Information Security Policy

Information Security Policy 

 

Policy Number:

OPER_0043

Contents

  1. Introduction
  2. Information Security Policy
  3. Acceptable Use Policy
  4. Disciplinary Action
  5. Protect Stored Data
  6. Information Classification
  7. Access to the sensitive card holder data
  8. Physical Security
  9. Protect Data in Transit
  10. Disposal of Stored Data
  11. Security Awareness and Procedures
  12. Network security
  13. System and Password Policy
  14. Anti-virus policy
  15. Patch Management Policy
  16. Remote Access policy
  17. Vulnerability Management Policy
  18. Configuration
  19. Change Control Process
  20. Audit and Log review
  21. Secure Application development
  22. Penetration testing methodology
  23. Incident Response Plan
  1. Roles and Responsibilities
  2. Third party access to sensitive data
  3. User Access Management
  4. Access Control Policy
  5. Wireless Policy
  6. Identity Theft Policy “Red Flag Rule”

Definitions

Applicability

Sensitive Information to be protected:

Risk Assessment

Suspicious Documents

Suspicious Personal Identifying Information

Unusual use of, or Suspicious Activity Related to the Covered Account

Protective Actions to be Taken

Detection of Red Flags GCCC shall address the detection of Red Flags in connection with the opening of Covered Accounts by:

Response to Red Flags

Oversight of Service Providers

Non-disclosure of Specific Practices

Annual Updates

Program Administration

Appendix B

List of Service Providers

 

 

 

1.       Introduction

This Policy Document encompasses all aspects of security surrounding confidential Garden City Community College information and must be distributed to all company employees. All company employees must read this document in its entirety and sign the form confirming they have read and understand this policy fully.

This document will be reviewed and updated by Director of Information Technology on an annual basis or, when relevant, include newly developed security standards. Policy updates will be distributed to all employees and contracts as applicable.

2.       Information Security Policy

Garden City Community College handles sensitive information daily. Safeguards must be in place to protect sensitive information, to protect privacy, to ensure compliance with various regulations and to guard the future of the organization.

Garden City Community College commits to respecting the privacy of all its employees and students and protecting any data about them from outside parties. To this end the college is committed to maintaining a secure environment in which to process information so that we can fulfill these promises.

Employees handling Sensitive data should ensure:

We each have a responsibility for ensuring our company’s systems and data are protected from unauthorized access and improper use.  Garden City Community College reserves the right to monitor, access, review, audit, copy, store or delete any electronic communications, equipment, systems and network traffic for any purpose. If you are unclear about any of the policies detailed herein you should seek advice and guidance from your director.



3.       Acceptable Use Policy

The Administration's intentions for publishing an Acceptable Use Policy are not to impose restrictions that are contrary to Garden City Community College’s established culture of openness, trust and integrity. Garden City Community College Administration is committed to protecting the college, employees and partners from illegal or damaging actions by individuals, either knowingly or unknowingly. The IT department will maintain an approved list of technologies and devices and personnel with access to such devices, as detailed in Appendix B.

 

 

4.       Disciplinary Action

Violation of the standards, policies and procedures presented in this document by an employee will result in disciplinary action, from warnings or reprimands up to and including termination of employment. Claims of ignorance, good intentions or using poor judgment will not be accepted as excuses for non-compliance. 

5.       Protect Stored Data

 

It is strictly prohibited to store:

6.       Information Classification

Data, and media containing data, is required to be labelled to indicate sensitivity level.

 

7.       Access to the sensitive card holder data

All Access to sensitive card holder data should be controlled and authorized. Any job functions that require access to card holder data should be clearly defined.

 

 

8.       Physical Security

Access to sensitive information in both hard and soft media format must be physically restricted to prevent unauthorized individuals from obtaining sensitive data.

 

 

9.       Protect Data in Transit

10.   Disposal of Stored Data

 

 

11.   Security Awareness and Procedures

The policies and procedures outlined below must be incorporated into company practice to maintain a high level of security awareness. The protection of sensitive data demands regular training of all employees and contractors. 

12.   Network security

 

13.   System and Password Policy

All users, including contractors and vendors with access to Garden City Community College systems, are responsible for taking the appropriate steps, as outlined below, to select and secure their passwords.

14.   Anti-virus policy

 

 

15.   Patch Management Policy

16.   Remote Access policy

 

 

17.   Vulnerability Management Policy

 

18.   Configuration

 

19.   Change Control Process

20.   Audit and Log review

21.   Secure Application development

Application Code Developers shall:

22.   Penetration testing methodology

Example 1#

Risk: Denial of Service in systems or network devices because of the network scans.

Mitigation measure 1: network scans must be performed in a controlled manner. The start and end of the scan must be notified to responsible personnel to allow monitoring during testing. For any sign of trouble will abort the scan in progress.

Mitigation measure 2: scanning tools must be configured to guarantee that the volume of sent packets or sessions established per minute does not cause a problem for network elements. In this sense, we must perform the first scans in a very controlled way and a use minimum configuration that may be expanded when is evident that the configuration is not dangerous for network devices or servers in the organization.

Director of IT: Andrew Knoll

Responsible for web site:www.gcccks.edu

Example:

 

 

23.   Incident Response Plan

'Security incident' means any incident (accidental, intentional or deliberate) relating to your communications or any information breach. The attacker could be a malicious stranger, a competitor, or a disgruntled employee, and their intention might be to steal information or money, or just to damage your business.

The Incident response plan has to be tested once annually. Copies of this incident response plan is to be made available to all relevant staff members, and take steps to ensure that they understand it and what is expected of them.

Employees of Garden City Community College will be expected to report to the security officer for any security related issues.

Garden City Community College PCI security incident response plan is as follows:

  1. Each department must report an incident to the Information Security Officer (preferably) or to another member of the IT Staff.
  2. That member of the team receiving the report will advise the Vice President of the incident.
  3. The IT Staff will investigate the incident and assist the potentially compromised department in limiting the exposure of data and in mitigating the risks associated with the incident.
  4. The IT Staff will resolve the problem to the satisfaction of all parties involved, including reporting the incident and findings to the appropriate parties (credit card associations, credit card processors, etc.) as necessary.
  5. The IT Staff will determine if policies and processes need to be updated to avoid a similar incident in the future, and whether additional safeguards are required in the environment where the incident occurred, or for the institution.
  6. If an unauthorized wireless access point or devices is identified or detected as part of the quarterly test this is should be immediately escalated to the Security officer or someone with similar privileges who has the authority to stop, cease, shut down, and remove the offending device immediately.
  7. A department that reasonably believes it may have a data breach or of systems related to the PCI environment in general, must inform Garden City Community College IT Staff. After being notified of a compromise, the IT Staff, along with other designated staff, will implement the Incident Response Plan to assist and augment departments’ response plans.

Garden City Community College Incident Response Team:

(Update as applicable)

Vice President of Administrative Services/CFO: CFO@gcccks.edu

Information Security Officer: IT@gcccks.edu

Collections & Merchant Services: Business@gcccks.edu

Incident Response Notification
Escalation Members:  IT Director, Network Administrator, IT@gcccks.edu
Escalation – First Level: Computer Technician, IT@gcccks.edu
Information Security Officer: IT Director, IT@gcccks.edu
Director of Financial Aid: finaid@gcccks.edu
Controller: business@gcccks.edu
Director of Marketing and Public Relations: marketing@gcccks.edu

Escalation – Second Level
Garden City Community College President Executive Cabinet
Internal Auditing Group
Auxiliary members (as needed)
External Contacts (as needed)
Merchant Provider Card
Brands
Internet Service Provider (if applicable)
Internet Service Provider of Intruder (if applicable)
Communication Carriers (local and long distance) Business Partners
Insurance Carrier
External Response Team as applicable (CERT Coordination Center 1, etc)
Law Enforcement Agencies as applicable inn local jurisdiction

In response to a systems compromise, the Incident Response Team will:
Ensure compromised system/s is isolated on/from the network.

 

Incident Response notifications to various card schemes: 

VISA Steps

If the data security compromise involves credit card account numbers, implement the following procedure: 

  1. Shut down any systems or processes involved in the breach to limit the extent, and prevent further exposure.
  2. Alert all affected parties and authorities such as Commerce Bank, Visa Fraud Control, and the law enforcement.
  3. Provide details of all compromised or potentially compromised card numbers to Visa Fraud Control within 24 hrs.
  4. For more Information visit:http://usa.visa.com/business/accepting_visa/ops_risk_management/cisp_if_ compromised.html

Visa Incident Report Template

This report must be provided to VISA within 14 days after initial report of incident to VISA. The following report content and standards must be followed when completing the incident report. Incident reporting must be securely distributed to VISA and Commerce Bank. Visa will classify the report as “VISA Secret”*. • Executive Summary

MasterCard Steps

  1. Within 24 hours of an account compromise event, notify the MasterCard Compromised Account Team via phone at 1-636-722-4100.
  2. Provide a detailed written statement of fact about the account compromise (including the contributing circumstances) via secured e-mail to compromised_account_team@mastercard.com.
  3. Provide the MasterCard Merchant Fraud Control Department with a complete list of all known compromised account numbers.
  4. Within 72 hours of knowledge of a suspected account compromise, engage the services of a data security firm acceptable to MasterCard to assess the vulnerability of the compromised data and related systems (such as a detailed forensics evaluation).
  5. Provide weekly written status reports to MasterCard, addressing open questions and issues until the audit is complete to the satisfaction of MasterCard.
  6. Promptly furnish updated lists of potential or known compromised account numbers, additional documentation, and other information that MasterCard may request.
  7. Provide finding of all audits and investigations to the MasterCard Merchant Fraud Control department within the required time frame and continue to address any outstanding exposure or recommendation until resolved to the satisfaction of MasterCard.

Once MasterCard obtains the details of the account data compromise and the list of compromised account numbers, MasterCard will:

Employees of Garden City Community College will be expected to report to the security officer for any security related issues. The role of the security officer is to effectively communicate all security policies and procedures to employees within Garden City Community College and contractors. In addition to this, the security officer will oversee the scheduling of security training sessions, monitor and enforce the security policies outlined in both this document and at the training sessions and finally, oversee the implementation of the incident response plan in the event of a sensitive data compromise. 

Discover Card Steps

  1. Within 24 hours of an account compromise event, notify Discover Fraud Prevention
  2. Prepare a detailed written statement of fact about the account compromise including the contributing circumstances.
  3. Prepare a list of all known compromised account numbers.
  4. Obtain additional specific requirements from Discover Card

American Express Steps

  1. Within 24 hours of an account compromise event, notify American Express Merchant Services
  2. Prepare a detailed written statement of fact about the account compromise including the contributing circumstances
  3. Prepare a list of all known compromised account numbers
  4. Obtain additional specific requirements from American Express

24.   Roles and Responsibilities

The Vice President of Administrative Services/CFO (or equivalent) is responsible for overseeing all aspects of information security, including but not limited to:

 

The Human Resources Office (or equivalent) is responsible for tracking employee participation in the security awareness program, including:

 

General Counsel (or equivalent) will ensure that for service providers with whom sensitive information is shared have:

25.   Third party access to sensitive data

26.   User Access Management

Name of person making request:

Job title of the newcomers and workgroup:

Start date:

Services required (default services are: MS Outlook, MS Office and Internet access)

27.   Access Control Policy

 

28.   Wireless Policy

 

If the need arises to use wireless technology it should be approved by Garden City Community College and the following wireless standards have to be adhered to:

29.   Identity Theft Policy “Red Flag Rule”

 

 

Definitions

Applicability


This program applies to all staff, faculty, students and all personnel affiliated with third parties providing services to the college relating to Covered Accounts and/or Sensitive Information within the custody of control of the college.

Sensitive Information to be protected:

Risk Assessment

Suspicious Documents

 

Suspicious Personal Identifying Information

Unusual use of, or Suspicious Activity Related to the Covered Account

Protective Actions to be Taken

Detection of Red Flags GCCC shall address the detection of Red Flags in connection with the opening of Covered Accounts by:

Response to Red Flags

GCCC shall respond quickly to prevent identity theft. In all cases Red Flags are to be reported to the Chief Financial Officer. Response to Red Flags may include, but not be limited to:

Oversight of Service Providers

The college will make reasonable efforts to ensure that the activity of a service provider engaged by the College to perform an activity in connection with Covered Accounts, is conducted with reasonable policies and procedures designed to detect, prevent, and mitigate the risk of identity theft. The college shall request that a copy of the service providers Red Flag Policy be sent to the college for review and maintained on file.

Non-disclosure of Specific Practices

For the effectiveness of this Identity Theft Prevention Program, knowledge about specific Red Flag identification, detection, mitigation and prevention practices may need to be limited to those employees with a need to know them. Any documents that may have been produced or are produced in order to develop or implement this program that list or describe such specific practices and the information those documents contain are considered “confidential” and should not be share with other College employees or the public. The Program Administrator shall inform the Committee and those employees with a need to know the information of those documents or specific practices which should be maintained in a confidential manner.

Annual Updates

The administrators of the College shall annually review this policy and recommend revisions when necessary to address changes in risks to students, faculty and staff based upon factors such as:

Program Administration

Training shall be conducted by the Program Administrator, Vice President of Business Affairs/Chief Financial Officer, for faculty and staff on an annual basis.

Additional information can be found at: http://www.ftc.gov/redflagsrule

 

Appendix B

 

List of Service Providers

 

 

Policy History:

October 1, 2025: Revised for accessibility