Internet & Information Security Policy Manual

(QMS-ISPL-M-IIS)

 

 

 

Version No

V20

Prepared by

 

Date

30-01-2015

 

Name

 

Krishna Prasad Vendra

 

Signature

 

 

Date

 

30-01-2015

Copy No

 

 

Approved by

Issued to

 

 

 

Name

 

Sai Prasad Koneru

 

Signature

 

 

Date

 

30-01-2015

 


 

Document Amendment Record

 

 

A-                        Added, M- Modified, D- Deleted

 

Sl.No

Date

Version No

Page No

Change Mode(A/M/D)

Brief description of change

1

11-01-2005

 

V01

N/A

A

Initial Release

2

28-02-2006

V02

N/A

M

Modified the name of the antivirus software using in Inooga Solutions Pvt Ltd in the section 7.1.4.1 and the time of schedule updated from 8hrs to 3hrs.

3

06-06-2012

V02

N/A

D

The Company address information is removed from the Footer

4

30-01-2015

V20

N/A

N/A

Reviewed and base lined

 


 

Table of Contents

 

1.         Purpose. 4

2.         Objective. 4

3.         Scope. 4

4.         Terms & Definitions. 4

5.         Entry criteria, Input, Activity, Output, Exit criteria. 4

6.         Responsibilities. 4

7.         Process description. 5

7.1       Antivirus Policy. 5

7.1.1                    Purpose. 5

7.1.2                    Objective. 5

7.1.3                    Scope. 5

7.1.4                    Description. 5

7.2       Information Sensitivity Policy. 7

7.2.1                    Purpose. 7

7.2.2                    Objective. 7

7.2.3                    Scope. 7

7.2.4                    Description. 7

7.3       Password Policy. 9

7.3.1                    Purpose. 9

7.3.2                    Objective. 9

7.3.3                    Scope. 9

7.3.4                    Description. 9

7.4       Email Policy. 12

7.4.1                    Purpose. 12

7.4.2                    Objective. 12

7.4.3                    Scope. 12

7.4.4                    Description. 12

 

 

 

 

1.           Purpose

 

To implement and maintain a policy at Inooga Solutions (Inooga) for

 

  • prevention of virus attacks,
  • email communication,
  • information and security management
  • password management

 

for the users of the Inooga network and hardware/software systems.

 

2.           Objective

 

The objective of this policies is to ensure virus free systems, email security, protection of information and security of internet and controlling unauthorized acces to users thereby maintaining high uptime and security of the systems.

 

3.            Scope

 

This policy will be applicable to all Inooga computers, but does not include, PC,  Storage Media deployed or used by Inooga staff at their residence or during the out station duty.

 

4.           Terms & Definitions

 

Abbreviations/Terms

Description

PC

Personal Computer

MB

Mega bytes

 

 

5.           Entry Criteria, Input, Activity, Output, Exit Criteria

 

Sl. No.

Entry Criteria

Input

Activity

Output

Exit Criteria

1.

Understanding the need of defining and implementing various policies for ensuring network security and maintenance of Inooga hardware-/ software systems

 

Identification of the required policies for Inooga to ensure network security and maintenance of hardware-/ software systems.

Definition of the policies defined for Inooga for network security and hardware-/ software maintenance.

Ensuring implementation of the defined policies for network security and hardware -/ software maintenance

Verification of proper maintenance of the defined policies.

 

 

6.           Responsibilities

 

Implementation of the defined policies – users of the allocated hardware/software systems and system administrator.

 

 

7.           Process Description

 

7.1            Antivirus Policy

 

7.1.1        Purpose

 

A virus is a piece of self –replicating code, most often a malicious software program designed to destroy or damage information on computers. Some viruses cause no damage, but a significant number are specifically designed to cause data loss. Potential sources of viruses include shared media such as floppy disk or CDs, e-mail and documents downloaded  from internet. A virus infection is almost always costly to the organization  whether through the loss of data, staff time to recover a system, or the delay of important work.

 

The purpose of the Anti-Virus policy is to prevent infection of Inooga computers and computer systems by computer viruses and other malicious code. This policy is intended to prevent major and widespread damage to user applications, files, and hardware.

7.1.2        Objective

 

The objective of this policy is to ensure virus free systems, thereby maintaining high uptime of the systems.

 

7.1.3        Scope

This policy will be applicable to all Inooga computers, but does not  include PC, storage media deployed or used by the Inooga staff at their residence or during the out station duty.

7.1.4         Description

 

7.1.4.1       General

 

·          Inooga  has installed Kaspersky Antivirus Corporate Edition on all the Computers.

 

  • The latest anti-virus upgrades are automatically downloaded from Kaspersky website http://www.kaspersky.com  on scheduled time for every 3 hours.
  • The downloaded virus definition is automatically loaded on Antivirus server.
  • The automated live update feature of the anti-virus server software downloads all the latest patches for every two hours. For every two hours client checks for update to the server and if server definition is newer than client, client automatically gets updated.
  • Scheduled scan on client computers of respective user and “abort scan” is disabled   everyday
  • All the remote incoming and outgoing E Mail through the Inooga server will be scanned for virus by the kaspersky Exchange anti virus solution.
  • Only folders can be shared with password protection in order to avoid virus spreading of drive sharing of PCs.

 

7.1.4.2       Recommended processes to prevent virus problem:

 

·          NEVER open any files or macros attached to an email from an unknown, suspicious or untrustworthy source. Delete these attachments immediately, then "double delete" them by emptying the trash.

 

·          Delete spam, chain, and other junk email without forwarding

 

·          Never download files from unknown or suspicious sources.

 

·          Avoid direct disk sharing with read/write access unless there is absolutely a business requirement to do so.

 

·          Always scan a floppy diskette from an unknown source for viruses before using it.

 

·          Back-up critical data and system configurations on a regular basis and store the data in a safe place.

 

·          When the anti-virus software is disabled, do not run any applications that could transfer a virus, e.g., email or file sharing.

 

·          New viruses are discovered almost every day. Periodically check the Anti-Virus Policy and the recommended processes list for updates.

 

 

 

 

7.4            Information Sensitivity Policy           

7.2.1           Purpose

 

The purpose of the Information Sensitivity Policy is to provide guidelines to be followed by all Inooga employees for protecting Inooga’s confidential information. This includes information about Inooga, Inooga’s business or Inooga’s clients and their business and covers information on all media as well as information received from all communication channels..

 

It should be noted that the sensitivity keyword is used as a guideline and to emphasize common sense steps that one can take to protect Inooga confidential information. This policy does not define the confidential information, but only provides guidelines to be followed to protect the Inooga confidential information. 

7.2.2           Objective

 

The Information Sensitivity Policy is intended to help employees determine what information can be disclosed to non-employees, as well as the relative sensitivity of information that should not be disclosed outside of Inooga without proper authorization.

7.2.3           Scope

 

This policy is applicable to all the information pertaining to Inooga and its related activities.

7.2.4           Description

 

To avoid any possible damages to information security, the following steps are taken where information is categorized into three classes below.

 

  • High Risk or Highly sensitive -  Examples of this type of information include  financial , legal and business related information, payroll and personnel data or data which falls under the class of privacy requirement etc. This policy recognizes that other data may need to be treated as high risk because it would cause severe damage to Inooga if disclosed or modified. The data owner should make this determination. It is the data owner’s responsibility to implement the necessary security requirements.

 

  • Confidential - This includes the information that should be protected very closely, such as trade secrets, drawings & design, development programs, potential acquisition targets and any other information integral to the success of Inooga. This also includes confidential information belonging or pertaining to another corporation , which has been entrusted to Inooga by that company under non-disclosure agreements and other contracts. Examples of this type of information include joint development efforts, customer & supplier information etc.

 

  • Public - Inooga public information is information that has been declared public knowledge by someone with the authority to do so and can be freely be given to anyone without any possible damage to Inooga.

 

It is recommended that the information, which is sensitive and has restricted access, should be clearly marked as highly sensitive. Inooga personnel are encouraged to use best judgment in securing Inooga confidential information to the proper extent

 

All Inooga documents are marked for sensitivity of information. Marking is at the discretion of the owner or custodian of the information. If the marking is desired, the words Inooga Confidential, Inooga Proprietary or any other at the discretion of individual business unit or department can be used. Also non-disclosure clause should be used wherever applicable. This marking can be used in hardcopy or when distributed through Electronic mail.

 

If no marking is present Inooga information is presumed to be Inooga confidential unless explicitly determined to be Inooga Public information by an Inooga employee with authority to do so.

 

In order to have proper access and security  controls all the Inooga family members are expected to follow Inooga password, Email and backup policy in addition to the Inooga non disclosure clause. Highly sensitive information should be encrypted during transmission over insecure channels. If the encryption is not available the same should not be transmitted over insecure channel.

 

 

 

 

7.5              Password Policy                     

7.2.5       Purpose

 

The purpose of the Password Policy is to establish a standard for creation of strong passwords, the protection of those passwords, and the frequency of change of passwords.

7.2.6    Objective

 

The objective of this policy is to ensure that all Inooga family members including contractors and vendors with access to Inooga systems are responsible for taking the appropriate steps, as outlined below, to select and secure their passwords.

7.2.7    Scope

 

The scope of this policy includes all personnel who have or are responsible for an account or any form of access that supports or requires a password on any system that resides at any Inooga facility, has access to the Inooga network, or stores any non-public Inooga information.

7.2.8    Description

 

7.3.4.1.      General

 

  • All system-level passwords (e.g., root, enable, NT admin, application administration accounts, etc.) must be changed on at least a quarterly basis.
  • All user-level passwords (e.g., email, web, desktop computer, etc.) must be changed at least every 45 days.
  • Passwords must not be inserted into email messages or other forms of electronic communication.
  • Inooga family members are not supposed to disclose their password to others. Inooga family members are required to  give his or her password to his Departmental Head only when he or she is going on leave or on leaving the company.
  • Inooga family members are not supposed to access others’ systems without prior permission of the department Head/CTO.
  • All the systems will be locked, by the policy of server, if they keep the system idle for more than 15 minutes.

 

 

 

 

 

7.3.4.2       Guidelines

 

A.   General Password Construction Guidelines

Passwords are used for various purposes at Inooga. Some of the more common uses include: user level accounts, web accounts, email accounts, voicemail password, and local system logins. Everyone should be aware of how to select strong passwords.

 

Poor, weak passwords have the following characteristics:

 

  • The password contains less than seven characters
  • The password is a word found in a dictionary (English or foreign)
  • The password is a common usage word such as:
    • Names of family, pets, friends, co-workers, fantasy characters, etc.
    • Computer terms and names, commands, sites, companies, hardware, software.
    • The words "INOOGA", "sachin", "anita" or any derivation.
    • Birthdays and other personal information such as addresses and phone numbers.
    • Word or number patterns like aaabbb, qwerty, zyxwvuts, 123321, etc.
    • Any of the above spelled backwards.
    • Any of the above preceded or followed by a digit (e.g., secret1, 1secret).

 

 

Strong passwords have the following characteristics:

 

  • Contain both upper and lower case characters (e.g., a-z, A-Z)
  • Have digits and punctuation characters as well as letters e.g., 0-9, !@#$%^&*()_+|~-=\`{}[]:";'<>?,./
  • Are at least seven alphanumeric characters long.
  • Are not a word in any language, slang, dialect, jargon, etc.
  • Are not based on personal information, names of family, etc.
  • Passwords should never be written down or stored on-line. Try to create passwords that can be easily remembered. One way to do this is create a password based on a song title, affirmation, or other phrase. For example, the phrase might be: "This May Be One Way To Remember" and the password could be: "TmB1w2R!" or "Tmb1W>r~" or some other variation.

 

NOTE 1: Do not use either of these examples as passwords!

 

NOTE 2: All passwords created by Inooga users who access Inooga systems in any form should follow the above mentioned characteristics as a policy.


 

 

B.   Password Protection Standards

 

Do not use the same password for Inooga accounts as for other non-Inooga access (e.g., personal ISP account, option trading, benefits, etc.). Where possible, don't use the same password for various Inooga access needs. For example, select a separate password to be used for an NT account and a UNIX account.

 

 

Do not share Inooga passwords with anyone, including administrative assistants or secretaries. All passwords are to be treated as sensitive, confidential Inooga information.

 

Here is a list of "dont's":

 

  • Don't reveal a password over the phone to ANYONE
  • Don't reveal a password in an email message 
  • Don't talk about a password in front of others
  • Don't hint at the format of a password (e.g., "my family name")
  • Don't reveal a password on questionnaires or security forms
  • Don't share a password with family members
  • Don't reveal a password to co-workers while on vacation

 

 

If someone demands a password, refer them to this document or have them call the CTO/CEO.

 

Do not use the "Remember Password" feature of applications  (e.g., Eudora, OutLook, Netscape Messenger).

 

Again, do not write passwords down and store them anywhere in your office. Do not store passwords in a file on ANY computer system (including Palm Pilots or similar devices) without encryption.

 

Change passwords at least once every 45 days (except system-level passwords which must be changed quarterly).

 

If an account or password is suspected to have been compromised, report the incident to CTO/CEO and change all passwords.

 

Password cracking or guessing may be performed on a periodic or random basis by Network administrator/CTO. If a password is guessed or cracked during one of these scans, the user will be required to change it.


 

 

C.   Application Development Standards

 

Application developers must ensure their programs contain the following security precautions.:

 

  • should support authentication of individual users, not groups.
  • should not store passwords in clear text or in any easily reversible form.
  • should provide for some sort of role management, such that one user can take over the functions of another without having to know the other's password.

 

 

7.6          Email Policy                     

7.2.9       Purpose

 

The purpose of Email Policy is to assure that

 

  • Inooga employees and third parties working at any Inooga premises are informed about the Inooga Email Policy.
  • Electronic Mail Services are used in compliance with those policies and laws.
  • Users of Electronic Mail Services are informed about how concept of privacy and security apply to Electronic Mail.

7.2.10Objective

 

The objective of this Email policy is to ensure that all the Inooga users are aware of the email policy followed at Inooga and implementation of the policy to prevent unauthorized usage of the Email services.

7.6.3          Scope

 

This policy is applicable to all the users of Inooga Electronic Mail services using the Inooga.com domain at Inooga or at any other site outside the premises of Inooga.

7.6.4          Description

1.                        New Email creation

 

  • Based on the service request raised by the HR and General affairs department new user along with email will be created.
  • The standard Email format unless otherwise specified is first name followed by surname @inooga.com .
  • In instances where several users have same name ,an initial or other character will be added to the Email name.
  • Generally Email account are valid for the user’s entire tenure with Inooga unless requested for deletion by the Human Resources Department.

 

2.                      Deletion of  Email user account 

 

  • Email user account will be deleted based on the service request raised by the HR and General affairs department.
  • It is the responsibility of the concerned department to take the backup of the Email( If required by them) before the employee leaves.

 

3.                      Purpose of  Use 

 

  • The use of Inooga Electronic Mail must be related to Inooga business.

 

4.                      Prohibited Uses of Electronic Mail 

 

List given below is indicative

 

  • The Inooga Electronic Mail resources shall not be used for personal monetary gain or for commercial purpose that are not directly related to Inooga business.
  • Sending unsolicited, confidential, sensitive and proprietary information via Email.
  • Any form of harassment via Email,
  • Sending copies of document in violation of copyright laws.
  • Use of Email for any illegal purpose.
  • Spend an unreasonable amount of time on personal Email.
  • Send company-wide virus alerts. Please forward any such information to Network administrator, so that appropriate action can be taken.
  • Make or post indecent remarks, proposals or materials.
  • Sending junk (Spam) mail, creating or forwarding “chain letters” or schemes.
  • Unauthorized use , or forging , of email header information.
  • Mailing system is for official usage only ; do not use mailing facility for mass mailing of personal information like invitation to parties, jokes etc.
  • Sending or receiving Email that unnecessarily block or tie up network  traffic.

 

 

5.                      Sending of  Email 

 

Employees must exercise utmost caution when sending any email from Inooga network to an outside network. Sensitive information will not be forwarded via any means, unless that email is critical to business and prior concern with higher authorities.

 

6.                      Restriction on size of message

 

There is no specific restriction on the user but they must follow the guidelines for sending and receiving messages on local & remote network.

  • Roaming Users – Maximum mail box size of 5MB. (in some cases maximum 10 MB )
  • 1 –2 MB while sending or receiving to / from the internet ( remote)
  • 3-5 MB while sending or receiving to / from on local Inooga network

 

7.                      Email retention/backup

 

All the Email users have to keep back-up of their own Email depending upon the importance of the information.

 

8.                      Personal usage

 

There is no specific restriction on the usage of Inooga Email for personal use. But users must take utmost caution & must follow the guidelines given in Prohibited Uses of Electronic Mail & follow the Inooga rule in this regard as defined in other policies.

 

9.                      Email monitoring 

 

Inooga encourages the use of Email and respects the privacy of users. It  will not monitor Email as a routine matter unless specifically requested by the Human Resources or when there is substantiated reason to believe that violations to the Inooga Email and other policy by the Email user