10.10.2014 Views

Policy 7230A - Department of Administration

Policy 7230A - Department of Administration

Policy 7230A - Department of Administration

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

11. Personnel Security<br />

These Personnel Security Non-Mandatory Baselines support the Enterprise Security <strong>Policy</strong><br />

(ITEC 7230 Rev 1), and the Acceptable Internet Use <strong>Policy</strong> (ITEC 1200).<br />

Mandatory<br />

Non-Mandatory<br />

Procedures Baselines Procedures Baselines<br />

11. Personnel Security <br />

11.1. Acceptable Usage<br />

11.1.1. Establish Acceptable Usage Baselines (6 sets) (6 sets)<br />

11.2. Personnel Operations<br />

11.2.1. Establish Pre-Hiring Processes (4 sets) (3 sets)<br />

11.2.2. Hire Employees in a Structured Fashion (3 sets) (1 set)<br />

11.2.3. Transfer Employees in a Structure Fashion (4 sets) (2 sets)<br />

11.2.4. Terminate Employees in a Structured Fashion (3 sets) (1 set)<br />

11.3. Maintain Records <br />

11.1. Acceptable Usage<br />

No applicable Non-Mandatory Baselines.<br />

11.2. Personnel Operations<br />

The following are the Non-Mandatory Baselines that support the Acceptable Usage<br />

section <strong>of</strong> the Default Security Requirements:<br />

11.2.1. Establish Pre-Hiring Processes<br />

Since employees will be assigned access to systems and information, steps<br />

should be taken to ensure appropriate security considerations are taken into<br />

account:<br />

11.2.1.a Positional Role<br />

• Role definition should be based partially on employee<br />

position:<br />

o Senior management.<br />

o Middle management.<br />

o Senior non-management.<br />

o Non-management.<br />

• Role definition should be based partially on employee<br />

responsibility:<br />

o Administrative staff.<br />

o Non-administrative staff.<br />

• Role definition should be based partially on employee access<br />

requirements:<br />

o Read access.<br />

o Write access.<br />

o Edit access.<br />

o Delete access.<br />

33

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!