The importance of an Acceptable Use Policy
|
|
|
- Godwin Green
- 10 years ago
- Views:
Transcription
1 GFI White Paper The importance of an Acceptable Use Policy In an ideal world, employees would use the computers and Internet access provided their employer solely for business use. It is however, sadly, not an ideal world. Throughout the work day, companies, schools, libraries and other organizations are exposed by their users to the misuse of the system. The dilemma faced by every company is what to do about it and how to start. In this white paper we examine both the extent of the problem of misuse, and the role the creation and dissemination of an Acceptable Use Policy (AUP) can offer in helping an enterprise avoid unwanted consequences and enabling it to deal with transgressions in a fair and systematic way that will survive legal challenges without reducing employee morale and productivity.
2 Contents The extent of misuse 3 Solutions 3 Acceptable Use Policy 3 What should be in an Acceptable Use Policy? 4 Ideally an AUP should do the following 4 Summary 5 About GFI 5 2
3 The extent of misuse According to a survey by International Data Corp (IDC), 30 to 40% of Internet access is spent on non-work related browsing, and 60% of all online purchases are made during working hours. The data IDC uncovered includes: 70% of all web traffic to Internet pornography sites occurs during the work hours of 9am-5pm. 58% of industrial espionage is perpetrated by current or former employees.»» 80% of computer crime is committed by insiders. They manage to steal $100 million by some estimates; $1 billion by others. 48% of large companies blame their worst security breaches on employees. 64% of employees say they use the Internet for personal interest during working hours. 70% of all Internet porn traffic occurs during the nine-to-five work day. 37% of workers say they surf the web constantly at work. 90% of employees feel the Internet can be addictive, and 41 percent admit to personal surfing at work for more than three hours per week. 25% of corporate Internet traffic is considered to be unrelated to work % of lost productivity is accounted for by cyber-slacking. 32.6% of workers surf the net with no specific objective; men are twice as likely as women. 27% of Fortune 500 organizations have defended themselves against claims of sexual harassment stemming from inappropriate . 90% of respondents (primarily large corporations and government agencies) detected computer security breaches within the previous 12 months, 80% acknowledged financial losses due to computer breaches, 44% were willing and/or able to quantify their losses, at more than $455 million. Solutions One solution to the problem, beyond simply disabling the connections or depending on sometimes unreliable URL blockers, is to use Internet monitoring systems (see GFI whitepaper: Internet monitoring ). According to IDC, 77.7% of major US companies keep tabs on employees by checking their , Internet, phone calls, computer files, or by videotaping them at work. 63% of companies monitor workers Internet connections and 47% store and review employee . Acceptable Use Policy While monitoring has been an effective tool in identifying abusers and cyber-slackers, Human Resources experts, as well as the courts agree that it needs to be accompanied by evidence of a duty of care intended to reduce unacceptable employee activity. A key aspect of this is what is commonly referred to as an Acceptable Use Policy. Nearly every enterprise has a specified set of rules, usually spelled out in an employee handbook, that an employee has to acknowledge by signature that he or she has read and understood. Some of these policies, such as that against racial or religious discrimination and mandatory archiving are required by law or regulation. Others may reflect common business ethics or a particular company s culture such as prohibitions against drinking, unexcused absences, sexual harassment and the like. Policies also include a set of sanctions that can be used against persons who violate the company s policies. They also provide a legally defensible basis for disciplinary action, up to and including termination. 3
4 One key advantage to policies like this is that while, traditionally, employers have been held responsible and liable for their actions in the workplace, the presence of policies prohibiting such actions has served as a liability shield that can completely or partially protect that company from lawsuits arising actions from employees acting in contravention of the policies. To safeguard its electronic communications, every company, large or small, should have an Acceptable Use Policy in place that governs Internet, and computer use in the business. In essence, an Acceptable Use Policy serves as guidance for staff and volunteers on the behavior and use of technology that is approved by the organization. The policy should also detail the consequences that company personnel can expect to face for the abuse of this technology. What should be in an Acceptable Use Policy? As discussed earlier, monitoring voice mail, and Internet use is generally legal, provided the employer has created and effectively communicated an Acceptable Use Policy. While the exact wording of the AUP will vary from company to company, there are some general guidelines on how an organization communicates such policies to its workers. The key goal of an AUP is to eliminate any employee expectations that these means of communication or use of computers, and the Internet at work are confidential. The policy must be non-discriminatory and it should prohibit all forms of non-business related communications. To this end, the policy informs employees that the employer may access, search and monitor voice mail, or company files of any employee that are created, stored or deleted from company computer systems. The policy must be uniformly enforced through employee education, ongoing monitoring and appropriate discipline. Obtaining prior consent will generally protect employers from liability. Ideally an AUP should do the following:»» Define what systems are covered by the policy, e.g., voice mail, , Internet, and computer systems and files. Specify that an employer s computer systems are for business purposes only, and all files and messages are company property. If the company chooses to allow some personal use, the policy should caveat this by forbidding personal use that interferes with an employee s work or that of others (e.g., prohibiting non-work related websites such as chat rooms, games, travel, shopping, stock trading, hate/discrimination, pornography, etc.). Specifically ban transmitting or downloading of material that is discriminatory, defamatory, harassing, insulting, offensive, pornographic or obscene. Prohibit copying and sending any confidential or proprietary information, or software that is protected by copyright and other laws protecting intellectual property. Prohibit unauthorized access by employees of other employees electronic communications. Warn employees that any misuse will be subject to discipline, up to and including termination. Advise and emphasize employees that they have no right to expect that their communications or use of employer s computer information systems is either confidential or private. After the AUP is drafted, organizations should require the employees to sign the AUP. Some companies have also taken the further step of installing an on-screen warning about their electronic communications policy that appears every time employees log onto their computers. 4
5 Summary Misuse of the Internet, and computers in the workplace represents a serious and growing challenge to every organization, regardless of size. In addition to potential illegal activity, disclosure of company secrets and introduction of malware, misuse of these systems has a real dollar cost in terms of lost productivity. To date, the most successful means of combating this has been through monitoring, by a variety of means. The first step in any organization s defensive measures against abuse is a prior consent statement, commonly referred to as an Acceptable Use Policy that specifies that employees have no right to an expectation of privacy with respect to their use of business computers, systems and Internet connections. The AUP also details unacceptable activities, specifies sanctions, advises of the potential for monitoring and places responsibility for inappropriate behavior on the employee who transgresses those rules. The AUP should be widely disseminated and employees required signing and acknowledging their understanding of it. In addition to providing employees throughout the organization with clear definition of the organization s expectations, a properly executed AUP can serve as a liability shield for the organization in the event of misbehavior by an employee, as well as a legally sanctioned basis for disciplinary actions, including termination. About GFI GFI Software provides web and mail security, archiving, backup and fax, networking and security software and hosted IT solutions for small to medium-sized enterprises (SMEs) via an extensive global partner community. GFI products are available either as on-premise solutions, in the cloud or as a hybrid of both delivery models. With award-winning technology, a competitive pricing strategy, and a strong focus on the unique requirements of SMEs, GFI satisfies the IT needs of organizations on a global scale. The company has offices in the United States (North Carolina, California and Florida), UK (London and Dundee), Austria, Australia, Malta, Hong Kong, Philippines and Romania, which together support hundreds of thousands of installations worldwide. GFI is a channel-focused company with thousands of partners throughout the world and is also a Microsoft Gold Certified Partner. More information about GFI can be found at 5
6 USA, CANADA AND CENTRAL AND SOUTH AMERICA Weston Parkway, Suite 104, Cary, NC 27513, USA Telephone: +1 (888) Fax: +1 (919) UK AND REPUBLIC OF IRELAND Magna House, London Road, Staines, Middlesex, TW18 4BP, UK Telephone: +44 (0) Fax: +44 (0) EUROPE, MIDDLE EAST AND AFRICA GFI House, San Andrea Street, San Gwann, SGN 1612, Malta Telephone: Fax: AUSTRALIA AND NEW ZEALAND 83 King William Road, Unley 5061, South Australia Telephone: Fax: [email protected] Disclaimer GFI Software. All rights reserved. All product and company names herein may be trademarks of their respective owners. The information and content in this document is provided for informational purposes only and is provided as is with no warranty of any kind, either express or implied, including but not limited to the implied warranties of merchantability, fitness for a particular purpose, and non-infringement. GFI Software is not liable for any damages, including any consequential damages, of any kind that may result from the use of this document. The information is obtained from publicly available sources. Though reasonable effort has been made to ensure the accuracy of the data provided, GFI makes no claim, promise or guarantee about the completeness, accuracy, recency or adequacy of information and is not responsible for misprints, outof-date information, or errors. GFI makes no warranty, express or implied, and assumes no legal liability or responsibility for the accuracy or completeness of any information contained in this document. If you believe there are any factual errors in this document, please contact us and we will review your concerns as soon as practical.
How to create a complex and secure backup strategy
GFI White Paper How to create a complex and secure backup strategy Data is the lifeblood of every organization and business. Data theft and data loss through negligence or hardware failure can cause irreparable
GFI MailSecurity deployment strategies
GFI White Paper GFI MailSecurity deployment strategies Which operating mode(s) to use in your network environment GFI MailSecurity can be deployed as an SMTP gateway or as a VS API version for Microsoft
Social networking at work: Thanks, but no thanks?
GFI White Paper Social networking at work: Thanks, but no thanks? Millions of people around the world with access to the Internet are members of one or more social networks. They have a permanent online
How to configure IBM iseries (formerly AS/400) event collection with Audit and GFI EventsManager
GFI White Paper How to configure IBM iseries (formerly AS/400) event collection with Audit and GFI EventsManager This document explains how to configure and use GFI EventsManager to collect IBM iseries
Archiving technologies
GFI White Paper Archiving technologies Have you ever considered the impact one untraceable email can have on an organization or individual s career? With so much corporate information contained within
Understanding data backups: why SMEs need them
GFI White Paper Understanding data backups: why SMEs need them Data is the lifeblood of every organization, yet many either fail to back up their data or they are not doing so properly. Losing data can
How to keep spam off your network
GFI White Paper How to keep spam off your network What features to look for in anti-spam technology A buyer s guide to anti-spam software, this white paper highlights the key features to look for in anti-spam
The business implications of not having a backup strategy: where businesses get it wrong
GFI White Paper The business implications of not having a backup strategy: where businesses get it wrong A business that fails to maintain a copy of its data is asking for trouble. It is extremely easy
Integrating faxes into today s world of healthcare e-records
GFI White Paper Integrating faxes into today s world of healthcare e-records This white paper examines the obstacles preventing the move away from fax machines, and the benefits of having a communications
Patch management with GFI LanGuard and Microsoft WSUS
GFI White Paper Patch management with GFI LanGuard and Microsoft WSUS A cost-effective and easy solution for network-wide patch management This white paper provides an overview of how to use GFI LanGuard
GFI White Paper. How Web Reputation increases your online protection
GFI White Paper How Web Reputation increases your online protection Contents Introduction to Web Reputation 3 Why use Web Reputation? 3 The value of using Web Reputation and antivirus software 3 The value
GFI Product Guide. GFI MailArchiver Archive Restrictions and Licensing Guide
GFI Product Guide GFI MailArchiver Archive Restrictions and Licensing Guide The information and content in this document is provided for informational purposes only and is provided "as is" with no warranty
GFI Product comparison. GFI MailArchiver vs. Microsoft Exchange 2010
GFI Product comparison GFI MailArchiver vs. Microsoft Exchange 2010 GFI MailArchiver 2011 GFI MailArchiver is an industry-leading email management solution. It is used globally by administrators to lower
GFI Product Comparison. GFI LanGuard 2011 vs Retina Network Security Scanner 5.12.1
GFI Product Comparison GFI LanGuard 2011 vs Retina Network Security Scanner 5.12.1 General features GFI LanGuard 2011 Retina 5.12.1 Scheduled scans Agent-less Agent-based Integration with Active Directory
GFI Product Comparison. GFI LanGuard 2011 vs Microsoft Baseline Security Analyzer 2.2
GFI Product Comparison GFI LanGuard 2011 vs Microsoft Baseline Security Analyzer 2.2 General features GFI LanGuard 2011 MBSA 2.2 Scheduled scans r Agent-less Agent-based Integration with Active Directory
Email security Cloud vs. On-premise solutions
GFI White Paper Email security Cloud vs. On-premise solutions Choosing whether to put your email security in the cloud or host it on premise is a major decision. Hopefully this white paper will help. Contents
GFI product comparison. GFI MailArchiver vs. Microsoft Exchange 2010
GFI product comparison GFI MailArchiver vs. Microsoft Exchange 2010 GFI MailArchiver GFI MailArchiver is an industry-leading email management solution. It is used globally by administrators to lower email
Quick Start Guide for administrators
Quick Start Guide for administrators Contents Welcome 3 Your login information 3 Step 1: Adding mailboxes 3 Part 1: Add users 3 Part 2: Add aliases 3 Step 2: Adjusting your spam handling settings 4 Optional
GFI MailEssentials Online Archive Configuration and usage
GFI MailEssentials Online Archive Configuration and usage Contents Retention policies 3 Message tagging 4 Access rights 5 Journaling 5 Accessing archived messages 7 Archive search / Viewing archived messages
Protecting your network against email threats
GFI White Paper Protecting your network against email threats The need for comprehensive server-based email security This white paper explains why antivirus software alone is not enough to protect your
Vulnerability management: Key questions you should be asking
GFI White Paper Vulnerability management: Key questions you should be asking Is vulnerability management critical for a business? Aren t traditional security tools sufficient to protect and secure the
GFI Product Comparison. GFI MailArchiver 6.0 vs Stimulus Software MailArchiva
GFI Product Comparison GFI MailArchiver 6.0 vs Stimulus Software MailArchiva Overview GFI MailArchiver 6.0 is the business archiving solution for small and medium-sized enterprises (SMEs). Reduce PST management
GFI Product Manual. GFI MailArchiver Evaluation Guide
GFI Product Manual GFI MailArchiver Evaluation Guide The information and content in this document is provided for informational purposes only and is provided "as is" with no warranty of any kind, either
GFI White Paper. Going beyond Exchange 2010 - Why it pays to have a dedicated email archiving solution
GFI White Paper Going beyond Exchange 2010 - Why it pays to have a dedicated email archiving solution Contents Introduction 3 The state of email archiving and data retention 3 The compliance challenge
GFI Product Comparison. GFI MailArchiver 6.0 vs Quest Software Archive Manager
GFI Product Comparison GFI MailArchiver 6.0 vs Quest Software Archive Manager General features GFI MailArchiver 6.0 Quest Software Archive Manager Supports Microsoft Exchange 2000, 2003 and 2007 Supports
GFI Product Guide. How to create a new SQL Server Instance in Microsoft SQL Server 2012 and SQL Server Express
GFI Product Guide How to create a new SQL Server Instance in Microsoft SQL Server 2012 and SQL Server Express The information and content in this document is provided for informational purposes only and
GFI Product Manual. Outlook Connector User Manual
GFI Product Manual Outlook Connector User Manual http://www.gfi.com [email protected] The information and content in this document is provided for informational purposes only and is provided "as is" with no
GFI product comparison. GFI MailArchiver vs. Symantec Enterprise Vault
GFI product comparison GFI MailArchiver vs. Symantec Enterprise Vault General features GFI MailArchiver Symantec Enterprise Vault Supports Microsoft Exchange Server 2003, 2007 and 2010 Supports distributed
GFI Product Comparison. GFI MailArchiver 6.0 vs EMC EmailXtender Archive Edition
GFI Product Comparison GFI MailArchiver 6.0 vs EMC EmailXtender Archive Edition General features GFI MailArchiver 6.0 EMC EmailXtender Archive Edition Supports Microsoft Exchange Server 2000, 2003 and
GFI MailEssentials 2014 Upgrade Guide A guide to upgrading from previous versions of GFI MailEssentials and GFI MailSecurity
GFI MailEssentials 2014 Upgrade Guide A guide to upgrading from previous versions of GFI MailEssentials and GFI MailSecurity The information and content in this document is provided for informational purposes
GFI Product Comparison. GFI MailArchiver 6.0 vs Waterford Technologies MailMeter Archive
GFI Product Comparison GFI MailArchiver 6.0 vs Waterford Technologies MailMeter Archive General features GFI MailArchiver 6.0 Waterford Technologies MailMeter Archive Supports Microsoft Exchange Server
GFI Product Comparison. GFI MailEssentials vs. Trend Micro ScanMail Suite for Microsoft Exchange
GFI Product Comparison GFI MailEssentials vs. Trend Micro ScanMail Suite for Microsoft Exchange GFI MailEssentials Trend Micro ScanMail Suite Microsoft Exchange Server 2003/2007/2010/2013 Integration Option
GFI FAXmaker for Exchange/SMTP 12: An introduction to the architecture and deployment options
GFI FAXmaker for Exchange/SMTP 12: An introduction to the architecture and deployment options An overview of how GFI FAXmaker works, and how to deploy it This white paper describes the different ways in
Patch management: Fixing vulnerabilities before they are exploited
GFI White Paper Patch management: Fixing vulnerabilities before they are exploited Managing and administering software updates remains one of the most challenging and resource-intensive tasks an IT Department
GFI Product Guide. GFI Archiver Evaluation Guide
GFI Product Guide GFI Archiver Evaluation Guide The information and content in this document is provided for informational purposes only and is provided "as is" with no warranty of any kind, either express
Survey: Web filtering in Small and Medium-sized Enterprises (SMEs)
September 2010 GFI Software www.gfi.com More and more organizations are seeing value in web filtering and web security solutions, a survey conducted by GFI Software shows, with seven in 10 stating they
GFI Product Comparison. GFI MailEssentials vs Barracuda Spam Firewall
GFI Product Comparison GFI MailEssentials vs Barracuda Spam Firewall GFI MailEssentials Barracuda Spam Firewall Integrates closely with Microsoft Exchange Server 2003/2007/2010 Integrates closely with
GFI MAX RemoteManagement Building Blocks to Managed services
GFI MAX RemoteManagement Building Blocks to Managed services Overview GFI s Building Block Program is all about making Managed Services a practical reality for IT support companies. A recent survey found
GFI Cloud white paper. Cloud-based services: Easing the IT burden while taking control. www.gficloud.com
GFI Cloud white paper Cloud-based services: Easing the IT burden while taking control www.gficloud.com Contents Introduction 3 Transferring workload into the cloud 4 Managing the cloud 5 Summary 6 About
Endpoint Protection Performance Benchmarks
Endpoint Protection Performance Benchmarks GFI Software conducted objective performance testing on four, publically available business endpoint protection security software products on Windows 7 Professional
GFI Product Comparison. GFI MailEssentials vs Symantec Mail Security for Microsoft Exchange 7.0
GFI Product Comparison GFI MailEssentials vs Symantec Mail Security for Microsoft Exchange 7.0 GFI MailEssentials Symantec Mail Security for Microsoft Exchange 7.0 Supports Microsoft Exchange Server 2003
GFI Product Guide. GFI Archiver and Office 365 Deployment Guide
GFI Product Guide GFI Archiver and Office 365 Deployment Guide The information and content in this document is provided for informational purposes only and is provided "as is" with no warranty of any kind,
How To Set Up A Journaling Mailbox In Microsoft Office 365 And Gfi Mailarchiver
GFI Product Guide GFI MailArchiver and Office 365 Deployment Guide The information and content in this document is provided for informational purposes only and is provided "as is" with no warranty of any
GFI Product Manual. GFI MailArchiver Outlook Addon
GFI Product Manual GFI MailArchiver Outlook Addon The information and content in this document is provided for informational purposes only and is provided "as is" with no warranty of any kind, either express
Why organizations need to archive email
GFI White Paper Why organizations need to archive email The underlying reasons why corporate email archiving is important Over the past few years, email has become an integral part of the business workflow.
GFI Product Manual. Outlook Connector Manual
GFI Product Manual Outlook Connector Manual The information and content in this document is provided for informational purposes only and is provided "as is" with no warranty of any kind, either express
GFI Product Guide. GFI MailArchiver Archive Assistant
GFI Product Guide GFI MailArchiver Archive Assistant The information and content in this document is provided for informational purposes only and is provided "as is" with no warranty of any kind, either
Social networking and security risks
GFI White Paper Social networking and security risks By Brad Dinerman The popularity of social networking sites has increased at astonishing levels. There is no arguing the usefulness of sites such as
APPROVED BY: DATE: NUMBER: PAGE: 1 of 9
1 of 9 PURPOSE: To define standards for appropriate and secure use of MCG Health electronic systems, specifically e-mail systems, Internet access, phones (static or mobile; including voice mail) wireless
The term Broadway Pet Stores refers we to the owner of the website whose registered office is 6-8 Muswell Hill Broadway, London, N10 3RT.
Website - Terms and Conditions Welcome to our website. If you continue to browse and use this website you are agreeing to comply with and be bound by the following terms and conditions of use, which together
City of Boston Department of Innovation and Technology Policy Title: Information Technology Resource Use Policy Effective Date: April 1, 2011
City of Boston Department of Innovation and Technology Policy Title: Information Technology Resource Use Policy Effective Date: April 1, 2011 Purpose and Intent The City of Boston recognizes the importance
Human Resources Policy and Procedure Manual
Procedure: maintains a computer network and either purchases software for use in the network or develops proprietary software systems for Company use. Company employees are generally authorized to use
Terms & Conditions. In this section you can find: - Website usage terms and conditions 1, 2, 3. - Website disclaimer
1 Terms & Conditions In this section you can find: - Website usage terms and conditions 1, 2, 3 - Website disclaimer -Acceptable internet use policy 1,2,3,4 - Acceptable email use policy 1, 2 - Copyright
Covered California. Terms and Conditions of Use
Terms and Conditions of Use Contents: Purpose Of This Agreement Privacy Policy Modification Of This Agreement Permission To Act On Your Behalf How We Identify You Registration Additional Terms For Products
U.S. Chemical Safety and Hazard Investigation Board
BOARD ORDER 035 U.S. Chemical Safety and Hazard Investigation Board SUBJECT: Use of Government Office Equipment CONTENTS 1. Purpose...1 2. Effective Date...1 3. Scope...1 4. References...1 5. Definition...1
How to perform network-wide security event log monitoring
GFI White Paper How to perform network-wide security event log monitoring Using GFI EventsManager for intrusion detection and essential auditing of security event logs This white paper explains the need
OXFORD COMMUNITY SCHOOLS 10 North Washington Street, Oxford, Michigan 48371 ACCEPTABLE USE POLICY
OXFORD COMMUNITY SCHOOLS 10 North Washington Street, Oxford, Michigan 48371 ACCEPTABLE USE POLICY 1. Purpose Oxford Community Schools (the District ) recognizes that advancements in technology affect the
GFI Product Manual. Evaluation Guide Part 1: Quick Install
GFI Product Manual Evaluation Guide Part 1: Quick Install The information and content in this document is provided for informational purposes only and is provided "as is" with no warranty of any kind,
LINCOLN UNIVERSITY. Approved by President and Active. 1. Purpose of Policy
LINCOLN UNIVERSITY Policy: Computer and Network Usage by Employees Policy Number: HRM-110 Effective Date: July 1, 2009 Revisions: Replaces, as they relate specifically to employees, IT Policies 517 Internet
GFI Product Manual. Version 6.0. Getting Started Guide
GFI Product Manual Version 6.0 Getting Started Guide The information and content in this document is provided for informational purposes only and is provided "as is" with no warranty of any kind, either
City of Grand Rapids ADMINISTRATIVE POLICY
City of Grand Rapids ADMINISTRATIVE POLICY NUMBER: 84-02 DATE: 7/23/84 REVISIONS: 6/17/88; 11/7/00 (replaces old #84-02, #95-07, & #95-08); 6/13/08; 11/26/13 ISSUED BY: City Manager SIGNED: SUBJECT: ELECTRONIC
TERMS and CONDITIONS OF USE - NextSTEPS TM
TERMS and CONDITIONS OF USE - NextSTEPS TM DATED MARCH 24, 2014. These terms and conditions of use (the Terms and Conditions ) govern your use of the website known as NextSTEPS TM, https://www.stepsonline.ca/
Hyde School Student Computer Systems Acceptable Use Policy
Hyde School Student Computer Systems Acceptable Use Policy A. Hyde School Computer Systems and Internet Access Please read the following carefully before signing this document. This is a legally binding
