Compliance Policy Requirements
4 slides · 1 min read · Domain 1
Compliance Policy Requirements
Organizations should use acceptable use policies (AUPS) for all personnel.
The AUP should detail, from the user's expected perspective, the appropriate and approved usage of the organization's assets, including the IT environment, devices, and data.
Each employee (or anyone having access to the organization's assets) should be required to sign an AUP, preferably in the presence of an employee of the organization, and both parties should keep a copy of the AUP for their records.
Policy aspects commonly included in AUPS include
Text on this slide
Passwords
all Data retention
Internet usage
Data access
System access
Data disclosure
Company device usage
It is also possible to determine and enforce personnel compliance with the organization's security policy by conducting surveillance of their activity.
If the organization uses this option, it is extremely important that surveillance programs and functions are conducted in strict accordance with applicable laws; many countries have severe legal restrictions on how and when organizations can observe the activity of their personnel.
