| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
|
5.4.1.9 HR (Human Resources) Policy To the typical IT person, the human resource department does not make a great deal of sense. In brief, the Human Resource department has a wide range of duties, and one area includes legal issues. There are so many governing bodies that must be complied with. To get an idea of the complexity go to the footnote436 and while at the web site, enter the word security in the search box and look at how many hundreds of different papers return from the system library. The HR department creates the handbook that each employee gets with the policies defined. They must also insure that paperwork is in place acknowledging that the employee has read the book, and understands the provisions. It may be part of your duties to help Human Resources understand the different technical issues. For example, Senior Management is encouraging the use of Instant Messaging. In this example a balancing act may need to be spelled out with you installing security software437 to protect against worm or viruses while the HR department includes polices instructing staff not to reveal sensitive information via Instant Messaging because data is sent in clear text (human readable form).
__________________ 436. http://www.hrnext.com/tools/subs.cfm?tools_id=5 437. http://www.instantmessagingplanet.com/security/article/0,,10818_1379731,00.html
Home - Table Of Contents - Contact Us CertiGuide for Security+ (http://www.CertiGuide.com/secplus/) on CertiGuide.com Version 1.0 - Version Date: November 15, 2004 Adapted with permission from a work created by Tcat Houser et al. CertiGuide.com Version © Copyright 2004 Charles M. Kozierok. All Rights Reserved. Not responsible for any loss resulting from the use of this site. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||