be required to change it.
C. Application Development
Standards
Application developers must ensure their programs contain the following
security precautions.:
The purpose of Email Policy is to
assure that
The objective of this Email
policy is to ensure that all the Inooga users are aware of the email policy
followed at Inooga and implementation of the policy to prevent unauthorized
usage of the Email services.
This policy is applicable to all
the users of Inooga Electronic Mail services using the Inooga.com domain at
Inooga or at any other site outside the premises of Inooga.
2.
Deletion
of Email user account
4.
Prohibited
Uses of Electronic Mail
List given below is indicative
Employees must exercise utmost caution when sending any email from Inooga
network to an outside network. Sensitive information will not be forwarded via
any means, unless that email is critical to business and prior concern with
higher authorities.
6.
Restriction
on size of message
There is no specific restriction
on the user but they must follow the guidelines for sending and receiving
messages on local & remote network.
All the Email users have to keep
back-up of their own Email depending upon the importance of the information.
There is no specific restriction
on the usage of Inooga Email for personal use. But users must take utmost caution & must follow the guidelines given in Prohibited Uses of Electronic
Mail & follow the Inooga rule in this regard as defined in other policies.
Inooga encourages the use of
Email and respects the privacy of users. It
will not monitor Email as a routine matter unless specifically requested
by the Human Resources or when there is substantiated reason to believe that
violations to the Inooga Email and other policy by the Email user