Skip to content

Network Security Policy And Procedure

Network Security Policy and procedure

Version history

Version Number Date Description Created By Approved By
0.1 23/Apr/2024 Initial Copy [Name] [Name]
0.2 18/Jun/2024 Approved [Name] [Name] [Name]
0.3 28/Aug/2026 Knowledge kernel, AI/agents, control alignment Knowledge steward [Name]

Purpose

This document provides details of the Policies being followed at the Company to ensure application of good practices to manage the company’s networks.

Scope

This policy covers security measures for firewalls, proxy, routers, switches, and wireless networks. The IT team shall be responsible for maintaining this policy and taking note of any deviations to the policy.

Objectives

  • Network security aims to protect network resources from unauthorized access and use.

  • It includes access control to security devices like firewall and routers, controlling remote access, logging network activity for any violations and the location of computer assets, to name a few. The objective of this document is to secure network resources at tecciance.

Roles and Responsibilities

The primary ownership of implementing this Policy is with IT. The IT Team shall implement this Policy under the guidance of the Leadership Team and in coordination with Department Heads.

Policy

  • Networks shall be designed in conformance with sound security practices. The following points shall be observed while designing networks:

  • The network design shall be supported by formal documentation of the network details and user service requirements that will be addressed throughout the network.

  • Adequate redundancy of critical network components shall be considered to ensure high availability, as necessary.

  • Coherent technical standards shall be incorporated while using consistent naming conventions and complying with applicable statutory and regulatory requirements.

  • Distinct sub-networks (LAN/VLAN) protected by rule-based traffic filtering mechanism using a firewall or other technology shall be established for ensuring appropriate segregation.

  • Single points of failures and the number of entry points into the network should be avoided as much as possible.

  • When choosing a network protocol, secure protocols shall be preferred over unsecured protocols (e.g., HTTPS over HTTP, SFTP over FTP, SSH over Telnet, etc.).

  • Appropriate authorization for enabling or disabling network services shall be followed. Such authorization shall consider security risks associated with the network service in context.

  • Any unused network service shall be removed or disabled.

  • Access to the network and network services shall be allocated, changed, or revoked in accordance with the Logical Access Control Policy.

  • External parties shall not be allowed to access the company’s LAN or WLAN. Internal parties shall be allowed to access the LAN/WLAN from a remote location only after formal approval and shall be required to use company-approved secure remote access mechanisms.

  • Vendor-supplied default credentials (administrative or otherwise) to the network devices shall be changed before making such network devices operational.

  • Guest accounts shall be disabled from all the network systems that come with built-in guest accounts by default.

  • Network device identification banners shall be either disabled or changed to avoid any identification attempt by malicious users.

  • Standard configurations for network devices shall be maintained and used. The workspace manager will conduct periodic reviews of network configurations against the configuration standards.

  • Access to diagnostic ports shall be controlled.

  • A business continuity plan together with a disaster recovery plan shall be maintained and evaluated annually for the network in accordance with the Business Continuity Policy.

Procedure

Network device acquisition and deployment:

  • The IT department will maintain sole responsibility for the creation and implementation of all networking within tecciance. Any change to any network architecture or configuration must be documented, approved by, and made by the IT department.

  • No user or department within tecciance may attach any device or system not owned and controlled by tecciance to any network access port.

  • Access to network devices and network services shall be based on the job function and role. Additional services more than what is required for the job function shall be allowed only after getting approval from appropriate personnel.

  • Network and network services access shall be periodically reviewed to ensure that unauthorized network services are not used, or authorized network services are not accessed by unauthorized personnel.

  • IP address (Zone based) restrictions shall be implemented to restrict users’ access from authorized workstations in case of personal devices used that also restrict access.

  • Access to tecciance’s network and network resources must be provided on need to have basis and appropriate level of authorization must be obtained from authorized personnel before the access is configured.

  • Access to local system control utilities (e.g., Batch Files, Unix Scripts etc.) shall be controlled. Access to these utilities shall be limited to authorized personnel only.

  • Modems shall not be used on machines when connected to the network.

  • For non-public information, all equipment that provides access to the network shall positively identify the user through a login sequence for providing access.

  • Remote Control Software shall be used over the network only by authorized personnel.

  • All default passwords used on network devices for administrative or otherwise authorization shall be changed.

  • All the administrative accounts or privilege user accounts shall be reconciled and reviewed periodically.

  • An access control rule list shall be maintained and implemented on all network equipment. No changes shall be made to existing rules without prior approval.

  • Any changes made or implemented shall follow change management procedure.

  • Any user on the LAN found to have a modem /mobile tethering connected to his/ her PC shall be held responsible for any breach of security.

  • Network connection controls shall be implemented on critical business applications to restrict connections from outside the organization’s boundaries.

  • There shall be proper authorization procedure for determining who is allowed to access which networks and networked services and proper protection shall be ensured for any such connectivity.

  • Automatic equipment identification shall be considered to authenticate connections from specific locations and equipment.

  • Access to diagnostic ports within tecciance’s shall be securely controlled.

  • It is the responsibility of Core team member from IT Department along with Head-IT to determine the following prior to connection:

  • Permitted network and network services.

  • Elements of the network that may be accessed.

  • The authorization procedure for gaining access.

  • Authorized users allowed to access these networks and network services.

  • Controls to protect the access to the network and services.

  • For shared networks especially those extending across the Organization’s boundaries, the capability of users to connect to the network shall be restricted.

Reference

  • Asset Management Policy

  • Logical Access Control Policy

  • Incident Response Policy

  • Business Continuity Policy

  • Configuration Standards

Definition

  • IST: Information Security Team

  • Network: A set of two or more computing devices connected to each other for exchanging electronic information.

  • Note: A network includes LAN, WAN, WLAN, etc.

  • LAN: Local Area Network

  • VLAN: Virtual Local Area Network

  • WAN: Wide Area Network

  • WLAN: Wireless Local Area Network

  • IDS: Intrusion Detection System

  • IPS: Intrusion Prevention System

  • LT: Leadership Team

Artificial intelligence, software agents, and organizational knowledge

This section is added in version 0.3 so the policy applies equally to employees and to software agents, and so reusable knowledge stays provenanced.

Software agents, bots, service accounts, CI jobs, and coding assistants are identities. They are in scope of this policy wherever people are.

Every retrieve or use of organizational knowledge or classified data requires a verified identity, a stated purpose, and a classification ceiling. Missing purpose is deny.

AI may extract, draft, rank, or propose. AI shall not approve access, classify or reclassify information, set reuse rights, waive a control, merge to a protected branch, or treat search ranking as truth.

Approved reusable knowledge is a governed claim with source, owner, lifecycle, applicability, and limitations. Raw chat, tickets, and scanner output are not approved knowledge.

Embeddings, summaries, caches, and compiled agent skills are derivatives. Withdrawal, reclassification, or destruction of a source shall propagate to derivatives.

Secrets, credentials, production data dumps, and Restricted (including client/PHI) material shall not be pasted into public generative-AI services or stored in vector indexes unless an authorized path and agreement exist.

HIPAA-regulated PHI is out of default scope. Enable the HIPAA pack and a business-associate path before any PHI is processed by agents or knowledge indexes.

Change to a must procedure (including knowledge used by agents) is a change under the Change / Release procedure and SOC 2 CC8.1. Agents cannot approve that change.

Outbound access from CI and agent runners to public model APIs shall be allowlisted and logged.