Purpose and Scope
This policy establishes responsibilities and operating controls for the secure use of company networks, computers, accounts and business data.
Core Requirements
- Access rights shall follow job responsibilities and the principle of least privilege.
- Passwords, authentication credentials and confidential data shall not be shared or stored in unsecured locations.
- Company devices shall use approved software, security updates and endpoint protection.
- Important business data shall be backed up and recovery procedures shall be tested regularly.
- Suspicious email, malware, account misuse or data loss shall be reported immediately.
Employees and service providers using company information systems are required to comply with this policy and applicable laws.
