Sample Electronic Mail Acceptable Use Standard:: Difference between revisions

From HORSE - Holistic Operational Readiness Security Evaluation.
Jump to navigation Jump to search
No edit summary
No edit summary
Line 1: Line 1:
==Document History==
==Sample Electronic Mail Acceptable Use Standard==
The Electronic Mail Acceptable Use Standard builds on the objectives established in the [[Sample_Acceptable_Use_Policy:|'''Acceptable Use Standard''']], and provides specific instructions and requirements on the proper and appropriate business use of Electronic Mail Resources.
 
==Objectives==
# '''Business Use'''
## Company Electronic Mail Resources are provided primarily for official and authorized Company business use and purposes in support of the following business goals and objectives: Support of the Company mission.
## Limited personal use of Company Electronic Mail Resources is acceptable as long as it does not interfere with normal business operations, conflict with business interests, or has an adverse impact on the reputation of the Company.
## The use of Company Electronic Mail Resources shall be in accordance with applicable laws and regulations.
## Users shall be accountable for all Electronic Mail activity associated with their accounts.
## All electronic mail transmissions outside the Company must have the following disclaimer attached: "This e-mail message (and any attachment) is intended for the use of the individual or entity to which it is addressed. This message contains information from Lazarus Alliance, LLC. that may be privileged, confidential, or exempt from disclosure under applicable law. If you are not the intended recipient or authorized to receive this for the intended recipient, any use, dissemination, distribution, retention, archiving, or copying of this communication is strictly prohibited. If you have received this e-mail in error, please notify the sender immediately by reply e-mail, delete this message, and delete the material from all computers."
# '''Improper Use'''
## Any use of Company Electronic Mail Resources must not be illegal, must not constitute or be perceived as a conflict of Company interest, must not violate Company policies, and must not interfere with normal business activities and operations.
## Users shall not violate any laws or regulations through the use of Company Electronic Mail Resources.
## Company Electronic Mail Resources shall not be used to forward chain letters, virus warnings, and hoaxes or support other such "re-mailing" activities.
## Company Electronic Mail Resources shall not be used to download, transmit, or store objectionable material, images, or content.
## Company Electronic Mail Resources shall not be used to conduct personal or non-Company solicitations.
## Users must not allow others to access Electronic Mail Resources by using their accounts.
## The use of third party Electronic Mail Resources such as personal Electronic Mail accounts outside of Company provided Electronic Mail Resources in the transmission of Company information is prohibited. Accessing third party personal Electronic Mail Resources is only permitted while an employee is off duty and while an employee is not using Company resources. The usage of Company owned resources is for business purposes only.
# '''Electronic Mail Software'''
## Only Company approved versions and configurations of electronic mail software listed within the Company System of Record documentation may be used.
## Users must not adjust the electronic mail software security settings to be less restrictive than the Company approved configuration.
## Users shall not use software or features that automatically forward electronic mail messages.
## Users shall not use software or features (such as an anonymous mail sender) that obscures or masks the identity of the message sender.
# '''Downloaded Materials'''
## Company Electronic Mail Resources shall not be used to send, receive or store any commercial software, shareware, or freeware without the Company's prior written authorization.
## The content and attachments of electronic mail messages must be reviewed for malicious code and viruses in accordance with the Asset Protection Standard and the Anti-Virus Standard.
## For security and performance purposes, electronic mail attachments must be less than [35 MB].
# '''Right to Monitor'''
## All Electronic Mail Resources and all messages created, received, processed, transmitted, and/or stored on Company Electronic Mail Resources are Company information assets and property.
## The Company reserves the right to monitor and review all activities and messages using Company Electronic Mail Resources at any time by authorized Company personnel.
## The Company reserves the right to disclose the nature and content of any User's messages and activities involving Company Electronic Mail Resources to law enforcement officials or other third parties without any prior notice to the User.
# '''Privacy Expectations'''
## Users should have no expectations of privacy when using Company Electronic Mail Resources.
# '''Storage Capacity'''
## Users shall delete unnecessary electronic mail message to avoid unnecessary accumulation of storage on the Company electronic mail servers.
## Electronic mail messages containing business critical information should be stored on production servers to ensure proper data backup.
## The approved record retention period for electronic mail messages is governed by the Records Retention Schedule.
# '''Misuse Reporting '''
## Actual or suspected misuse of Company Electronic Mail Resources should be reported in accordance with the Misuse Reporting Standard.
## Upon the receipt or continued receipt of objectionable electronic mail, Users should contact Information Security in accordance with the Misuse Reporting Standard.
<br>
<br>
{| id="table1" width="100%" border="1"
 
| bgcolor="#C0C0C0" | '''Version'''
==Document Examples==
| bgcolor="#C0C0C0" | '''Date'''
Use these samples as a guide for your policy development. Fully customizable versions are available from [http://policy-machine.com The Policy Machine].<br>
| bgcolor="#C0C0C0" | '''Revised By'''
| bgcolor="#C0C0C0" | '''Description'''
|-
| 1.0
| 1 January 2010 <Current date>
| Michael D. Peters '''<Owners's name>'''
| This version replaces any prior version.
|}
<br>
==Document Certification==
<br>
{| id="table1" width="100%" border="1"
| bgcolor="#C0C0C0" | '''Description'''
| bgcolor="#C0C0C0" | '''Date Parameters'''
|-
| '''Designated document recertification cycle in days:'''
| 30 - 90 - 180 - '''365''' '''<Select cycle>'''
|-
| '''Next document recertification date:'''
| 1 January 2011 '''<Date>'''
|}
<br>
<br>
<gallery>
Image:Electronic Mail Acceptable Use Standard.png|Electronic Mail Acceptable Use Standard page one of nine.
Image:Electronic Mail Acceptable Use Standard(1).png|Electronic Mail Acceptable Use Standard page two of nine.
Image:Electronic Mail Acceptable Use Standard(2).png|Electronic Mail Acceptable Use Standard page three of nine.
Image:Electronic Mail Acceptable Use Standard(3).png|Electronic Mail Acceptable Use Standard page four of nine.
Image:Electronic Mail Acceptable Use Standard(4).png|Electronic Mail Acceptable Use Standard page five of nine.
Image:Electronic Mail Acceptable Use Standard(5).png|Electronic Mail Acceptable Use Standard page six of nine.
Image:Electronic Mail Acceptable Use Standard(6).png|Electronic Mail Acceptable Use Standard page seven of nine.
Image:Electronic Mail Acceptable Use Standard(7).png|Electronic Mail Acceptable Use Standard page eight of nine.
Image:Electronic Mail Acceptable Use Standard(8).png|Electronic Mail Acceptable Use Standard page nine of nine.
</gallery>


=='''Sample Electronic Mail Acceptable Use Standard'''==
<br>
The '''<Your Company Name>''' (the "Company") [[Sample Acceptable Use Policy:|'''Sample Acceptable Use Policy''']] defines objectives for establishing specific standards on the appropriate business use of information assets.<br>
<br>
This Electronic Mail Acceptable Use Standard builds on the objectives established in the [[Sample Acceptable Use Policy:|'''Sample Acceptable Use Policy''']]
, and provides specific instructions and requirements on the proper and appropriate business use of Electronic Mail Resources.<br>
<br>
=='''I. Scope'''==
<br>
All employees, contractors, part-time and temporary workers, and those employed by others to perform work on Company premises, or who have been granted access to and use of Company Electronic Mail Resources, are covered by this standard and must comply with associated guidelines and procedures.<br>
<br>
'''Information assets''' are defined in the [[Sample Asset Identification and Classification Policy:|'''Sample Asset Identification and Classification Policy''']].<br>
<br>
'''Electronic Mail Resources''' refer to the Company systems, networks, equipment, software, and processes that provide access to and/or use of the electronic mail, including accessing, downloading, transmitting, or storing data and information, as well as the operation of software products and tools.<br>
<br>
'''Objectionable''' refers to anything that could be reasonably considered to be obscene, indecent, harassing, offensive, or any other uses that would reflect adversely on the Company, including but not limited to comments or images that would offend, harass, or threaten someone on the basis of his or her race, color, religion, national origin, gender, sexual preference, or political beliefs.<br>
<br>
'''Users''' refer to all individuals, groups, or organizations authorized by the Company to access and use Company Electronic Mail Resources.<br>
<br>
=='''II. Requirements'''==
<br>
:'''A. Business Use'''
<br>
::1. Company Electronic Mail Resources are provided primarily for official and authorized Company business use and purposes in support of the following business goals and objectives:<br>
<br>
::*<List, reference, or describe business goals><br>
<br>
::2. Limited personal use of Company Electronic Mail Resources is acceptable as long as it does not interfere with normal business operations, conflict with business interests, or has an adverse impact on the reputation of the Company.<br>
<br>
::3. The use of Company Electronic Mail Resources shall be in accordance with applicable laws and regulations.<br>
<br>
::4. Users shall be accountable for all Electronic Mail activity associated with their accounts.<br>
<br>
::5. All electronic mail transmissions outside the Company must have the following disclaimer attached:<br>
<br>
::"This E-mail and any of its attachments may contain <Company> proprietary information, which is privileged, confidential, or subject to copyright belonging to the <Company>. This E-mail is intended solely for the use of the individual or entity to which it is addressed. If you are not the intended recipient of this E-mail, you are hereby notified that any dissemination, distribution, copying, or action taken in relation to the contents of and attachments to this E-mail is strictly prohibited and may be unlawful. If you have received this E-mail in error, please notify the sender immediately and permanently delete the original and any copy of this E-mail and any printout."<br>
<br>
:'''B. Improper Use'''
<br>
::1. Any use of Company Electronic Mail Resources must not be illegal, must not constitute or be perceived as a conflict of Company interest, must not violate Company policies, and must not interfere with normal business activities and operations.<br>
<br>
::2. Users shall not violate any laws or regulations through the use of Company Electronic Mail Resources.<br>
<br>
::3. Company Electronic Mail Resources shall not be used to forward chain letters, virus warnings, and hoaxes or support other such "re-mailing" activities.<br>
<br>
::4. Company Electronic Mail Resources shall not be used to download, transmit, or store objectionable material, images, or content.<br>
<br>
::5. Company Electronic Mail Resources shall not be used to conduct personal or non-Company solicitations.<br>
<br>
::6. Users must not allow others to access Electronic Mail Resources by using their accounts.<br>
<br>
:'''C. Electronic Mail Software'''
<br>
::1. Only Company-approved versions and configurations of electronic mail software may be used. The following electronic mail software is authorized for use:<br>
<br>
::*<Insert list of software><br>
<br>
::2. Users must not adjust the electronic mail software security settings to be less restrictive than the Company-approved configuration.<br>
<br>
::3. Users shall not use software or features that automatically forward electronic mail messages.<br>
<br>
::4. Users shall not use software or features (such as an anonymous mail sender) that obscures or masks the identity of the message sender.<br>
<br>
:'''D. Downloaded Materials'''
<br>
::1. Company Electronic Mail Resources shall not be used to send, receive or store any commercial software, shareware, or freeware without the Company's prior written authorization.<br>
<br>
::2. The content and attachments of electronic mail messages must be reviewed for malicious code and viruses in accordance with the [[Sample Asset Protection Policy:|'''Sample Asset Protection Policy''']] and the [[Sample Anti-Virus Standard:|'''Sample Anti-Virus Standard''']].<br>
<br>
::3. For security and performance purposes, electronic mail attachments must be less than <Enter size limit>.<br>
<br>
:'''E. Right to Monitor'''
<br>
::1. All Electronic Mail Resources and all messages created, received, processed, transmitted, and/or stored on Company Electronic Mail Resources are Company information assets and property.<br>
<br>
::2. The Company reserves the right to monitor and review all activities and messages using Company Electronic Mail Resources at any time by authorized Company personnel.<br>
<br>
::3. The Company reserves the right to disclose the nature and content of any User's messages and activities involving Company Electronic Mail Resources to law enforcement officials or other third parties without any prior notice to the User.<br>
<br>
:'''F. Privacy Expectations'''
<br>
::1. Users should have no expectations of privacy when using Company Electronic Mail Resources.<br>
<br>
:'''G. Storage Capacity'''
<br>
::1. Users shall delete unnecessary electronic mail messages to avoid unnecessary accumulation of storage on the Company electronic mail servers.<br>
<br>
::2. Electronic mail messages containing business critical information should be stored on production servers to ensure proper data backup.<br>
<br>
::3. The approved record retention period for electronic mail messages is <Insert number> days.<br>
<br>
:'''H. Misuse Reporting'''
<br>
::1. Actual or suspected misuse of Company Electronic Mail Resources should be reported in accordance with the Misuse Reporting Standard.<br>
<br>
::2. Upon the receipt or continued receipt of objectionable electronic mail, Users should contact <Specify Contact> in accordance with the [[Sample Misuse Reporting Standard:|'''Sample Misuse Reporting Standard''']].<br>
<br>


=='''III. Responsibilities'''==
[[file:Electronic Mail Acceptable Use Standard.png]]
<br>
[[file:Electronic Mail Acceptable Use Standard(1).png]]
The Chief Information Security Officer (CISO) approves the Electronic Mail Acceptable Use Standard. The CISO also is responsible for ensuring the development, implementation, and maintenance of the Electronic Mail Acceptable Use Standard.<br>
[[file:Electronic Mail Acceptable Use Standard(2).png]]
<br>
[[file:Electronic Mail Acceptable Use Standard(3).png]]
Company management is responsible for ensuring that the Electronic Mail Acceptable Use Standard is properly communicated and understood within its respective organizational units. Company management also is responsible for defining, approving, and implementing processes and procedures in its organizational units, and ensuring their consistency with the Electronic Mail Acceptable Use Standard.<br>
[[file:Electronic Mail Acceptable Use Standard(4).png]]
<br>
[[file:Electronic Mail Acceptable Use Standard(5).png]]
Users are responsible for familiarizing themselves and complying with the Electronic Mail Acceptable Use Standard and the associated guidelines provided by Company management. Users also are responsible for reporting misuse of Company Electronic Mail Resources to management, and cooperating with official Company security investigations relating to misuse of such resources.<br>
[[file:Electronic Mail Acceptable Use Standard(6).png]]
<br>
[[file:Electronic Mail Acceptable Use Standard(7).png]]
=='''IV. Enforcement and Exception Handling'''==
[[file:Electronic Mail Acceptable Use Standard(8).png]]
<br>
Failure to comply with the Electronic Mail Acceptable Use Standard and associated guidelines and procedures can result in disciplinary actions up to and including termination of employment for employees or termination of contracts for contractors, partners, consultants, and other entities. Legal actions also may be taken for violations of applicable regulations and laws.<br>
<br>
Requests for exceptions to the Electronic Mail Acceptable Use Standard should be submitted to <Insert Title> in accordance with the Information Security Standards Exception Procedure. Prior to official management approval of any exception request, the individuals, groups, or organizations identified in the scope of this standard will continue to observe the Electronic Mail Acceptable Use Standard.<br>
<br>
=='''V. Review and Revision'''==
<br>
The Electronic Mail Acceptable Use Standard will be reviewed and revised in accordance with the [[Sample Information Security Program Charter:|'''Sample Information Security Program Charter''']].<br>
<br>
Approved: _______________________________________________________<br>
<br>
::Signature<br>
<br>
::<Insert Name><br>
<br>
::Chief Information Security Officer<br>
<br>

Revision as of 19:28, 16 January 2014

Sample Electronic Mail Acceptable Use Standard

The Electronic Mail Acceptable Use Standard builds on the objectives established in the Acceptable Use Standard, and provides specific instructions and requirements on the proper and appropriate business use of Electronic Mail Resources.

Objectives

  1. Business Use
    1. Company Electronic Mail Resources are provided primarily for official and authorized Company business use and purposes in support of the following business goals and objectives: Support of the Company mission.
    2. Limited personal use of Company Electronic Mail Resources is acceptable as long as it does not interfere with normal business operations, conflict with business interests, or has an adverse impact on the reputation of the Company.
    3. The use of Company Electronic Mail Resources shall be in accordance with applicable laws and regulations.
    4. Users shall be accountable for all Electronic Mail activity associated with their accounts.
    5. All electronic mail transmissions outside the Company must have the following disclaimer attached: "This e-mail message (and any attachment) is intended for the use of the individual or entity to which it is addressed. This message contains information from Lazarus Alliance, LLC. that may be privileged, confidential, or exempt from disclosure under applicable law. If you are not the intended recipient or authorized to receive this for the intended recipient, any use, dissemination, distribution, retention, archiving, or copying of this communication is strictly prohibited. If you have received this e-mail in error, please notify the sender immediately by reply e-mail, delete this message, and delete the material from all computers."
  2. Improper Use
    1. Any use of Company Electronic Mail Resources must not be illegal, must not constitute or be perceived as a conflict of Company interest, must not violate Company policies, and must not interfere with normal business activities and operations.
    2. Users shall not violate any laws or regulations through the use of Company Electronic Mail Resources.
    3. Company Electronic Mail Resources shall not be used to forward chain letters, virus warnings, and hoaxes or support other such "re-mailing" activities.
    4. Company Electronic Mail Resources shall not be used to download, transmit, or store objectionable material, images, or content.
    5. Company Electronic Mail Resources shall not be used to conduct personal or non-Company solicitations.
    6. Users must not allow others to access Electronic Mail Resources by using their accounts.
    7. The use of third party Electronic Mail Resources such as personal Electronic Mail accounts outside of Company provided Electronic Mail Resources in the transmission of Company information is prohibited. Accessing third party personal Electronic Mail Resources is only permitted while an employee is off duty and while an employee is not using Company resources. The usage of Company owned resources is for business purposes only.
  3. Electronic Mail Software
    1. Only Company approved versions and configurations of electronic mail software listed within the Company System of Record documentation may be used.
    2. Users must not adjust the electronic mail software security settings to be less restrictive than the Company approved configuration.
    3. Users shall not use software or features that automatically forward electronic mail messages.
    4. Users shall not use software or features (such as an anonymous mail sender) that obscures or masks the identity of the message sender.
  4. Downloaded Materials
    1. Company Electronic Mail Resources shall not be used to send, receive or store any commercial software, shareware, or freeware without the Company's prior written authorization.
    2. The content and attachments of electronic mail messages must be reviewed for malicious code and viruses in accordance with the Asset Protection Standard and the Anti-Virus Standard.
    3. For security and performance purposes, electronic mail attachments must be less than [35 MB].
  5. Right to Monitor
    1. All Electronic Mail Resources and all messages created, received, processed, transmitted, and/or stored on Company Electronic Mail Resources are Company information assets and property.
    2. The Company reserves the right to monitor and review all activities and messages using Company Electronic Mail Resources at any time by authorized Company personnel.
    3. The Company reserves the right to disclose the nature and content of any User's messages and activities involving Company Electronic Mail Resources to law enforcement officials or other third parties without any prior notice to the User.
  6. Privacy Expectations
    1. Users should have no expectations of privacy when using Company Electronic Mail Resources.
  7. Storage Capacity
    1. Users shall delete unnecessary electronic mail message to avoid unnecessary accumulation of storage on the Company electronic mail servers.
    2. Electronic mail messages containing business critical information should be stored on production servers to ensure proper data backup.
    3. The approved record retention period for electronic mail messages is governed by the Records Retention Schedule.
  8. Misuse Reporting
    1. Actual or suspected misuse of Company Electronic Mail Resources should be reported in accordance with the Misuse Reporting Standard.
    2. Upon the receipt or continued receipt of objectionable electronic mail, Users should contact Information Security in accordance with the Misuse Reporting Standard.


Document Examples

Use these samples as a guide for your policy development. Fully customizable versions are available from The Policy Machine.