Please enable JavaScript.
Coggle requires JavaScript to display documents.
Policy, Legal Ethics and
Compliances (PLE) - Coggle Diagram
Policy, Legal Ethics and
Compliances (PLE)
Cybersecurity Concept:
• Goal: Protection of information and information systems.
• Definition: Protecting information systems against unauthorized access, modification, or denial of service to authorized users.
-
Sensitive Data:.
• Loss of confidentiality, integrity, or availability results in a catastrophic impact.
• Types: Employee data, financial, payroll, medical, and privacy-related legal data.
• Cybercrime: Criminal activity where a computer is the tool, target, or place of the criminal activity.
-
-
Best Practices:
-
• Protect Personally Identifiable Information (PII): Minimize it, secure it, protect its transfer, and dispose of it properly.
• Situational Awareness: Avoid discussing work in public, remove security badge when leaving the workstation.
• Prevent Spillage: Encrypt data before storage, store on accredited networks, categorize papers containing PII.
Social Engineering:.
• DO: Document the situation (verify identity, get info), and contact your Information System Security Officer (ISSO).
• DON'T: Participate in surveys, share personal information, or give out computer systems/network information.
• Mobile Computing: Always maintain physical control, disable wireless functionality when not in use.
• Reporting: Immediately report suspicious computer problems (Trojan Horses, Worms, etc.) to the ISSO or EDCIRC.
-
-
Password Policy:
-
-
• Must be Strong (at least 8 characters and contain 3 of 4 properties: numbers, alphabetical letters, uppercase/lowercase, special characters).
• Organization Security: Do not store PII on unencrypted storage devices, remove PIV card, do not write down passwords.
• Facility Protection: Always use your own badge, report any suspicious activity to the ISSO.