Entity provides guidance on decomissioning of information assets that contain classified information in the Media disposal policy.
Entity ensures that endpoints with access to critical servers or data are configured to auto-screen-lock after 15 minutes of inactivity
Entity ensures that security patches to the operating systems are applied to endpoints with access to critical servers or data in a timely manner
Where applicable, Entity ensures that endpoints with access to critical servers or data must be encrypted to protect from unauthorised access
Where applicable, Entity ensures that endpoints with access to critical servers or data must be protected by malware-protection software
Entity’s Senior Management or the Information Security Officer periodically reviews and ensures that administrative access to the critical systems is restricted to only those individuals who require such access to perform their job functions