Sensitive Information Policy
Includes HIPAA Audit Program Guide and a PCI Audit
Program
This
policy is easily modified and defines how to treat Credit Card,
Social Security, Employee, and Customer Data. The template is
29
pages in length and complies with Sarbanes Oxley Section 404,
ISO 27000 (17799), and HIPAA. The PCI Audit Program that is
included is an additional 50 plus pages in length.
This policy applies to the entire enterprise, its vendors, its
suppliers (including outsourcers) and co-location providers and
facilities regardless of the methods used to store and retrieve
sensitive information (e.g. online processing, outsourced to a third
party, Internet, Intranet or swipe terminals).
The HIPAA Audit Program Guide provides you with a checklist of
the must be implemented items which HIPAA mandates.
You can
download the Table of Contents and some sample pages by clicking on
the link below.
Internet,
e-Mail,
Mobile Device,
Electronic Communications, and
Record Retention
Policy
This policy is
is compliant with all recent legislation (SOX, HIPAA, Patriot Act,
and Sensitive information), and
covers:
-
Appropriate Use of Equipment
-
Mobile Devices
-
Internet Access
-
Electronic Mail
-
Retention of Email on Personal
Systems
-
E-mail and Business Records
Retention
-
Copyrighted Materials
-
Banned Activities
-
Ownership of Information
-
Security
-
Sarbanes-Oxley
-
Abuse
Included are these ready to
use forms:
-
Internet & Electronic
Communication Employee Acknowledgement
-
E-Mail - Employee
Acknowledgement
-
Internet Use Approval Form
-
Internet Access Request Form
-
Security Access Application Form
Travel and Off-Site Meeting Policy -
Protection of data and software is often is complicated by the fact
that it can be accessed from remote locations. As individuals travel
and attend off-site meetings with other employees,
contractors, suppliers and customers data and software can be
compromised. This policy is four page in length and covers:
Outsourcing Policy - This
policy is seven page in length and covers:
Note: Look at the
Practical Guide for Outsourcing
over 110 page document for a more extensive process for
outsourcing
|