Work From Home Information Security Requirements¶
WORK FROM HOME INFRMATION SECURITY REQUIREMENTS
Version history¶
| Version Number | Date | Description | Created By | Approved By |
|---|---|---|---|---|
| 0.1 | 23/Jan/2024 | Initial Copy | [Name] [Name] | |
| 0.2 | 18/Jun/2024 | Approved | [Name] [Name] | [Name] |
| 0.3 | 28/Aug/2026 | Knowledge kernel, AI/agents, control alignment | Knowledge steward | [Name] |
Objectives¶
tecciance and team members working remotely have a responsibility to ensure that area in which they are working, equipment used to perform their job duties follow the existing process/procedures. Also, while dealing with tecciance and client confidential and personal data, reasonable steps must be taken to ensure data is treated with utmost protection, confidentiality, and security measures.
General Security¶
-
Ensure that all access to tecciance databases is provided through a secure ID and if there are specific issues related to access or IT security contact tecciance’s IT team.
-
No unauthorized personnel must be permitted to access to tecciance’s computer or any client documents, or confidential data.
-
Access to computer’s desktop should at least be password protected, and the password should be a strong one as defined in the Password Requirements of tecciance.
-
Work-related emails should not be sent from private email addresses and vice versa.
-
Ensure that work devices are shut down or locked-including mobile phones when you are away from the devices.
-
Ensure files are stored on cloud or server storage offered by the organization and avoid storing them locally ensuring safety and availability of documents.
-
Ensure all the Antivirus and Patches are updated periodically on the business/work machines.
-
Ensure that private areas/headsets are utilized for business related calls.
Secure connections¶
-
Ensure home wi-fi is secured with a strong password and the default password is changed.
-
Ensure network encryption such as WPA2 (strongest) is enabled in home Wi-Fi/router devices.
-
Ensure you are running the latest version of your firmware for the home Wi-Fi setup.
Artificial intelligence, software agents, and organizational knowledge¶
This section is added in version 0.3 so the policy applies equally to employees and to software agents, and so reusable knowledge stays provenanced.
Software agents, bots, service accounts, CI jobs, and coding assistants are identities. They are in scope of this policy wherever people are.
Every retrieve or use of organizational knowledge or classified data requires a verified identity, a stated purpose, and a classification ceiling. Missing purpose is deny.
AI may extract, draft, rank, or propose. AI shall not approve access, classify or reclassify information, set reuse rights, waive a control, merge to a protected branch, or treat search ranking as truth.
Approved reusable knowledge is a governed claim with source, owner, lifecycle, applicability, and limitations. Raw chat, tickets, and scanner output are not approved knowledge.
Embeddings, summaries, caches, and compiled agent skills are derivatives. Withdrawal, reclassification, or destruction of a source shall propagate to derivatives.
Secrets, credentials, production data dumps, and Restricted (including client/PHI) material shall not be pasted into public generative-AI services or stored in vector indexes unless an authorized path and agreement exist.
HIPAA-regulated PHI is out of default scope. Enable the HIPAA pack and a business-associate path before any PHI is processed by agents or knowledge indexes.
Change to a must procedure (including knowledge used by agents) is a change under the Change / Release procedure and SOC 2 CC8.1. Agents cannot approve that change.
Home working does not authorize use of personal AI accounts for organization or client data.