close

What Is Truth to Power?

dedicated to bridging the gaps between governance and practice, technology and business, regulation and control, risk management and real market pressures, and your own knowledge and the knowledge of your peers.

built to create a common pool of knowledge—one big brain—that lets you work more efficiently, build technology and business practices more effectively, and endure audits more effortlessly.

a neutral hub through which you can reach many valuable information nodes, resource collections, and organizations that are helping people like you already, but in fractured ways.

against the idea that auditors, analysts, and consultancies can control information simply through their ability to collect and distill it. T2P's goal is to unlock the vast body of knowledge, insight, and conventional wisdom that we all have, make it freely available to you, and help you digest and interpret it—without undue cost, bias, or hype.

Top Panel
WHAT IS T2P?
Top Panel
 
Personnel Security (Policy)
------- INDEX AND GLOSSARY. DO NOT CHANGE OR DELETE! ----------
-------------------------------------------------------------------------------------------------

Overview and Purpose

Intentional and unintentional misuse and abuse of [variable: Covered Organization] systems pose the greatest threats to information confidentiality, integrity, and availability. Therefore, [variable: Covered Organization] requires that all users of organizational information systems meet minimum personnel requirements related to the sensitivity of their roles, suitability for employment, personnel investigations, and other personnel security considerations.

Coverage

All personnel who use, manage, design, or implement [variable: Covered Organization] Information Resources.

Roles and Responsibilities

Director

  • Publishes and maintains policy guidelines for personnel security
  • Determines the security access requirements for all positions
  • Ensures that all personnel have undergone the appropriate background checks and security training

Information Security Officer (ISO)

  • Prepares personnel security policy
  • Monitors the adherence to the personnel security policy
  • Ensures all personnel are trained in the computer security responsibilities and duties associated with their jobs

Supervisor

  • Communicates to the users the personnel security requirements outlined in this policy
  • Monitors the adherence to the personnel security policy
  • Ensures all personnel are trained in the computer security responsibilities and duties associated with their jobs
  • Informs [variable: covered Organization or System] Security Officer when access is to be removed
  • [variable: Role] is responsible for tracking new personnel account requests, creation, issues, and deletions.

[variable: Covered Organization or system] Security Officer

  • Monitors compliance with personnel security policy
  • Promptly deletes passwords for systems and applications under their control when users terminate employment, suspect passwords are compromised, or no longer need access
  • [variable: Role] is responsible for tracking users and their access authorizations.

Users

  • Understand their personnel security responsibilities and duties
  • Use [variable: covered Organization] information in accordance with job functions, internal policy, and external regulations and laws
  • Immediately notify supervisor of suspected misuse of data, security breaches, violations of policies and procedures, or compromise of password security

Policy

  • All organizational positions (users, application managers, system management personnel, and security personnel) must be defined. Security issues related to the functions and responsibilities of these positions must be be identified and addressed.
  • Access privileges for any given position must be based on principles of 1) Separation of Duties and 2) Least Privilege.
  • All employees are subject to a limited background check, depending on role and system access needs.
  • Employees shall be trained in computer security responsibilities and duties associated with their jobs.
  • User account management on a system will be reviewed not less than once per [variable: time period] and/or under the following criteria and conditions: [variable: review trigger(s) or criteria]
  • Managers will follow established procedures for:
    • Personnel transfers or discontinuation the associated changes to or removal of access privileges, system accounts, and authentication tokens.
    • Control of [variable: Covered Organization] physical keys
    • Training employees on their responsibilities for confidentiality and privacy
    • Return of [variable: Covered Organization] property and ongoing availability of data generated by individual employees.
    • Involuntary termination and consequences, such as suspension of user accounts and, in some cases, the physical removal of personnel from the [variable: Covered Organization] offices.
  • Periodic reinvestigation of personnel background and qualifications may be required.

Enforcement

Gross negligence or willful disclosure leading to illicit exposure of [variable: Covered Organization] information may result in prosecution for misdemeanor or felony resulting in fines, imprisonment, civil liability, and/or dismissal. [variable: Cite relevant laws, policies, or statutes to support enforcement.]

Supporting Documentation

This policy is supported by the following rules, standards, and procedures:

  • [variable: internal documents (with links, if available)]
  • [variable: external documents (with links, if available)]

Policy Support Contact

  • [variable: title (not personal name) of role responsible for overseeing this procedure]
  • [variable: Contact information of office responsible for overseeing this procedure]

References

Research Resources

 

Hide comment form

Antispam Refresh image Case sensitive