Think HR Think CHRM
Thursday - 9 Feb 2012

CHRMGlobal.com on LinkedIn
Username : Password: Forgot Password?
Information Security Policy
Human Resources » Policies & Samples


Chrm Message From: tracy_m Total Posts: 28 Join Date: 19/08/2006
Rank: Executive Post Date: 24/08/2006 03:07:45 Points: 140 Location: United States

Hello All,

Can any one help me out with a draft of Information Security Policy and Procedure for a medium size software development company.

Thanks and Regards

Tracy

Chrm Message From: CHRM Total Posts: 178 Join Date: 19/08/2006  
Rank: Leader Post Date: 24/08/2006 04:50:47 Points: 890 Location: United States

Dear Tracy,

Though the draft of information security policy is not something that is available freely on the internet, let me give you few pointers on the same :-

- Access to information is strictly role based

- Access is on a need-to-know basis.

- Partner and Customer specific information is shared and maintained within a well-defined control group.

- Information of Partners and Customers is agreed during the initiation of the engagement and appropriate confidentiality agreements are signed.

- In addition, the senior management of the organisation is governed by a legal & ethical framework, which ensures that they will not be in a position to misuse/ abuse the information that they absorb as part of their roles.

- All facilities have security personnel who monitor asset movement and ensure that proper documentation.

- Development areas are restricted by access control systems, which allow only authorised staff movement in each area.

- In terms of information security, the networks are protected through firewalls and detection systems.

- Network access for staff is role based.

- Access to Product literature and software is regulated based on the role and needs of the staff.

- All other software and product information is available only on specific approvals.

Members to pour in their views on this topic ??

Regards,

CHRM







Chrm Message From: tracy_m Total Posts: 28 Join Date: 19/08/2006  
Rank: Executive Post Date: 25/08/2006 00:22:59 Points: 140 Location: United States

Dear chrm,

The pointers were really helpful in understanding the basic principles and points to be considered for preparation of an informatin security policy draft.

Thanks for the prompt and helpful response.

Regards,

Tracy

 
Events
 
Related Discussion
Components of Information
Leave Policy for BPO
Need Information on Asses
Leave Encashment Policy
Cell Phone usage in the o
Policy on Late coming
Policy Review
HR POLICY MANUAL TEMPLATE
Sliding Scale Leave Polic
Help Needed on Recruitmen
 
Related Articles
The Requirement of Inform
Being there - An Open Doo
Information Architecture
Win-Win Policy a Must for
Human Resource Informatio
Data Security Challenges
The Carrot & Stick Policy