close

What Is Truth to Power?

dedicated to bridging the gaps between governance and practice, technology and business, regulation and control, risk management and real market pressures, and your own knowledge and the knowledge of your peers.

built to create a common pool of knowledge—one big brain—that lets you work more efficiently, build technology and business practices more effectively, and endure audits more effortlessly.

a neutral hub through which you can reach many valuable information nodes, resource collections, and organizations that are helping people like you already, but in fractured ways.

against the idea that auditors, analysts, and consultancies can control information simply through their ability to collect and distill it. T2P's goal is to unlock the vast body of knowledge, insight, and conventional wisdom that we all have, make it freely available to you, and help you digest and interpret it—without undue cost, bias, or hype.

Top Panel
WHAT IS T2P?
Top Panel
 
Network Access (Policy)
------- INDEX AND GLOSSARY. DO NOT CHANGE OR DELETE! ----------
-------------------------------------------------------------------------------------------------

Overview and Purpose

The [variable: Covered organization] network infrastructure is a central utility for employees, contractors, partners, and vendors. It connects people, business processes, offices, and systems. To protect the network, as well as systems available through the network, it is important for all employees to observe rules that safeguard access to and use of the network infrastructure. These rules exist to preserve the integrity, availability and confidentiality of critical information that supports business functions.

Coverage

All individuals with access to any [variable: Covered organization] Information Resource.

Definitions

Network Access Policy

  • Users may use only those network addresses issued to them by [variable: covered Organization] IT management
  • All remote dial-in access (dial in services) must be either through an approved modem pool or via an Internet Service Provider (ISP).
  • Remote users may connecting to [variable: covered Organization] through an ISP must use protocols approved by IT management
  • Users inside the [variable: covered Organization] firewall may not be connected to the internal network at the same time they are connected to an external network.
  • Users must not extend or re-transmit network services via routers, switches, hubs, wireless access points, etc., without prior approval from IT management.
  • Users must not install network hardware or software that provides network services without prior approval from IT management.
  • Non-[variable: covered Organization] computer systems that require network connectivity must conform to [variable: covered Organization] IT standards.
  • Users must not download, install or run security programs or utilities that reveal weaknesses in system security (for example, password cracking programs, packet sniffers, network mapping tools, or port scanners) while connected in any manner to [variable: covered Organization] network infrastructure.
  • Users must not alter network hardware in any way.

Enforcement

Violation of this policy may result in disciplinary action which may include termination for employees and temporaries; a termination of employment relations in the case of contractors or consultants; dismissal for interns and volunteers; or suspension or expulsion in the case of a student. Additionally, individuals are subject to loss of [variable: covered Organization] Information Resources access privileges, civil, and criminal prosecution.

Supporting Documentation

This policy is supported by the following rules, standards, and procedures:

  • [variable: internal documents (with links, if available)]
  • [variable: external documents (with links, if available)]

Policy Support Contact

  • [variable: title (not personal name) of role responsible for overseeing this procedure]
  • [variable: Contact information of office responsible for overseeing this procedure]

References

Policy Models(s)

State of Texas, Department of Information Resources

 

Hide comment form

Antispam Refresh image Case sensitive