• Home
  • Sydney City College of Management
  • Diploma of Information Technology
  • Information Security Policy and Procedures

Information Security Policy and Procedures

INTERNATIONAL INSTITUTE OF EDUCATION RTO 45150 | CRICOS 03838G Information Security Policy and Procedures Purpose The purpose of this document is to outline the security procedures that are enforced within the company. The procedures stated here are applicable to all employees and contractors. User Identification and Passwords Each user is allocated an individual username and password. Logon passwords must not be written down or disclosed to another individual. Users are held responsible for all actions performed using this user name. Staff must notify the IT Help Desk when moving to a new position or location within the company. This ensures that the necessary setups to provide fast access to the most appropriate mail and file servers can be put in place. Management must notify IT of staff changes. All user accounts have the following password settings: · Minimum password length of 8 characters; · A combination of alpha, numeric and punctuation should be used; . Passwords must not be easily guessed (i.e. names, months of the year, days of the week, usernames, etc. must not be used as passwords). Access to company Information All information held on the networks including email, file systems and databases are the property of the company and staff should have no expectation of privacy for this data. Although it is not the general practice of our company to monitor stored files, email messages and Internet access for their general content, we reserve the right to do so for the protection of staff, for system performance, maintenance, auditing, security or investigative functions (including evidence of unlawful activity or breaches to policy) and to protect itself from potential corporate liability. Requests to access the computer account of a member of staff who is absent from the office must be directed to the IT team. Staff must not issue any information to third parties unless they have authorisation to do so. Users are only permitted to access electronic information and data that they require to perform their duties. If confidential information is lost, either through loss of a notebook computer, backup media or other security breach, the IT team must be notified immediately. All computers must be switched off at the end of the day. Version: 1.0 Page:1 International Institute of Education RTO:45150 | CRICOS: 03838G File Name: ICTCYS407 Simulation Pack Revised Date: 9/12/2021 INTERNATIONAL INSTITUTE OF EDUCATION RTO 45150 | CRICOS 03838G Security Computers must not be left unattended for long periods while signed on e.g. during breaks. Users must either logoff or activate a password-controlled screensaver if they are leaving their PC. The screensaver should be set to activate by default after 10 minutes of inactivity. IT equipment must not be removed from our premises unless written approval has been received. Software must not be copied, removed or transferred to any third party or non-organisational equipment such as home PCs without written authorisation from the IT team. Only software that has been authorised by the IT team may be used on computers connected to t network.