RE: IT Security Policy & Procedures Manual

Subject: RE: IT Security Policy & Procedures Manual
From: KMcLauchlan -at- chrysalis-its -dot- com
To: "TECHWR-L" <techwr-l -at- lists -dot- raycomm -dot- com>
Date: Fri, 16 Feb 2001 09:00:46 -0500

Some things to add:

Restriction of physical access to IT equipment areas
(server rooms, etc.)

Requirement for users installing (with permission)
specialty software and one-of-a-kind software to
"escrow" the installation media AND any activation
codes with IT dept.

Requirement for each computer user to refrain from
altering the Administrator or Root account on their
machines (so that IT personnel can get access to fix,
upgrade, etc.).

Password rules, including:
- change intervals
- minimum length of passwords
- minimum requirements for mixed characters
- penalties for being caught with your password
taped to the inside of your desk drawer or under
your mousepad...

If your company allows/encourages Remote Access, then
you'll need a whole slew of procedures and rules to
cover that.

Also rules for safeguarding company info on home PCs
that are used to connect to the office.

Also rules for safeguarding company info on laptops
that are carried home or on business trips.


> -----Original Message-----
> From: Dick Margulis [mailto:margulis -at- mail -dot- fiam -dot- net]
> Sent: Thursday, February 15, 2001 7:52 PM
> Subject: Re: IT Security Policy & Procedures Manual
> Merv,
> This topic just came up today, coincidentally. If you are
> aiming for a comprehensive policy, you want to include an
> agreement/acknowledgment that all employees sign and that
> specifies proscribed behaviors.
> The range of behaviors you have to address includes, but is
> not limited to:
> What software it is permissible to install on a
> company-provided computer, along with related licensing issues

Develop HTML-Based Help with Macromedia Dreamweaver 4 ($100 STC Discount)
**WEST COAST LOCATIONS** San Jose (Mar 1-2), San Francisco (Apr 16-17) or 800-646-9989.

Sponsored by ForeFront, Inc., maker of ForeHelp Help authoring tools
for print, WinHelp, HTML Help, JavaHelp, and cross-platform InterHelp
See for more information and free evaluation downloads

You are currently subscribed to techwr-l as: archive -at- raycomm -dot- com
To unsubscribe send a blank email to leave-techwr-l-obscured -at- lists -dot- raycomm -dot- com
Send administrative questions to ejray -at- raycomm -dot- com -dot- Visit for more resources and info.

Previous by Author: RE: Help: '97 to 2000 Access question
Next by Author: RE: reviewing: the saga continues
Previous by Thread: Re: IT Security Policy & Procedures Manual
Next by Thread: Re: IT Security Policy & Procedures Manual

What this post helpful? Share it with friends and colleagues:

Sponsored Ads