Transcription of Group IT Security Policy V2 - Coorpacademy
1 - 28th of May 2014 Group IT Security Policy V2 Entity Name Position Date Signature - - 1. SCOPE AND TARGETS .. 4 Foreword .. 4 Why a Security Policy ? .. 4 Applicability statement .. 4 Group Security Policy approval process .. 4 Group vs. Entities responsibilities .. 4 Policy Management .. 5 Main acronyms .. 5 Security related business needs .. 5 About Security needs .. 6 Security needs and risks assessment .. 8 Security Policy audience .. 8 Management related targets .. 8 Security expertise related targets .. 8 Personnel related targets .. 8 2. Security MANAGEMENT .. 9 Organization and responsibilities .. 9 Security .. 9 Responsibilities .. 9 Security framework .. 10 Security forum .. 10 Conformity, reporting and improvement .. 11 Controls and traceability.
2 11 Security Reporting .. 11 Incident management and business continuity .. 11 Security incident and crisis management .. 11 Business applications continuity needs .. 12 Business applications continuity means .. 12 Personnel management, behaviour and training .. 13 HR process and procedures .. 13 IT end user Policy .. 13 External parties management .. 13 Outsourcing and subcontracting .. 13 Third party IT users .. 14 Legal Compliance .. 14 Compliance with applicable legislation .. 14 Software Compliance .. 14 3. INFRASTRUCTURE AND OPERATIONS Security .. 15 Computing devices and network Security .. 15 Workstations and mobile devices Security .. 15 Group network Security .. 15 Entities network Security .. 16 Operation Security .. 16 Servers protection .. 16 Supervision and control .. 16 Physical and environmental Security .
3 17 IT facilities perimeter and access .. 17 Hazardous threats protection .. 17 4. APPLICATIONS AND DATA Security .. 18 Applications and data classification .. 18 Classification process and specific Security rules .. 18 - - Inventory of the sensitive assets .. 18 Development and maintenance .. 18 Security within project management .. 18 Software development and maintenance Security .. 19 Logical access protection .. 19 Accounts and privileges .. 19 Authentication .. 20 Remote access .. 21 5. IT Security COMPONENTS .. 22 - - 1. Scope and targets Foreword Why a Security Policy ? Information Technology (IT) has become an essential factor in the operational effectiveness and continued competitiveness of the Group . As IT becomes more and more integral to the successful delivery of the companies objectives, IT must reach a satisfactory level of reliability.
4 In accordance with Pernod Ricard s Integrity value, the Security Policy is a key factor in ensuring information reliability. Therefore, the application of this document has to fulfil three expectations: To protect the Group Information systems assets, To improve the Group IT Security level among entities while taking into account their disparities in terms of activity, sales level and culture. To ensure compliance with applicable legal requirements such as French LSF , Data privacy, .. Applicability statement This Security Policy is applicable to the IT of the Group and some of its partners (customers, suppliers, consultants, etc.), therefore: Each entity (regional level, affiliate or data centre) must be covered by an IT Security Policy . The Group IT Security Policy should be considered a minimum.
5 Locally, affiliate Security Policy can be stricter. If an entity Security Policy does not exist, the upper level Security Policy will be considered as directly applicable ( the Group Security Policy will apply to an entity which does not have its own Policy ). All aspects are applicable to third parties IT users, external ). Furthermore, any employee of the Pernod Ricard Group has to comply with this Policy through clear and appropriate training and/or documentation as required. Group Security Policy approval process The Group Security Policy is inter-related with the IT resources and processes. It is also inter-related with each Group business process, therefore, the approval involves: The executive management, The Group IT department, The Group Internal Audit department. Group vs. Entities responsibilities There are well defined responsibilities for both the Group and the entity levels functions: Group level is responsible for defining, supporting and updating the Group Security Policy .
6 - - For Group applications and services spread worldwide (Prisma, Group Active Directory, ESN, Group cloud ), Group is responsible for global compliance and the local affiliates must apply local Security rules ( user management, application access ) Entity level is responsible for understanding and implementing the Security Policy taking into account specific local requirements. Policy Management The Group Security Policy is to be reviewed on a yearly basis in order to keep up to date with changing Security requirements (new threats, etc), risk assessments, business/IT developments and entities feedback. Policy reviews are to be conducted at a Group level in collaboration with entity Security representatives. To fulfil this objective, each of the Security representatives is to participate in a draft review of the Group Security Policy and to provide suggestions and feedback.
7 For each Policy update, an appropriate review and communication plan will be formalised. Following the publication of the Group Security Policy , any existing entity level Security policies will be updated in accordance with Group Security Policy . Main acronyms The main acronyms used in this document are listed in the table below: Acronyms Meaning A, I, C, T Availability, Integrity, Confidentiality, Traceability BCP Business Continuity Plan DMZ Demilitarized Zone DRP Disaster Recovery Plan ESN Enterprise Social Network IS Information System IPS Intrusion Prevention System ISMS Information Security Management System IT Information Technology NDA Non-Disclosure Agreement PKI Public Key Infrastructure UPS Uninterruptible Power Supplies RTO Recovery Time Objective RPO Recovery Point Objective SOC Security Operation centre (service provided for monitoring data centres Security ) Security related business needs - - About Security needs Criteria These four criteria form the basis for Security requirements and risks assessment.
8 Therefore, they should be understood by each individual handling sensitive IT assets. Criteria Meaning Main threats Availability Recovery of an application or data within a pre-determined time period (Recovery Time Objective) and to a pre-determined point in time (Recovery Point Objective). System failures, environmental and natural disasters, energy supply shock Integrity Non-alteration of data and systems. Human error, user access rights usurpation or overruling, virus, system and software failures, hacking. Confidentiality Non-disclosure of strategic information to unauthorised groups or individuals. User access rights usurpation and overruling, industrial espionage, Human behaviour, and Trojans, network eavesdropping. Traceability Capability to trace and proof the origin of an event related to the IT data and process. Denial of action, fraud, user access rights usurpation, breach of the legal requirements.
9 Security levels The Security levels (or criticality Levels ) defined below are the Group guidelines for any IT related processes and/or resources. The Security level (1 Low, 2 Medium, 3 High) of an asset or process are determined by the business value (criticality) of the asset to the operation of the Group . - - Criticality Levels 1 2 3 Impacts Image Image of the Group is altered, in the very short term, for a few individuals (customers, employees and partners). Image of the Group is altered, in the short term, for a moderate number of individuals (customers, employees and partners). Image of the Group is altered, in the middle or long term, for a large number of individuals (customers, employees and partners). Finance Competiveness Financial consequences are not significant regarding the profitability and the competitiveness of the concerned entity (No gearing impact).
10 Financial consequences impact moderately the profitability and the competitiveness of the concerned entity (gearing impact <5%). Financial consequences impact strongly the profitability and the competitiveness of the concerned entity (gearing impact >5%). Strategy Strategy of an entity is slightly delayed or affected (office ). Strategy of an entity is moderately delayed or affected (management organisation, product ). Strategy of an entity is affected concerning major topics (merger, acquisition, international ). Compliance Industry standard best practices are not fully applied (professional standards, ). Some laws and regulation are not yet fully applied. The potential consequences shall remain moderate. Some laws and regulation are not applied.