Cyberstudy
PDF p.432 In progress

Conduct Policies

Open PDF at p.432 18 flashcards

Summary

PDF p.432

Operational policies include privilege/credential management, data handling, and incident response. Important security policies also govern employee conduct and respect for privacy, such as acceptable use policies, codes of conduct, and clean desk policies.

In plain words

Supplementary — not from your PDF

Conduct policies govern employee behaviour. The acceptable use policy (AUP) protects the organization from misuse (fraud, defamation, illegal material, unauthorized hardware/software, snooping) and must be reasonable. A code of conduct sets professional standards and notes that communications are logged and monitored, and may cover social media and privileged access. Personal devices bring risks (copying, cameras, recording) managed with NAC, endpoint management and DLP, and shadow IT is a concern. A clean desk policy keeps sensitive documents off work surfaces.

Detailed explanation

PDF p.432
  • Acceptable Use Policy (AUP)
    • Definition: Protects the organization from security and legal implications of equipment misuse.
    • Prohibitions: Defrauding, defaming, obtaining illegal material, installing unauthorized hardware/software, snooping on confidential data.
    • Guidelines: Must be reasonable and not interfere with job duties or privacy rights.
    • Internet Use: May restrict to work-related duties or break times.
  • Code of Conduct and Social Media Analysis
    • Definition: Sets out expected professional standards.
    • Risks: Virus infection, system intrusion, lost work time, copyright infringement, defamation.
    • Data Communications: Likely stored, logged, and monitored.
    • Social Media Monitoring: Employers may analyze personal accounts for policy infringements.
    • Privileged Access: Clauses to prevent misuse of privileges by technicians and managers.
  • Use of Personally Owned Devices in the Workplace
    • Threats: File copying, camera, and voice-recording functions.
    • Controls: Network access control, endpoint management, data loss prevention solutions.
    • Enforcement: Difficult to prevent staff from bringing personal devices on-site.
    • Shadow IT: Unauthorized use of personal software/services poses security vulnerabilities.
  • Clean Desk Policy
    • Definition: Work areas should be free from documents.
    • Purpose: Prevent unauthorized access to sensitive information.

Important terms

taken from the text above
Acceptable Use Policy (AUP)
Protects the organization from security and legal implications of equipment misuse.
Prohibitions
Defrauding, defaming, obtaining illegal material, installing unauthorized hardware/software, snooping on confidential data.
Guidelines
Must be reasonable and not interfere with job duties or privacy rights.
Internet Use
May restrict to work-related duties or break times.
Code of Conduct and Social Media Analysis
Sets out expected professional standards.
Data Communications
Likely stored, logged, and monitored.
Social Media Monitoring
Employers may analyze personal accounts for policy infringements.
Privileged Access
Clauses to prevent misuse of privileges by technicians and managers.
Threats
File copying, camera, and voice-recording functions.
Enforcement
Difficult to prevent staff from bringing personal devices on-site.
Shadow IT
Unauthorized use of personal software/services poses security vulnerabilities.
Clean Desk Policy
Work areas should be free from documents.
AUP Acceptable Use Policy

Examples & real-world scenarios

Supplementary — not from your PDF
  • An AUP prohibiting installing unauthorized software.
  • A clean desk policy requiring documents to be locked away.
  • A code of conduct clause on privileged access misuse.

Scenario

Staff leave printouts with customer data on their desks overnight. A clean desk policy, enforced by managers, keeps sensitive documents out of sight of cleaners and visitors.

Common mistakes

Supplementary — not from your PDF
  • Writing an AUP so restrictive it interferes with job duties.
  • Ignoring shadow IT (unauthorized personal software and services).

Practical skills

Supplementary — not from your PDF
  • Identify what an AUP and a clean desk policy cover.

What I should remember

Key Points PDF p.432
  • Acceptable Use Policy (AUP)
    • Protection: Security and legal implications.
    • Prohibitions: Unauthorized activities, hardware/software installation.
    • Guidelines: Reasonable, non-intrusive.
  • Code of Conduct and Social Media Analysis
    • Standards: Professional behavior.
    • Risks: Security threats, legal issues.
    • Monitoring: Data communications, social media.
  • Use of Personally Owned Devices
    • Threats: Data security risks.
    • Controls: Network access, endpoint management.
    • Shadow IT: Unauthorized software/services.
  • Clean Desk Policy
    • Work Areas: Free from documents.
    • Purpose: Protect sensitive information.