Clean Desk Policy:
Goal:
Establish the minimum requirements for maintaining a “clean desk” – where sensitive/critical information about employees, intellectual property, students is secure in locked areas and out of site.
Procedure:
a.Employees are required to ensure that all sensitive/confidential information in hardcopy or electronic form is secure in their work area at the end of the day and when they are expected to be gone for an extended period.
b.Computer workstations must be locked when workspace is unoccupied.
c.Computer workstations must be shut completely down at the end of the work day.
d.Any Restricted or Sensitive information must be removed from the desk and locked in a drawer when the desk is unoccupied and at the end of the work day.
e.File cabinets containing Restricted or Sensitive information must be kept closed and locked when not in use or when not attended.
f.Keys used for access to Restricted or Sensitive information must not be left at an unattended desk.
g.Laptops must be either locked with a locking cable or locked away in a drawer.
h.Passwords may not be left on sticky notes posted on or under a computer, nor may they be left written down in an accessible location.
i.Printouts containing Restricted or Sensitive information should be immediately removed from the printer.
j.Upon disposal Restricted and/or Sensitive documents should be shredded in the official shredder bins or placed in the lock confidential disposal bins.
k.Whiteboards containing Restricted and/or Sensitive information should be erased.
l.Lock away portable computing devices such as laptops and tablets.
m.Treat mass storage devices such as CDROM, DVD or USB drives as sensitive and secure them in a locked drawer.
Password Policy:
Goal:
Passwords are a critical component of information security and serve to protect user accounts; however, a poorly constructed password may result in the compromise of individual systems, data, or network. This policy provides best practices for creating secure passwords.