1.1 This policy ensures that information technology systems and disaster recovery and response processes are in place to maintain business continuity, confidentiality, integrity, and availability of information assets.
02
2. Scope
2.1 This policy applies to all IT resources, including hardware, software, networks, and data, and all employees, contractors, consultants, and others using these resources on behalf of the Society.
03
3. Roles and Responsibilities
3.1 The IT department is responsible for maintaining and updating IT systems and ensuring appropriate security measures are in place.
3.2 The DRR team is responsible for developing, implementing, and testing disaster recovery plans.
3.3 All employees are responsible for complying with this policy and reporting suspected security incidents or vulnerabilities to the IT department.
04
4. IT Security
4.1 Access to IT resources should be restricted to authorized personnel with least-privilege user accounts and strong passwords.
4.2 Information security policies should protect confidentiality, integrity, and availability of data, including regular backups, encryption, and access controls.
4.3 Network security policies should protect against unauthorized access and data breaches using firewalls, intrusion detection systems, and regular network scans.
4.4 Employees should follow email security best practices and avoid suspicious emails or attachments, weak passwords, and personal email for work purposes.
4.5 Employees should use social media and online activities responsibly, avoid sharing confidential information, and avoid activities harming the Society reputation.
05
5. Disaster Recovery and Response
5.1 The Society should have a business continuity plan outlining procedures for responding to disasters and maintaining business continuity.
5.2 Regular backups should be performed and stored securely offsite.
5.3 An incident response plan should outline procedures for responding to security incidents and be reviewed and tested regularly.
5.4 An emergency response plan should outline procedures for natural disasters, pandemics, and other emergencies and be reviewed and tested regularly.
06
6. Compliance
6.1 The Society should comply with applicable laws and regulations related to IT security and disaster recovery and response, including the Information Technology Act, 2000 and Disaster Management Act, 2005.
07
7. Training
7.1 All employees should receive regular training on IT security and disaster recovery and response policies and procedures.
08
8. Monitoring and Review
8.1 The IT department should monitor systems for vulnerabilities and threats and conduct security assessments.
8.2 The DRR team should review and test disaster recovery plans regularly.
8.3 This policy should be reviewed and updated regularly to ensure effectiveness and relevance.