Home > Security Tips > Compliance Counselor > Sample security policy for end users, part four
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

COMPLIANCE COUNSELOR

Sample security policy for end users, part four


Nap van Zuuren
12.05.2001
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   




Here is the fourth part of a sample security policy for end users, submitted by searchSecurity member Nap van Zuuren. Give it a read and tell us what you think by rating it at the bottom of the page. And, don't miss the rest of the policy; follow the link below.

XIII. Additional Policy & (basic) Procedures on Security Issues
As a (highly necessary) precaution, you should keep your system well protected.

Keeping your Windows 2000 updated:
Your Windows 2000 should have Service Packs 1 and 2 installed.
- Check Version via Help -> About ->
- It should indicate: Version 5.0 (Build 2195: Service Pack 2)

When connected to the Internet:
In your Programs List activate "Windows Update"
-> windowsupdate.microsoft.com
- Click "Show Installed Updates"
You will be guided on the necessary Updates; many of these Updates are security related, so take your time for them.
Install "Windows Critical Update Notification" - If a "flag" is shown in your taskbar, you should act on the required install of a Critical Update.
When asked: Install "Microsoft Windows Update Active Setup"
Windows Update also provides the Updates for Internet Explorer.

Do NOT change any of the installed security settings!

Keeping your Microsoft Office programs updated:
When you have selected "Windows Update," being at windowsupdate.microsoft.com and selected "Product Updates," you also have a choice for "Microsoft Office Update," guiding you to office.microsoft.com/ProductUpdates/default.aspx, in which you will find a choice for "Product Updates."
- You will have the possibility to download and install the "Microsoft Office Product Updates Detection Engine."
You will be guided on the necessary Updates; many of these Updates are security related, so take your time with them.

"Windows Update" also provides the updates for Internet Explorer 5.50. - (last Critical Update: Service Pack 1 of May 24,2001; Version now 5.50.4522.1800)
"Microsoft Office Update" also provides the Updates for Outlook, apart from the "Office" products.
Note: For these Updates you might need the CD, with which the installed Office 2000 files were installed on your system. You will have to contact your Network- or Sys-Admin in that case.
If it is impossible for you to get hold of the required CD, the same Service Packs (SPs) and Service/Security Releases (SRs) can be found via www.microsoft.com/security

Virus protection
It is the end user's responsibility to keep the antivirus software updated. is e-mailing the update information, and the updating has then to be carried out right after receipt of the Update E-Mail. It is recommended that, once a week, the end user updates the virus protection by selecting Start -> Programs -> Norton Antivirus and then activating "Live Update."

Please remember, updating your virus protection is your responsibility! Failure to do so has caused files to be destroyed in the past (losing literally several years of work) and cost considerably in time and money. Furthermore, you might "open" your system to non-invited "guests."

Password Requirements

As proper password usage is the most efficient way to prevent unauthorized access, the System Administration did set rules for passwords. If you use the wrong combination(s) of Login-ID and related Password, your system with be locked out after five access attempts, and intervention of the SysAdmin is required to get you online again.

For the choice of password the following requirements have to be met:
- Minimum length seven characters
- Minimum two of those characters have to be 'special' characters, so non-alphabetical and/or non-numerical


This sample policy is continued in Part Five.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Security Resources,   Compliance Counselor,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Security Resources
PCI Standards to be updated on new three-year cycle
Information Security magazine May issue PDF 2
Information Security magazine April issue PDF
Information Security Profession Takes Two Steps Backward
A written information security policy (WISP) example for compliance
EMC buys Archer Technologies for compliance management
FERPA regulation guidelines to email student personal data unencrypted
Information Security magazine November issue PDF
Jerry Freese: Make Critical Infrastructure Protection a Priority
Jon Moore: Build a Security Control Framework for Predictable Compliance

Compliance Counselor
HIPAA covered entity and business associate agreement requirements
Choosing smartphone encryption software for mobile smartphone security
How to manage compliance as Chief Information Security Officer (CISO)
Ease credit card risks: POS encryption and data tokenization for PCI
Employee compliance: Creating a compliance-focused workforce
How to change from WEP to WPA for PCI DSS compliance
How to use COBIT for compliance
PCI compliance requirements affect IT risk assessments
Cloud computing compliance: Exploring data security in the cloud
The future of PCI DSS encryption requirements? Tokenization for PCI

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2010, TechTarget | Read our Privacy Policy
  TechTarget