Skip to main content

Access Management Policy

Version:1
Approval date:20 November 2019
 
Approved by:  CEO
Review date:20 November 2023
Responsible Officer:Director, Customer and Corporate Services
Authorising Officer:CEO

Introduction

Purpose

The purpose of this policy is to enable the City to:

  • define standards for connecting to The City’s network from any device;
  • minimize the potential exposure to The City from damages, which may result from unauthorized use of City's resources. Damages include the loss of sensitive or confidential data, intellectual property, damage to public image, damage to critical City internal systems, et; and.
  • protect all information networks, regardless of connectivity, whether City-owned, leased, or contractor operated, from unauthorized access.

Scope

This policy applies to all Employees with a city-owned or personally owned computer or workstation used to connect to the City network. This policy applies to remote access connections from any device. This policy also applies to software programs that access or administer access to information resources.

Revoked Polices

This policy revokes the following policy and procedures:

  • Data Access Management Policy
  • Broadband Access for Home Use Management Policy
  • Email and Internet Access Management Policy
  • Information Technology Access Control Procedure.

Definitions

This section defines the key terms used in this policy.

City - The City of Greater Geelong organisation, led by the CEO.

Council - The City of Greater Geelong Council comprised of elected councillors and led by the Mayor.

ELT - The Executive Leadership Team of the City, as constituted from time to time.

Employee - An officer, employee, contractor, consultant, labour hire employee and any other worker at the City.

Access - Any connection to City’s corporate network through a City controlled network, device, or medium.

Access controls - Methods used to prevent unauthorized access to City’s corporate network, such as passwords, user IDs, digital certificates, etc.

Two-factor authentication is a form of authentication that requires the Employee to provide two things in order to access the network (for example, a password and a code sent to a mobile device).

Policy

Passwords

  • Employees must comply with having their identity verified with a user ID and a secret password.
  • Always use different passwords for various City systems access whenever possible.
  • Inactive logon credentials are suspended after 60 days. Removal will occur at the discretion of City management and IT.
  • IT will monitor and review accounts against HR add/move/deletes.
  • IT will require managers to revalidate their Employee’s system access on an annual basis.
  • To prevent password guessing attacks against Employees, the number of consecutive attempts to enter an incorrect password must be strictly limited. Following three consecutive failed attempts, the involved user ID will be suspended until reset by the IT service desk.
  • Whenever the security of system passwords has been compromised, or even if there is a convincing reason to believe that it has been compromised, the Employee should immediately:
    1. Notify IT;
    2. Reassign all relevant passwords; and
    3. Force every password on the involved system to be changed at the time of next login.
  • The display and printing of passwords must be masked, suppressed, or otherwise obscured such that unauthorized parties will not be able to observe or subsequently recover the passwords.
  • Employees must create passwords that have:
    1. A minimum of ten characters in length and
    2. Upper and lowercase letters, non-sequential numbers, and special characters.
  • Employees are required to change network passwords at least every 120 days and will be prompted to do so either prior to or upon password expiry.
  • The initial passwords issued by a security administrator must be valid only for the first login. At that time, the Employee must be forced to choose another password before any work can be initiated.

Remote Access

Remote access to corporate applications and systems will be available on city issued mobile devices (tablets, laptops).  For any non-city issued devices (such as person computers or public computers) Two-factor Authentication may be required to provide an extra layer of security, however not all applications will be available as the IT department cannot guarantee the security controls in place on these devices.

  • Remote access to City resources must be through the City’s secure virtual private network (VPN) application.

The City must ensure that:

  • Firewall filters must be configured to deny connections unless otherwise approved by the IT department.
  • Firewall administration is limited to authorized employee appointed by IT. Changes to the firewall require approval by IT Management.
  • To the extent feasible, connections between City networks and the Internet must be brokered by an application proxy.
  • The City's internal network-addressing scheme must not be visible to external connections.
  • To eliminate many of the vulnerabilities inherent with TCP/IP, routers, switches and firewalls, the City must not accept external connections that appear to be coming from internal addresses. This reduces the risk of a successful spoofing attack.

Third-Party Access

Contractor access

  • Contractors are expected to ensure that they only access City information which is required for them to perform their task.
  • Encryption or password protection must be used when available to protect City information. If unable to encrypt, contractors should contact the IT service desk for further assistance.
  • Each contractor must safeguard his or her password, user ID, and badge and protect them from unauthorized use.

Vendor access

  • Vendor access must be uniquely identifiable (e.g. a separate User ID) and password management must comply with the City's password standard practice.
  • The Vendor must log the Vendor’s major work activities and make the logs available to the City on request. Logs must include, but are not limited to, events such as personnel changes, password changes, project milestones, deliverables, and arrival and departure times.
  • On termination of contract or at the request of City, the vendor must surrender all City identification badges, access cards, equipment and supplies immediately.
  • Equipment and/or supplies that the City agrees the vendor may retain, must be documented by authorised City management.
  • Vendors must comply with all state and City auditing requirements, including the auditing of the vendor's work.
  • All software used by the vendor in providing service to the City must be properly licensed and secure (free from malware).

City Equipment at Third-Party Sites

  • In many cases it may be necessary to have City-owned and maintained equipment at a third-party site.
  • Access to network devices such as routers and switches are secured via password and will only be provided to IT approved personnel.
  • All City-owned equipment located at third-party sites must be used only for City business purposes.
  • Any misuse of access or tampering with City-provided hardware or software may result in the City exercising its rights to termination of the agreement with the third party.

Internet and Network Monitoring

  • To protect the integrity of the City network and the data maintained on it, the IT department shall monitor Internet usage and network traffic on all computers and devices connected to the corporate network, through an automated monitoring system.
  • For all traffic the monitoring system must record the source IP Address, the date, the time, the protocol, and the destination site or server. Where possible, the system should record the user ID of the person or account initiating the traffic.
  • Information recorded by the automated monitoring systems can identify an individual employee and show their browsing history, for example, a website or document that an employee has been viewing and the time spent browsing. Because of this, employees must not assume privacy in their use of the corporate systems, even when accessing the systems in their personal time i.e. out of paid working hours.
  • If the City requests, an Employee must allow the City to inspect or remove any information stored on the City-provisioned device or attached peripherals and must assist the City to do so.
  • Incident response team members may access all reports and data if necessary to respond to a security incident.
  • Internet use reports that identify specific employees, sites, teams, or devices will only be made available to Employees outside the incident response team upon written or e-mail request to the IT department from a Human Resources representative.

Internet Filtering System

The IT department shall block access to Internet websites and protocols that are deemed inappropriate for City's corporate environment. The following protocols and categories of websites should be blocked:

  • Adult/Sexually Explicit Material
  • Advertisements and Pop-Ups
  • Gambling
  • Hacking
  • Illegal Drugs
  • Intimate Apparel and Swimwear
  • Peer-to-Peer (P2P) File Sharing
  • Personals and Dating
  • SPAM, Phishing, and Fraud
  • Spyware
  • Tasteless and offensive content
  • Violence, Intolerance, and Hate
  • Web Based E-mail
  • Chat and Instant Messaging
  • Social Network Services

Internet Filtering Exceptions

If a site is improperly categorised, Employees may request the site be unblocked by submitting a ticket to the IT help desk. IT will review the request and unblock the site if it is improperly categorised.

Implementation of this Policy

Monitoring and reporting

The Digital Information Technology team will verify compliance to this policy through various methods, including but not limited to, business tool reports, internal and external audits, and feedback to the policy owner.

Exceptions

Any exception to the policy must be approved in writing by the Chief Information Officer in advance.

Non-Compliance

An Employee found to have violated this policy may be subject to disciplinary action, including termination of employment.

Advice and assistance

The Responsible Officer for this policy manages the provision of advice to the organisation regarding this policy.

Records

The City must retain records associated with this policy and its implementation for at least the period shown below.

RecordRetention / Disposal AuthorityRetention PeriodLocation
Necessary registers and reportsDirector, Customer and Corporate services7 yearsRelevant Rex binder
    
    
    

Review

The City should review and, if necessary, amend this policy within four years of the approval date.

References

  • Management Policy - DIT – Acceptable Use
  • Management Policy - DIT – Records and Information Management
Page last updated: