This Policy covers physical and logical security of IT equipment and data at all BALLY CHOHAN TECHNOLOGY locations.
BALLY CHOHAN TECHNOLOGY Policies on Security will be followed. Deviations due to local environment will be documented and approved by the DIRECTOR-IT.
Appropriate operating environment as recommended by the equipment manufacturer would be provided for all IT equipment. For Personal Computers and Servers, power supply will be through an Uninterrupted Power Supply system. Servers, LAN and WAN components would be located in physically secure areas with access controls and Fire Prevention Systems as appropriate with the criticality of the equipment and the scale of business operation.
All critical business data will be identified and would reside on Servers.
Data owners will be identified for all key business data.
Data Backups will be maintained as per the BALLY CHOHAN TECHNOLOGY India Data Backup Policy. Backups will be maintained only for data on Servers and other common equipment. The user will be responsible for backing up data on personal computers and laptops.
A Disaster Recovery Plan will be created and tested.
Dial In access will be provided using BALLY CHOHAN TECHNOLOGY approved dial in service provider.
Password protection is enabled for all key applications and is as per the BALLY CHOHAN TECHNOLOGY Password Policy. The user is responsible for following password policies and guidelines for securing passwords, and for ensuring that his / her passwords are not compromised.
Add, Change, and Deletion of user-ID and Passwords will be per relevant sections in the IT Operations Manual.
Interconnection to third party networks will be through firewalls.
Shared Folders on personal computers and notebooks are discouraged. If required to be used, such shares must be password-protected, with appropriate access (preferably “read-only”) to selected users.
All personal computers and notebooks must be protected with a two-level (user / administrator) power-on password.
Password-protected screen-savers must be installed on all personal computers and desktops, with automatic password-protected screen-saver being turned on after 30 minutes of inactivity.
Virus Policy : The best protection against virus attacks are informed and responsible users. All users are required to inform the IT Help Desk as soon as they suspect a virus attack. Mails from unknown persons, or from known persons with suspicious attachments, are not to be opened without consulting the IT Help Desk. The IT group has procedures in place to update the latest virus updates on all appropriate IT equipment – the user needs to periodically check that the virus update files on his / her desktop / notebook are not more than two weeks old.
BALLY CHOHAN TECHNOLOGY approved virus scanning/removal software must be kept at the current software and data file revision levels.
The BALLY CHOHAN TECHNOLOGY approved virus scanning/removal software must be active whenever PC’s, gateways and e-mail related servers are operational. File system servers must be scanned periodically – at least weekly. Virus scanning may be turned off only while installing software.
All vendor software must be certified as virus-free before installation.
All “foreign” media (tapes, disks, etc.) must be virus scanned before used in computer systems. At the discretion of Business Unit IT operations, media from trusted vendors may be exempted from this requirement.
All newly acquired PC’s and servers must have the BALLY CHOHAN TECHNOLOGY approved virus scanning/removal software installed and operational before being deployed.
Virus protection software will not be removed from any active IT asset without the written approval of the DIRECTOR-IT.
Executables received through e-mail will NOT be run unless the sender is known to be reliable.
Virus scanning and detection software must be used on home personal computers if files and/or e-mail are exchanged between the home system and BALLY CHOHAN TECHNOLOGY.
Basic virus education will be provided to all users.
The IT Help Desk will be the central point of contact for virus reporting. Information on possible virus detection / attack will be passed by users to the IT Help Desk.