Written Information Security Program (Wisp) For Protection Of Personal Information Template Page 6

ADVERTISEMENT

III. PROTECTIONS AGAINST EXTERNAL DATA SECURITY BREACH
To combat external risks to the security, confidentiality, and/or integrity of any
electronic, paper or other records containing Personal Information, and evaluating and
improving, where necessary, the effectiveness of the current safeguards for limiting such
risks, the following measures are effective immediately:
A. The Corporation’s Office:
1. The Corporation’s office is intended to be a secure facility, due to the
Personal Information contained in the Corporation’s files. All paper
records containing Personal Information shall be maintained in locked
storage when the office is unoccupied.
2. Visitors shall not be permitted to visit unescorted any area within the
Corporation’s office that contains Personal Information.
3. The Corporation’s office shall be locked at all times when unoccupied.
B.
Third Party Service Providers
1. “Third Party Service Providers” are defined as any non-employee to
whom the Corporation grants partial or full access to the Corporation’s
paper or electronic data that contains Personal Information or to areas
within the Corporation’s office in which Personal Information is
stored.
2. All Third Party Service Providers must acknowledge in writing that
they have instituted Personal Information security measures and their
business operations are in compliance with the requirements of CMR
17.00 as it relates to Personal Information to which the Corporation
has granted them access.
3. The Data Security Coordinator shall maintain all Third Party Service
Providers acknowledgments.
C.
The Corporation’s Computers and Electronic Information Systems
1. The wireless network at the Corporation shall always be encrypted.
2. All laptops used by Corporation personnel must be password
protected.
3. All portable devices used by employees or Board Members of the
Corporation to send and receive their Corporation e-mail shall be
password protected, and shall be locked when not in use.
4. The Corporation’s computers and computer system, including any
wireless system, shall, at a minimum, and to the extent technically
feasible, have the following elements:
6

ADVERTISEMENT

00 votes

Related Articles

Related forms

Related Categories

Parent category: Life