employee security controls

29
Employee Security Controls CS5493(7493)

Upload: bien

Post on 25-Feb-2016

52 views

Category:

Documents


0 download

DESCRIPTION

Employee Security Controls. CS5493(7493). Contracts. Employment contract Accompanying job responsibility description Non-Disclosure Agreement Acceptable Usage Policy Service Level Agreements. Employee Controls. Things to consider when hiring: Credit check Background check Drug testing - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Employee Security Controls

Employee Security Controls

CS5493(7493)

Page 2: Employee Security Controls

Contracts

• Employment contract– Accompanying job responsibility description

• Non-Disclosure Agreement• Acceptable Usage Policy• Service Level Agreements

Page 3: Employee Security Controls

Employee Controls

• Things to consider when hiring:– Credit check– Background check– Drug testing– Lie detector test

Page 4: Employee Security Controls

Employee Controls

• All of the aforementioned controls are intrusive.

• The employee or candidate must be properly informed and must agree.

• Give them an opportunity to make any disclosures.

Page 5: Employee Security Controls

Employee controls

• Credit check – relatively inexpensive compared to the other listed alternatives.

Page 6: Employee Security Controls

Employee controls

• Background check– Resume verification– Job history verification– Criminal history check– References

Page 7: Employee Security Controls

Employee Controls

• When conducting a job history check, one can contact former employers

• Former employers are allowed to disclose information that is not protected by law, is accurate, and truthful.

Page 8: Employee Security Controls

Employe Controls

• Drug testing• Lie detector testExpensive to administer, not required for all

employees.

Page 9: Employee Security Controls

Employee Controls

• Separation of Duties

Page 10: Employee Security Controls

Employee Controls

• Separation of Duties• Need-to-Know

Page 11: Employee Security Controls

Employee Controls

• Separation of Duties• Need-to-Know• Job Rotation

Page 12: Employee Security Controls

Employee Controls

• Separation of Duties• Need-to-Know• Job Rotation• Vacations

Page 13: Employee Security Controls

Employee Controls

• Separation of Duties• Need-to-Know• Job Rotation• Vacations• Audits/Reviews

Page 14: Employee Security Controls

Separation of Duties

• This prevents someone from overseeing their own work: reduces errors and fraud.

Page 15: Employee Security Controls

Separation of Duties

• The people writing checks to vendors cannot be the same people who make the orders and establish vendor contracts.

Page 16: Employee Security Controls

Need-to-Know

• Employees will be given access to the information required for them to perform their duties.

Page 17: Employee Security Controls

Need-to-Know

• Reduces the possibility of improper disclosure of information.

Page 18: Employee Security Controls

Job Rotation

• Separation of duties and need-to-know can be defeated by collusion. Job Rotation is a strategy to prevent collusion.

Page 19: Employee Security Controls

Job Rotation

• Makes it possible to track which users were authorized to do what and when.

• Provides redundancy in job positions.• Enhances human capitol.

Page 20: Employee Security Controls

Vacations

• Vacations are important for determining if your operation can function properly while someone is away.

• A dishonest employee may be hiding something and fearful of ever leaving their post.

Page 21: Employee Security Controls

Audits/Reviews

• Employees should be reviewed.– Usually annually.

Page 22: Employee Security Controls

Audits/Reviews

• Employees should be reviewed.• If an employee is not following security

controls, find out why.

Page 23: Employee Security Controls

Audits/Reviews

• Employees should be reviewed.• If an employee is not following security

controls, find out why.– Could be out of ignorance

Page 24: Employee Security Controls

Audits/Reviews

• Employees should be reviewed.• If an employee is not following security

controls, find out why.– Could be out of ignorance– Could be deliberate deception

Page 25: Employee Security Controls

Disclosure

• Employees need to know why Employee-Controls are necessary.

Page 26: Employee Security Controls

Disclosure

• Employees need to know why Employee-Controls are necessary.– For example, explain the necessity of need-to-

know

Page 27: Employee Security Controls

Disclosure

• Employees need to know why Employee-Controls are necessary.– Explain the necessity of need-to-know– Employees can be disgruntled if they don’t know

why they are uninformed about some issues

Page 28: Employee Security Controls

Exit Interviews

• Create a record of why an employee leaves.

Page 29: Employee Security Controls

Exit Interviews

• Make a checklist of actions – Collect physical access items: keys, keycards, etc.– Close accounts– Notify vendors, contractors, business partners,

helpdesk, etc (create a list of contacts).