Acceptable Use Policy for Information and Other Associated Files
Introduction
This document establishes Gauss Control’s Acceptable Use Policy for information assets, in accordance with Section 5.10 of the ISO/IEC 27002:2022 standard. This Policy applies to all employees, contractors, suppliers, and third parties who have access to Gauss Control’s information assets and sets forth the responsibilities, guidelines, and consequences associated with non-compliance. The implementation of this Policy is essential to ensure the protection and appropriate use of Gauss Control’s information assets and to support the effective management of the organization’s information security.
2. Objective
The purpose of this Policy is to establish guidelines for the acceptable use of Gauss Control’s information assets. Information assets include any type of information, data, systems, equipment, devices, software, documents, and materials owned by Gauss Control.
3. Scope
This Policy applies to all employees, contractors, suppliers, and any other individuals who use information assets owned by Gauss Control. Information assets include, among others, computing equipment, mobile devices, email, software, networks, databases, and data stored on any electronic medium.
4. Responsibilities
Data Owners and Data Stewards:
They must ensure that users under their supervision are aware of and comply with Gauss Control’s Acceptable Use Policy for Information and Other Associated Assets.
They must take appropriate disciplinary action in the event of non-compliance with this Policy and notify Gauss Control’s Information Security Officer of any security incidents or suspected security incidents.
They shall identify and maintain an inventory of the information assets required to support Gauss Control’s business processes.
Classify information assets according to the type of information being processed, in accordance with the provisions of the Information Classification and Labeling Policy.
Technology Manager:
Must ensure that Gauss Control’s assets are protected against damage, loss, or theft, and that the security controls implemented for such assets are operating effectively.
Must collaborate with Gauss Control’s Information Security Team to regularly update this Policy and provide guidance and training to authorized users of the organization’s assets.
Must report any security incident or suspected security incident related to the organization’s assets to Gauss Control’s Information Security Officer.
Information Security Officer:
Is responsible for regularly reviewing and updating this Policy and for providing guidance and training regarding its contents.
Must collaborate with the IT Manager to ensure that the security controls implemented for Gauss Control’s assets are operating effectively and to manage security incidents.
Must report to Gauss Control’s management any significant breach of this Policy or any major security incident that has occurred.
5. Policy
Acceptable Use
Gauss Control’s assets may only be used for legitimate and authorized business purposes.
Authorized users must comply with all laws, regulations, and standards applicable to the use of Gauss Control’s assets.
Authorized users must protect Gauss Control’s assets against damage, loss, or theft and must immediately report any security incident or suspected security incident to Gauss Control’s Information Security Team.
Authorized users must not attempt to circumvent or disable the security controls implemented on Gauss Control’s assets.
Misuse
Misuse of Gauss Control’s assets may result in disciplinary action, including, but not limited to, termination of employment, civil or criminal prosecution, or liability for damages.
Misuse includes, but is not limited to, unauthorized access, unauthorized disclosure, unauthorized modification, unauthorized destruction, or damage to Gauss Control’s assets.
Authorized users must not attempt to gain unauthorized access to Gauss Control’s assets or disclose confidential or proprietary information belonging to Gauss Control to third parties without authorization.
6. Policy Review
Gauss Control reserves the right to audit the use of its assets to ensure compliance with this Policy and other applicable policies and procedures. This Policy forms part of the terms and conditions of employment and applies to all authorized users of the assets.
7. Policy Effective Period
This document shall remain in effect for one year from the date of its most recent approval.
8. Reviews
One of the responsibilities of Gauss Control’s Information Security Committee is to reassess the organization’s information security policies. This reassessment shall be conducted at least once every two years, or whenever a significant change in technology, personnel, or any other event warrants a review, in order to ensure their continued suitability, adequacy, efficiency, and effectiveness.