preview

Policy Framework : Management Of Information Security

Decent Essays

Policy Framework
Management of Information Security
• At board level, responsibility for Information Security shall reside with the Head of ICT.
• The managers shall be responsible for enforcing, implementing, monitoring, documenting and communicating security policy requirements for the company.
• All staff, permanent or temporary, and third party contractors must be aware of the information security procedures and comply.

Information Security Training

• Information security training shall be borne in the staff induction process.
• An ongoing awareness program shall be established and maintained in this company to ensure that staff awareness is refreshed and updated as necessary.
Contracts of Employment

• Staff security requirements shall be addressed at the recruitment phase and all contracts of employment shall contain a clause for confidentiality.
• The job description of all staff shall clearly state the company’s expectations as it relates to information security.

Acceptable conduct
• Emails shall not contain offensive and abusive messages, indecent images and materials that harasses others.
• Internet access must be used strictly for official purposes. Indecent and offensive websites, personal downloads and unofficial discussion sessions will not be acceptable.
• All mobile devices and tablet PCs must not be used for unapproved business purposes.

Employee Termination

• Employee credentials shall be deactivated immediately upon termination of employee contract

Get Access