Corporate Data Security Policy

1. Purpose

This policy defines enterprise information security responsibilities, and directs the development of related standards, controls, and procedures. Implementation of this policy will contribute to the realization of the following business and management control objectives:

  • Assure the continued availability of EON’s information resources to support lawful business activities.
  • Preserve the integrity of our business information to support high quality services and effective decision making.
  • Preserve the confidentiality of sensitive information resources.
  • Establish clear accountability for the management and use of EON’s information resources.
  • Assure the implementation of reasonable, cost-effective, and consistent enterprise information security controls and procedures throughout EON and its information technology systems and application systems.
  • Promote user awareness and understanding of the risks associated with EON’s information resources.
  • Preserve EON’s legal options and employee legal rights in the event of misuse or abuse of information resources.

2. Roles and Responsibilities

Intended audiences are included in Section 6.

2.1. Chief Technology Officer

  • Overall information security of the EON Information Technologies
  • Ensure security violations are addressed appropriately.

2.2. Operations Director

  • Ensure compliance with the policy and procedures prescribed herein.

2.3. IT Manager

  • Ensure compliance with the policy and procedures prescribed herein.
  • Provide security awareness training to EON’s associates.
  • Respond to and address security violations.
  • Coordinate the distribution, communication and maintenance of this policy and any related policies and procedures.

2.4. EON’s Associates, Visitors, and Guests

  • Comply with the policy and procedures contained herein, as appropriate (See Section 6).
  • Supervise the conduct and activities of contractors and guests.
  • Report violations or discrepancies to the appropriate supervisor or the IT Manager immediately.

3. Scope

This policy applies to all EON employees, contractors, consultants, temporaries, and all other personnel using EON information processing and communications equipment. This policy applies to all equipment that is owned or leased by EON.

4. Policy Statement

The following policy statements are to be achieved through the EON Information Security Program as directed by Information Security Governance. Detailed policies and procedures referenced within the policy statements are described in Section 6.

4.1. Security Management

Policy Statement: Comprehensive policies should be developed to establish a framework that provides direction and supports establishing a secure environment that protects EON assets from inappropriate use and malicious acts. Security should be a common goal throughout EON. EON should perform continuous programs for audit logging, risk management and awareness training.

4.2. Acceptable Use

Policy Statement: EON’s computer systems and application systems should be operated and managed in an appropriate manner to ensure they are adequately protected, secured, and used for company approved purposes; to maintain the confidentiality, integrity and availability of systems and data; and to minimize risk of system errors and failure.

4.3. Physical Security

Policy Statement: EON’s premises, assets and the information contained therein should be secured and protected from inappropriate use and malicious acts.

4.4. Information Systems Access

Policy Statement: Access controls should be utilized to provide accountability for EON’s information assets; and ensure that information is protected consistently with its sensitivity and value to EON.

4.5. Malicious Code

Policy Statement: Software that scans for malicious code should be installed and enabled on all EON firewalls and desktop machines. Software and detection engines should be regularly updated.

4.6. Corporate Firewalls

Policy Statement: EON’s corporate firewalls should be configured to allow only explicitly authorized application systems traffic into and out of the EON corporate application systems.

4.7. Encryption

Policy Statement: Procedures should be implemented to ensure sound practice encryption and key management. Strong encryption techniques (i.e. at least 128 bit, e.g. SSL) should be utilized in the transmission of sensitive customer and other data over public application systems. Sensitive customer data should never be transmitted in un-encrypted format.

4.8. Security Monitoring

Policy Statement: Standards, solutions, and procedures should be utilized to monitor and ensure compliance with policies, monitor activity on application systems for inappropriate access and use; and monitor access to and use of designated sensitive resources.

4.9. Incident Response

Policy Statement: Standards and procedures should permit the timely and effective response to real or apparent security incidents to minimize damage, preserve evidence, and ensure response and resolution in compliance with relevant laws and EON policies. Primary categories of incidents include attacks from external sources, internal inappropriate use, and malicious code.

4.10. Employee Screening

Policy Statement: Employees should be screened to help ensure that only appropriately skilled and trustworthy personnel gain access to critical business systems and data.

5. Compliance Statements

Users who access EON’s information systems should sign a compliance statement prior to issuance of a user-ID. A signature on this compliance statement indicates the user understands and agrees to abide by these EON policies and procedures related to computers and information systems. Annual confirmations should be required from all system users.

6. Policy Maintenance

The Corporate Data Security Policy and the related policies and procedures described within should be reviewed and updated, accordingly, in response to changing business, legal or technological conditions or at least on an annual basis. Updated policies should be distributed to intended audiences subsequent to updating the content. Training should be provided, as appropriate.