The Service
Information Services Policies...
Please note that as this policy is periodically reviewed and updated, if you print it from the website, its accuracy cannot be guaranteed for more than a 24 hour period following printing.
The objective of this Network Services Policy is to determine the controls to be applied to the ICT Network Information and Communications Technology.
Information assets that use networked services shall be transmitted in a controlled manner such that they do not jeopardize the reputation of HFRS.
The IS Department shall ensure that controls are identified, designed, implemented and maintained to protect information assets that use HFRS network services.
The IS Department shall be responsible for ensuring that employees are aware of the correct controls to adopt when using HFRS network services.
HFRS has installed a wireless network that shall be used by authorised HFRS employees.
Access to network services shall be restricted to authorised employees and shall be protected by appropriate physical and logical authentication and authorisation controls.
Employees shall not attempt to access network services unless permissions have been explicitly granted to them.
Internal and external networks shall be managed by the IS Department to ensure the protection of information transmitted across the networks and to protect the supporting infrastructure.
The IS Department shall perform risk assessments on a regular basis and monitor network services to confirm that the implemented controls remain fit for purpose and to identify controls that require improvement.
Such controls shall include the documentation of systems and procedures, segregation of duties, change management, and maintenance of separate test and production environments. Network failures shall be minimised through appropriate planning and acceptance processes.
The IS Department shall implement and maintain network boundary controls to prevent and detect unauthorised intrusion by outsiders and malicious software.
The IS Department shall be responsible for the voice network and shall ensure that controls are applied that are consistent with the level of security required. Please refer to the Voice User Policy.