Security Policy Document: Global Distributions, Inc.
The purpose of this document is to establish key security parameters and guidelines for Global Distributions, Inc. (GDI) in order to protect the interests of the company and its clients.
Scope
These policies apply to all operations managed by GDI, including interactions and interfaces with client companies that are managed by GDI. All communication networks, database systems, and servers full under the purview of this policy.
Policies
Definition of Sensitive Information
All information that could identify a client of GDI, monetary values of client goods or contracts, physical addresses of client goods or business locations, physical addresses of GDI company locations, any details of client-specific services rendered by GDI to clients, and any personally identifying information for any client or GDI personnel shall be considered sensitive information and treated as such. This designation applies to this policy document and to other documents, guidelines, and directives issued by GDI as they may be from time to time.
Rationale: This definition is necessary for simplifying further security policies and future guidelines. The definition of sensitive information is purposefully broad, as over-conclusion is far less problematic than under-inclusion.
3.1.2 Definition of GDI/GDI Client Personnel and Property
All movable items located on or within GDI buildings, grounds, and/or transportation vehicles (whether owned, leased, or contracted to GDI) as well as the buildings, grounds, and vehicles themselves shall be considered GDI property for the purposes of this document. All employees, contracted workers, and any other personnel with legitimate business-related tasks to perform on or with GDI property shall be considered GDI personnel for the purposes of this document. All physical items owned by GDI clients that GDI is in possession of, has contracted for possession of, is monitoring, or is in any other way connected to GDI services, shall be considered client property for the purposes of this document. All employees, contract workers, and other individuals with legitimate business tasks related to client property shall be considered GDI client personnel for the purposes of this document.
Rationale: This definition is necessary for simplifying, clarifying, and making explicit those properties and personnel included in this document's security policies.
3.1.3 Safety of Personnel and Property as Overriding Concerns
All GDI personnel are primarily tasked first with acting in a manner that ensures the safety of all personnel and other individuals, and second with acting in a manner that protects the property of GDI and GDI clients. No security policy in this document or any other shall supersede these primary tasks.
Rationale: Ensuring the security and safety of personnel and property must be central to overall security, as there are no company interests or security concerns without the personnel and property with which company operations are concerned.
3.1.4 General GDI Personnel Conduct
No GDI personnel shall engage in tasks, access information, or enter areas of GDI operation that are not directly pertinent to the performance of the tasks for which they are responsible and that they have been expressly authorized to perform. No deviations from this policy are allowed save in cases of emergency situations that cause threat to the safety of personnel or of GDI/GDI client property, and reviews shall be conducted following all such emergency exceptions.
Rationale: Limiting the scope of activities for all personnel to those they have been expressly authorized to perform limits the potential for security breaches, both purposeful and accidental, and also greatly simplifies and eases investigations carried out in the wake of potential security breaches.
3.2 INFORMATION SECURITY
3.2.1 Limitations on the Communication of Sensitive Information
No sensitive information shall be transmitted via any medium, including direct oral communication, without verifying the authorization of the receiving party(ies) to receive the sensitive information. Regular authorization verification of common GDI communication partners need not be obtained for every communication, so as to maintain practicality in daily operations, however all non-GDI communication partners must be verified on a per-communication basis.
Rationale: Ensuring authorization for the receipt of sensitive information will help to ensure that sensitive information does not reach those who do not have a proper and legitimate use for this information. Stringent verification procedures will also limit incorrect assumptions of a legitimate need to communicate sensitive information.
3.2.2 Communication of Sensitive Information Using Physical Media
Sensitive information stored on physical media, including directly-readable media (e.g. ink and paper) as well as information stored electronically on physical media (e.g. computer disks) shall be transported only in sealed GDI-provided envelopes marked "confidential." This policy applies to inter-office communications, communications between separate GDI departments, communications with GDI clients, and communications with such governmental agencies that might require such communication from time to time.
Rationale: Controlling the means by which physical media are transmitted will help to track the movement...
Good researchers tend to pull methods out of a tool kit as they are needed" (2006, p. 54). Notwithstanding these criticisms and constraints, though, most social researchers seem to agree that classification by some type of research paradigm is a useful approach based on the need to determine which approach is best suited for a given research enterprise. In this regard, Corby concludes that, "The contested nature of research
Our semester plans gives you unlimited, unrestricted access to our entire library of resources —writing tools, guides, example essays, tutorials, class notes, and more.
Get Started Now