Lab #4 - Assessment Worksheet Craft A Layered Security Management Policy - Separation of Duties ABC Credit Union Policy Name+ Policy Statement
Lab #4 - Assessment Worksheet Craft A Layered Security Management Policy - Separation of Duties ABC Credit Union Policy Name+ Policy Statement
Lab #4 - Assessment Worksheet Craft A Layered Security Management Policy - Separation of Duties ABC Credit Union Policy Name+ Policy Statement
Policy Statement
- Employees using resources that belong to ABC Credit Union must act in
compliance with the policies of this company in regards to using these
resources.
Purpose/Objectives
- The purpose of this policy is to ensure that no individual should be able to
execute a high-risk transaction or conceal errors or fraud in the normal course
of their duties. This policy must be in compliance with GLBA
Scope
- This policy applies to all employees, systems, and customers of ABC Credit
Union. Standards All employees will be separated into group/departments and
each department will have specific duties assigned to them
Standards
- All employees will be separated into group/departments and each department
will have specific duties assigned to them
Procedures
- Group Policies will be implemented to ensure that employees have access to
only the files they need.
- Each department will have annual training to discuss any possible changes to
department duties and policies.
- Chain of command will be established within each department leading up to
executive management.
- Users who have been charged with the management of IT systems are
responsible for ensuring that they are at all times properly protected against
known threats and vulnerabilities as far as is reasonably practicable and
compatible with the designated purpose of those systems.
Guidelines
- Users will be trained to follow all policies and procedures in the organization.
System Administrators can refer to NIST Special Publication 800-53 Security
and Privacy Controls
Lab #4 – Assessment Worksheet
Craft a Layered Security Management Policy – Separation of Duties
11. Why is it important to define access control policies that limit or prevent
exposing customer privacy data to employees?
- Access control policies limits or prevents employees from exposing customer
privacy data. From that, you are limiting the risk of the exposure of that
information to only those that require access to the information and adhering
to compliance laws.
12. Explain why the seven domains of a typical IT infrastructure helps
organizations align to separation of duties
- By separating the responsibilities, it makes it easier for an organization to
identify possible risks/areas of impact and the ability to delegate resources to
mitigate those risks.