Information Security Policy Manual
1Introduction
AG Mortgage Bank is committed to creating and maintaining an environment that protects the Bank’s information resources from accidental or intentional unauthorized use, modification, disclosure, or destruction. AG Mortgage Bank Information Security Policy Manual establishes the information security policies required for appropriately identifying information resources and business requirements and, appropriately protecting those information resources.
Adherence to these information security policies shall safeguard the integrity, confidentiality, and availability of the Bank information and shall protect the interests of the Bank, personnel, customers, business partners, and other stakeholders.
1.1Purpose
The intent of this policy manual and the information security policies contained therein is to create and preserve an environment that:
- Protects information resources critical to the Bank.
- Manages the risk of security exposure or compromise.
- Protects information as mandated by regulatory authorities.
- Protects the personal information and privacy of employees and customers.
- Reinforces the reputation of the Bank as an institution deserving of public trust.
- Identifies and responds to events involving information asset misuse, loss, or unauthorized disclosure.
- Monitors systems for anomalies that might indicate compromise.
- Promotes and increases awareness of information security.
- Complies with due diligence standards for the protection of information resources.
- Assigns responsibilities for the achievement of defined goals to Bank executives, officers, managers, employees, contractors, partners, and vendors as appropriate.
- Incorporates local and international regulatory and compliance requirements and standards for corporate governance
2Policy Manual
2.1Roles and Responsibilities
Head, Internal Control & Audit
The responsibility of the Head of Internal Control and Audit, shall include but not be limited to the following:
- Provide Bank-wide information security program oversight
- Review, prioritize and recommend information security project initiatives for implementation across the Bank
- Review and assist information security strategy and integration efforts, and ensure that business unit managers and process owners support integration
- Review and recommend information security policies for IT Steering Committee consideration.
- Promote awareness of security initiatives within the Bank
- Be the primary sponsor of information security initiatives in the Bank
- Lead responsibility in the management team for information security and shall be working through the Head IT Audit, and be responsible for the development, implementation, and maintenance of the ISMS.
- Guidance on the subject of IT security and the Information Technology Department.
- Respond to security breaches
- Determine whether the expected level of security is being achieved by establishing Key Performance Indicators (KPI) for security such as:
- Number of security incidents
- Number of times a security policy is violated
- Number of attempted intrusions into a system
- Oversee the process of granting access to data by ensuring that access is granted on a need-to-know basis
- Ensure periodic IT risk assessments are performed
Functional Unit Heads/Asset owners
- Accountable for protecting the information within the systems they own
- Sign off accepted security threats, and agree on exemptions
- Define security classification for information they own
- Develop access policies for systems they own
- Give information security management high priority and direct resources accordingly
- Authorize varying levels of access to data as required
- Responsible for specific, named information assets
- Maintain and review security controls for the allocated asset(s)
- Participate in risk assessments concerning their asset(s)
- Ensure the relevant entry in the asset inventory is kept up to date
All Users (Personnel, Vendors, Contractors)
- Comply with the Bank information security policies as published on the Bank’s intranet
- Notify the Information Security Manager or IT Security Officer of all system security issues
- Ensure you use the Bank’s computing and communications facilities in an ethical and legal manner
- Safeguard passwords and/or any other sensitive access information or token relating to user systems or network access account
- Take reasonable precautions to prevent unauthorized use of their accounts, programs, or data by others
- Ensure that accounts or computer and network privileges are restricted to your use only
- Use accounts or network access only for the purpose for which they were provided
For other roles within the ISMS, see Information Security Roles and Responsibilities Document.
2.2Separation of Duties
- To reduce the risk of accidental or deliberate system misuse, separation of duties and areas of responsibility must be implemented where appropriate.
- Whenever separation of duties is not technically feasible, other compensatory controls must be implemented, such as monitoring of activities, audit trails, and management supervision.
- The audit and approval of security controls must always remain independent and segregated from the implementation of security controls.
See Access Control Matrix and ISO 27001 Control Matrix for details.
2.3Information Security Requirements in Project Management
It is vitally important that the Bank information assets are protected at all times, and this is no less true when running a project to achieve business change. These guidelines apply to projects that cover the whole spectrum of business operations and are not limited to those with a significant IT involvement.
AG Mortgage Bank maintains an Information Security Management System (ISMS) which complies with the ISO/IEC 27001:2022 international standard. In order to ensure that this ISMS remains effective on an ongoing basis it is essential that major business changes which are managed as projects address the issue of how information security will be maintained both during the project and once the project has been delivered.
See Information Security Requirements in PM for detailed information security requirements in project management.
2.4Management responsibilities
The Management of AG Mortgage Bank shall demonstrate its commitment to the Bank’s information security policy and standards by providing exemplary leadership and support in enforcing the Bank’s information security policies and standards. Management shall also ensure that all employees, contract staff, and third-party personnel:
- are informed of the Bank’s security policies, requirements, assigned roles, and responsibilities
- conform to the terms and conditions of their employment, which includes compliance with the Bank’s information security policy and practices
- are motivated to fulfill the security policies of the Bank
- are trained and educated on information security to a level relevant and appropriate to their assigned roles and responsibilities
2.5Contact with Authorities and Special Interest Groups
The Bank shall establish and maintain appropriate contacts with relevant secular authorities to facilitate timely reporting of eligible information security incidents and obtain the necessary support to ensure effective management of such.
The Bank shall also maintain appropriate contacts with relevant special interest groups and other specialist security forums and professional associations to constantly update available knowledge of its information security environment and gain access to specialist information security advice
2.6Inventory of Information Assets
The Bank’s information assets shall be clearly identified, and an inventory of all key information assets drawn up and maintained. Information Security Manager & IT shall liaise with Asset Owners to maintain this inventory
All new information assets shall be added to the appropriate schedule as and when they are acquired and removed from the schedule when they are disposed of.
2.6.1Ownership of Information Assets
- All information assets that support the Bank’s processes and operations shall have a designated owner responsible for its effective use and protection.
- Information asset owners shall be involved in:
- Ensuring the correct security classifications of the asset
- Establishing and periodically reviewing the specific access control policies for the asset stating the roles, functions, processes, systems and applications that may have access to their information assets and the level of access or specific actions that shall be permitted.
- Promoting awareness and compliance with the defined security requirements and controls.
- When there are several possible owners of a given information asset, ownership assignment shall go to the individual/department that makes the greatest use of the information resource.
- With the exception of systems and network devices employed by IT to provide services to all other systems and users e.g. Active Directory, Application Development & Testing Environments, Operations Monitoring etc., the IT Department personnel shall not be the designated owners of any of the Bank’s information assets.
- Routine operational and maintenance tasks over an information asset shall be assigned to a designated custodian or administrator that looks after the asset on a daily basis
- Based on the importance of an information asset, its business value and its security classification, levels of protection commensurate with the importance of the asset shall be identified and applied
- Information asset owners shall ensure that staff and external parties using their resource(s) are aware of their responsibility and held accountable for its protection and preservation. Owners shall spread this awareness appropriately.
2.6.2Acceptable use of the Bank’s information assets
- The rules for the acceptable use of information and assets associated with information processing facilities shall be identified, documented, and implemented.
- The Bank’s information resources will be used in an approved, ethical, and lawful manner to avoid loss or damage to the Bank’s operations, image, or financial interests and will be used such as to comply with official policies and procedures on acceptable use. Staff and other personnel shall seek clarification from the Information Security and IT Risk Management, on any activity not explicitly covered by these policies.
- Generally prohibited activities when using the Bank’s information resources include, but are not limited to the following:
- Stealing electronic files or copying of electronic files not related to your normal business activities without management approval.
- Violating copyright laws.
- Downloading and installing unauthorized software, including games and screensavers.
- Browsing the private files or accounts of others, except with explicit Management approval.
- Performing unofficial activities that may degrade the performance of information resources, such as playing electronic games and sending chain emails.
- Performing activities intended to circumvent security or system access controls of the Bank or any other organization, including the possession or use of hardware or software tools intended to defeat software copy protection, discover passwords, identify security vulnerabilities, and decrypt encrypted files or compromise information security by any other means.
- Writing, copying, executing, or attempting to introduce any computer code designed to self-replicate, damage, or otherwise hinder the performance of, or access to, any Bank computer, network, or information. (e.g. computer viruses, worms, trojans, spyware and other forms of malicious software)
- Accessing the Bank’s network via modem or other remote access service without the explicit approval of the Head of IT and Chief Risk Officer of the Bank.
- Promoting or maintaining a personal or private business using the Bank’s information resources i.e. for personal gain.
- Conducting fraudulent or illegal activities, including but not limited to: gambling, trafficking in drugs or weapons, participating in terrorist acts, or attempting unauthorized entry to any Bank or other organization’s systems or network.
- Conducting fundraising, endorsing any product or service, lobbying, or participating in any partisan political activity.
- Disclosing any Bank information that is not otherwise public without authorized management approval.
- Performing any act that may discredit, defame, libel, abuse, embarrass, tarnish, misrepresent, or portray in false light the Bank, its personnel, business partners, or customers.
- Using a logon ID and password not explicitly assigned to you, revealing your account password to others or allowing use of your account by others. This includes family and other household members when working from home.
- Using the bank’s computing assets to actively engage in procuring or transmitting material that is objectionable or in violation of the Bank’s HR policies
- Any automated process used for gathering information about systems is strongly prohibited unless prior approval is obtained. Port scanning or security vulnerability scanning is expressly prohibited except with the prior authorization of the Chief Risk Officer & Divisional Head, IT.
- Executing any form of network monitoring which will intercept data intended for some other system or sending messages of any kind intended to interfere with, or disable someone else’s active session via any means, locally or remotely unless this activity is a part of the employee's normal job/duty.
Refer to Acceptable Use Policy for more details.
2.6.3Return of Asset
- All employees, contract staff and third-party personnel are required to return all the Bank’s properties and assets in their possession upon termination of their employment, contract or agreement.
- The supervising manager shall be responsible for ensuring that custody of the Bank’s information assets has been secured and for confirming to HR that this has been done.
- This shall include such items as all previously issued software, corporate documents, and equipment, mobile computing devices, access cards, keys, manuals, and information stored on electronic media.
- Where an employee, contract staff or third party personnel purchases the Bank’s equipment or uses their own personal equipment, the supervising manager must ensure that all relevant information is transferred to the Bank and securely erased from the equipment
2.7Corporate Electronic Messaging Services Acceptable Usage
- The organization-provided email address must always be used when communicating with others on official business. You should not use a personal email address for this purpose. Guidelines on the sending of classified information (information classified as Restricted or Confidential) via email must be observed at all times.
- All emails sent from an organization email address remain the property of AG Mortgage Bank and are considered to be part of the corporate record. All organization emails should be considered to be official communications from the organization and treated accordingly.
- The organization maintains its legal right to monitor and audit the use of email by authorized users to assess compliance to this policy. This will be done in accordance with the provisions of relevant legislation.
- Deletion of an email from an individual account does not necessarily mean that it has been permanently removed from the organization’s IT systems and such emails may still be subject to audit and review.
- All e-mails sent from organization addresses to recipients outside of the organization will automatically carry the following disclaimer:
“The information contained in this message is intended for the addressee only and may contain classified information. If you are not the addressee, please delete this message and notify the sender; you should not copy or distribute this message or disclose its contents to anyone. Any views or opinions expressed in this message are those of the individual(s) and not necessarily of the organization. No reliance may be placed on this message without written confirmation from an authorized representative of its contents. No guarantee is implied that this message or any attachment is virus free or has not been intercepted and amended.”
- Users should remain aware that it cannot be guaranteed that an email will be received or read by a recipient and that messages can be interpreted in different ways according to the culture, role and even prevailing mood of the individual reading it. You should therefore at all times consider whether the use of email is an appropriate means of conveying the information involved and whether an alternative such as the telephone would be preferable, particularly if the message is urgent or complex.
- Particular care must be taken when addressing emails that include classified information to prevent accidental transmission to unauthorized recipients. Beware of the auto-completion feature of some email clients where the system suggests recipients based on the characters typed in so far.
- Do not use auto-forwarding e.g. whilst on holiday, if there is a possibility that this may result in classified information being forwarded to a recipient that does not have sufficient security clearance for the level of information involved.
- Users should avoid sending unnecessary messages to distribution lists, particularly those with wide circulation such as the “global list” of all employees. Where required, such emails should be sent via the organization’s communications department.
- Emails from an organization email address should be considered in the same way as other more formal methods of communication. Nothing should be sent externally which might affect the organization’s reputation or affect its relationships with suppliers, customers or other stakeholders.
- In particular, users should not send emails containing material, which is defamatory, obscene, does not comply with the organization’s Equality and Diversity Policy or which a recipient might otherwise reasonably consider inappropriate. If you are not sure whether your intended message falls into this category, please consult your line manager before sending the email.
- Official organization email addresses and facilities should not be used:
- for the distribution of unsolicited commercial or advertising material, chain letters, or other junk-mail of any kind, to other organizations
- to send material that infringes the copyright or intellectual property rights of another person or organization
- for activities that corrupt or destroy other users’ data or otherwise disrupt the work of other users
- to distribute any offensive, obscene or indecent images, data, or other material, or any data capable of being resolved into obscene or indecent images or material
- to send anything which is designed or likely to cause annoyance, inconvenience or needless anxiety to others
- to convey abusive, threatening or bullying messages to others
- to transmit material that either discriminates or encourages discrimination on the grounds of race, gender, sexual orientation, marital status, disability, political or religious beliefs
- for the transmission of defamatory material or false claims of a deceptive nature
- for activities that violate the privacy of other users
- to send anonymous messages - i.e. without clear identification of the sender
- for any other activities which bring, or may bring, the organization into disrepute
If you receive unsolicited junk email or spam, it is advised that you delete such messages without reading them. Do not reply to the email as this can confirm the existence of a valid address to the sender, resulting in further unwanted communications.
2.8Information Classification
On creation, all information assets must be assessed and classified by the owner according to their content. The classification will determine how the document should be protected and who should be allowed access to it. Any system subsequently allowing access to this information should clearly indicate the classification.
The AG Mortgage Bank Information Security Classification Scheme requires information assets to be protectively marked into one of 3 classifications (excluding Public information which does not need to be marked). The way the document is handled, published, moved and stored will be dependent on this scheme.
The levels of information are:
- 3Confidential
- 2Restricted
- 1Internal Use
- 0Public (or unclassified)
Refer to Information Security Classification Scheme for details.
2.9Password Policy
The following rules are based on guidance from the UK NCSC (National Cyber Security Centre), USA National Institute of Standards and Technology (NIST) and the Payment Card Industry Standard Security Council. Where possible, passwords will have the following characteristics:
- Require a minimum length of at least eight characters
- Password expiry of about 30 days
- Password history shall be set to 10
- Password complexity requirements will be used (e.g., specifying that a password must contain special characters and numbers)
- Single Sign-On (SSO – where a user is authenticated once and then has access to many systems) will be used where available and appropriate
- After three unsuccessful login attempts are made, the user account will be locked out for about 30 mins or will need to be re-enabled by an administrator
- If a session has been idle for a period of 5 minutes, the user will be required to re-authenticate
- Newly issued passwords will be subject to change immediately after first use
- System default accounts/passwords will be disabled/changed immediately as part of initial setup and configuration.
- Passwords will never be displayed in clear text whilst being entered and will be stored in encrypted files separate from main application data .
- All password standards shall be system enforced where possible.
- Inactive accounts for more than ninety (90) days are to be either removed or disabled
2.9.1Additional guidelines for users
The following additional guidelines are given to assist all employees, stakeholders and third parties to ensure their account passwords are always protected:
- Do not reveal your password to anyone at any time on any medium (telephone, email, instant message etc.).
- Do not write passwords down.
- When creating a password, do not use dictionary words, names of family members or information about yourself that could be easily found e.g. date of birth.
- If you suspect your password has been compromised, change it immediately .
- Where IT systems offer ‘password hints’ do not make the hint easy enough for anyone to guess your password e.g. password hint = my surname.
- Where possible use passphrases instead of passwords. A passphrase is a longer version of a password and is, therefore, more secure. It is typically composed of multiple words therefore reducing the risk of ‘dictionary attacks’.
- Be mindful when entering your password that no one is watching you over your shoulder.
- If you suspect the IT system you are about to enter your password into is compromised or looks suspicious, do not enter the password and report the issue to your line manager/ team lead. Please refer to the organization’s Incident Management Process for more information.
2.10Anti-Malware Policy
- All AG Mortgage Bank production and non-production systems and servers must have anti-virus protection software installed. The anti-virus software must be configured to automatically scan all files for malicious code.
- All users must adhere and comply with applicable AG Mortgage Bank information security policies.
- Users must not, under any circumstance, disable or tamper with the antivirus software/configurations.
- Users cannot uninstall nor can they stop any anti-virus-related services. Users can set up a custom scan of their own machine.
- Anti-virus software signature files must be kept current. These files require regular updating to protect against new malicious codes that appear regularly. The signature files must be updated automatically, on a regular basis as definition updates become available and must be downloaded to all AG Mortgage Bank systems and servers.
- Distribution of signature files and anti-virus client engine files will be done via a primary server which is distributed within the network. The primary server provides compliance monitoring. From the primary server monitoring utility, reporting can be performed on all clients which show the current definition version, threat status, last completed scan, etc.
- The Bank has approved the use of Kaspersky to protect the Bank PC and mobile devices from malware.
- Downloading software from external sources (e.g., from an external network or a bulletin board, a vendor's product or demo, vendor's diagnostic/maintenance package, client, customer, etc.) using AG Mortgage Bank’s information assets is prohibited unless:
- An approved business need requires such download.
- The downloaded software is approved by the IS Team.
- The software is installed in accordance with all applicable AG Mortgage Bank licensing policies and standards
- The software is screened for virus and other malicious code with the approved anti-virus software.
- AG Mortgage Bank shall provide anti-virus protection at the network boundary for all email that is forwarded to and from the Internet, file servers, and staff systems. Staff systems are locked from removing or modifying anti-virus schedules but can schedule additional scans.
- All employees must notify the IT and Information Security Manager of any virus found by the anti-virus software
3Violation
AG Mortgage Bank Staff found to have violated this policy may be subject to disciplinary action, up to and including termination.