Compliance Policy Requirements

4 slides · 1 min read · Domain 1

Compliance Policy Requirements

Organizations should use acceptable use policies (AUPS) for all personnel.

The AUP should detail, from the user's expected perspective, the appropriate and approved usage of the organization's assets, including the IT environment, devices, and data.

Each employee (or anyone having access to the organization's assets) should be required to sign an AUP, preferably in the presence of an employee of the organization, and both parties should keep a copy of the AUP for their records.

Policy aspects commonly included in AUPS include

Text on this slide

Passwords

all Data retention

Internet usage

Data access

System access

Data disclosure

Company device usage

It is also possible to determine and enforce personnel compliance with the organization's security policy by conducting surveillance of their activity.

If the organization uses this option, it is extremely important that surveillance programs and functions are conducted in strict accordance with applicable laws; many countries have severe legal restrictions on how and when organizations can observe the activity of their personnel.

Test this domain