IT policies and procedures are designed to help protect organizations, their employees, customers, data, and technology resources. Every organization should maintain written acceptable-use policies and cybersecurity best practices and incorporate them into employee handbooks, onboarding materials, and ongoing security awareness training. Falcon IT Services provides its clients with bespoke Employee Cybersecurity and Acceptable Use Policy documents for inclusion into existing HR on-boarding documentation.
Depending on your organization’s industry, size, operations, and the types of data it handles, additional policies and security controls may be necessary. Organizations may also have specific legal, regulatory, contractual, or industry requirements, including those associated with HIPAA, FISMA, GLBA, CTPAT, PCI DSS, and other applicable requirements or security frameworks.
Every organization and its users have unique operational needs. Security policies therefore should not be treated as absolute in every circumstance. Organizations should establish a formal process for reviewing and documenting policy exceptions. The goal should be to balance usability and business requirements with an appropriate level of security based on risk.
Organizations should also establish and communicate disciplinary procedures for employees who violate security policies. Policies are effective only when they are consistently communicated, understood, and enforced.
The following are Falcon IT Services’ recommended cybersecurity policies and best practices. These represent the minimum security practices we expect our managed-service clients and their users to follow when using company systems and resources.
This guide is not intended to replace an organization’s Written Information Security Program (WISP), employee handbook, acceptable-use policy, incident-response plan, or other formal policies required by law, regulation, contract, or industry standards. Clients should maintain a WISP and other appropriate policies that provide the detailed requirements and procedures applicable to their organization.
For additional information, please review our Cybersecurity Best Practices or contact Falcon IT Services for complimentary guidance regarding implementation.
Cybersecurity Policies and Best Practices
Behavior Analysis / Data Loss Prevention / File Auditing
Organizations that store sensitive information such as protected health information (PHI), personally identifiable information (PII), financial information, or intellectual property should implement appropriate data loss prevention (DLP), file auditing, and monitoring controls.
These controls are designed to help identify and prevent unauthorized access, use, copying, or transmission of sensitive information through channels such as email, file uploads, cloud services, removable media, and other transfer methods.
Organizations should define which users are authorized to access sensitive information and which channels may be used to store and transfer it.
Change Requests
When users request changes to access controls, permissions, or other security settings through our help desk, the request must be approved by the company’s designated authorized contact.
Falcon IT Services will not make access-control changes based solely on a user’s request without appropriate authorization. Organizations should designate a knowledgeable and trustworthy person as an authorized point of contact (POC) who can responsibly approve or deny access requests.
Requests for access to another employee’s email, files, folders, or other data should receive appropriate management authorization. Requests involving ownership, executive, or similarly privileged accounts should be approved by the appropriate organizational authority.
Contractor Requirements
Contractors and third parties who have access to an organization’s network resources, systems, facilities, or physical assets should follow the same applicable security requirements as organizational personnel.
Contractors should be required to provide appropriate documentation, including a Scope of Work and Vendor Access Form where applicable. Contractors should be supervised while accessing company facilities or systems unless their access has been specifically authorized and appropriate security controls are in place.
Password Policies
Organizations must maintain strong password practices.
Passwords should be at least 12 characters long and preferably use memorable phrases that are difficult to guess. Passwords should not contain information that can be easily obtained from social media or casual conversation, such as family names, pet names, birth dates, schools attended, or hobbies.
Passwords should not be written on sticky notes or left in locations where unauthorized individuals can access them. When a password must be written down, it should be stored securely in a combination safe or locked drawer, or stored using an organization-approved password manager.
Passwords should not be stored in unauthorized applications or locations. Organizations should establish an approved method for password storage and management.
Passwords must never be shared with other users, including IT or help desk personnel. If a technician resets a password and provides the temporary password to the user, the user should change it immediately.
Do not reuse the same password, or variations of the same password, across multiple services. Work passwords must be unique and should not be reused for personal email, social media, banking, or other personal accounts.
Do not transmit passwords through email, text messages, or other unapproved communication methods.
Each user should have an individual username and password. Users should not share accounts or allow multiple people to access systems using a single set of credentials unless specifically authorized for a legitimate technical or business requirement.
Multifactor Authentication (MFA)
Multifactor authentication should be enabled wherever supported and is required for systems designated by Falcon IT Services or the organization’s security policies.
MFA should be used for email, cloud applications, VPN and remote access, administrative accounts, financial systems, and other systems containing sensitive information whenever supported.
Users must never approve an unexpected MFA request. Suspicious or unexpected MFA prompts should be reported to the help desk or designated security contact.
MFA devices, authentication codes, and recovery codes must not be shared with other users.
Portable Media Policies
Portable media such as USB drives can introduce malware and create a risk of data loss because they can be lost, stolen, or connected to untrusted devices.
The use of removable media should be restricted to legitimate business purposes and may be blocked on managed devices. Contact our help desk for assistance with approved methods of securely transferring files without using portable media.
Data Classification Policies
Organizations should classify data according to its sensitivity and the level of protection it requires. Examples include personally identifiable information (PII), protected health information (PHI), financial information, confidential business information, and intellectual property.
Organizations should define where different classifications of information may be stored, how they may be transferred, and which users are authorized to access them.
Sensitive information should be accessed only by authorized individuals on a need-to-know basis and should be transferred only through approved and appropriately secured channels.
Management & Administration
Administrative access to managed IT infrastructure is restricted to authorized personnel. Falcon IT Services researches, evaluates, and scans unknown programs before installation and obtains software from appropriate and trusted sources.
Users and other personnel should not have local or network administrative privileges unless specifically authorized and required for their job duties.
Users must not install unauthorized software or make unauthorized configuration changes to managed devices. Software installations and changes to managed devices should be requested through the Falcon IT Services help desk.
Users must not uninstall, disable, modify, or otherwise interfere with Falcon IT Services’ endpoint detection and response (EDR) or other managed security software.
Equipment Purchasing Policy
Commercial-grade hardware is designed for demanding business environments and is typically more reliable, durable, supportable, and manageable than consumer-grade equipment.
Clients should consult Falcon IT Services before purchasing computers, servers, networking equipment, firewalls, storage devices, or other technology that will connect to or operate within the organization’s network.
Duty to Not Deliberately Waste Resources
Employees must not deliberately waste computer, network, storage, Internet, printing, or other organizational resources or unfairly monopolize resources to the exclusion of others.
Examples include sending mass mailings or chain letters, excessive non-business Internet usage, unauthorized games or online services, excessive printing, or activities that unnecessarily consume network or computing resources.
Audio, video, and image files can consume significant resources and should not be transferred, copied, or downloaded using business resources unless required for legitimate business purposes.
Help desk support is intended for business-related technology issues. Personal computers, personal email accounts, personal devices, and other non-business technology are outside the normal scope of managed IT support unless specifically covered by the service agreement.
Login Policy
Organizations should display an appropriate legal and security notice before users log in to company-managed computers and systems.
A typical notice may state that the system is privately owned, intended for authorized business use, and subject to monitoring and security controls. Clients should consult their legal counsel regarding the wording appropriate for their organization and jurisdiction.
File Storage & Transfer Policies
Organizations should define approved channels for storing and transferring business information.
Users must not transfer sensitive or confidential information through unauthorized file-sharing services, personal cloud-storage accounts, personal email accounts, or other unapproved channels.
Email Attachment Blocking Policy
Organizations should use appropriate email security controls to block or quarantine file types that commonly contain malicious code, including executable files and other potentially dangerous attachments.
Security controls should be configured based on organizational risk and business requirements.
Personal Email Policy
Personal email accounts should not be used to conduct company business or to store, transmit, or receive company information.
Users should not use personal email as a means of bypassing organizational security controls.
Remote Access
Organizations should prohibit unauthorized remote-access software and connections.
Remote access to organizational resources should use approved, encrypted connections and appropriate authentication controls, including multifactor authentication where supported.
Public-cloud remote-control software should be centrally managed, secured, and monitored. Freeware or user-managed remote-access applications should not be installed on company-managed devices without authorization.
Users with laptops or other devices intended for remote access should connect to the organization’s network regularly to verify that credentials, security controls, updates, and connectivity remain functional.
Cybersecurity Training
All new employees should receive cybersecurity awareness training as part of the onboarding process. Existing employees should receive cybersecurity awareness training at least annually, with additional training provided when appropriate based on organizational risk.
Organizations should provide additional awareness training or simulated phishing exercises when appropriate.
Falcon IT Services provides cybersecurity awareness training and can assist clients with training requirements, attendance tracking, and certificates of completion.
Security awareness training should cover topics including phishing, malware, social engineering, password security, MFA, safe Internet use, data protection, acceptable use, and procedures for reporting suspicious activity.
Smartphone & Mobile Device Policies
Organizations should establish policies governing company-owned and personally owned smartphones, tablets, and other mobile devices used for company business or to access organizational resources.
Where possible, company-owned devices should be used for business purposes. Organizations that permit BYOD should establish appropriate security requirements and controls.
Mobile devices used for business should use appropriate security controls, including screen locks, encryption, supported operating systems, and security updates.
Users should not jailbreak or root devices used to conduct company business or access organizational resources.
Lost or stolen devices must be reported promptly so that appropriate security measures can be taken.
Organizational data should be protected when devices are repaired, transferred, recycled, or disposed of.
Onboarding Policy
New employees should receive the organization’s written acceptable-use and cybersecurity policies as part of the onboarding process.
New employees should complete required cybersecurity awareness training before or shortly after receiving access to organizational systems.
Access should be provisioned according to the employee’s job responsibilities and limited to the resources necessary to perform those duties.
Network Segmentation Policy
Organizations should use network segmentation to separate trusted systems from untrusted or higher-risk devices.
Devices such as NVRs, IP phones, IoT devices, guest Wi-Fi, and similar equipment should be separated from computers, servers, storage, backup systems, and other sensitive resources where appropriate.
Network access controls should be implemented to prevent unauthorized or unmanaged devices from connecting to trusted network segments.
URL Filtering
Organizations should use appropriate web and URL filtering to reduce exposure to malware, phishing, malicious websites, and other security threats.
Access to websites may also be restricted based on organizational productivity, legal, regulatory, or acceptable-use requirements.
High-risk categories and known malicious websites should be blocked based on the organization’s security requirements. Exceptions should require appropriate authorization and documented justification.
UTM / WAF Firewall
Organizations should use appropriately configured firewalls and other gateway security controls to protect their networks.
Where appropriate, security features may include gateway malware filtering, intrusion detection and prevention (IDS/IPS), application filtering, DNS security, web filtering, and geographic filtering.
Firewall configurations should be reviewed periodically and adjusted based on business requirements and security risks.
Software Policies
Users must not install or use unauthorized software.
Software installations and changes to managed devices must be requested through the Falcon IT Services help desk.
Users must not install or use pirated, cracked, or unauthorized software. Key generators, software cracks, unauthorized patches, and similar tools frequently present significant security risks and may contain malicious software.
Users should contact the help desk when they require an application that is not already authorized.
Browser Extensions & Plug-Ins
Users must not install browser extensions, plug-ins, add-ons, or other browser-based software without authorization from Falcon IT Services.
Browser extensions can introduce security, privacy, and data-access risks. Falcon IT Services may restrict or remove unauthorized extensions from managed devices.
Network and Online Storage Folder Creation Policy
When creating folders or shared storage locations containing sensitive or confidential information, users should contact the help desk so that appropriate access controls can be established.
New folders may inherit permissions from their parent folders, which may not be appropriate for sensitive information. Access controls should be reviewed whenever new shared folders or sensitive data repositories are created.
Organizational Access
Users should access organizational email, intranet sites, VPNs, cloud services, and other organizational resources only from authorized and appropriately secured devices.
Where required by organizational policy, users must use managed devices to connect to organizational systems and conduct company business.
Single Sign-On Policy
Organizational email addresses and credentials should not be used as single sign-on credentials for non-business services unless specifically approved.
Users should not connect organizational accounts to unauthorized applications, websites, cloud services, browser extensions, or other third-party services.
Before granting an application access to organizational data through OAuth, API access, or another delegated authorization mechanism, the application should be reviewed and approved according to the organization’s security requirements.
Assignment of Rights
Organizations should clearly communicate that data created, transmitted, received, or stored using company systems and resources may be considered company information and may be subject to monitoring, retention, legal discovery, or disclosure as permitted by applicable law and organizational policy.
Employees should not have an expectation that personal information stored on company-owned systems will remain private.
Organizations should consult legal counsel when establishing policies concerning employee privacy, monitoring, legal discovery, and ownership of information.
Secure Communications
Users must not transmit sensitive information, including PII, PHI, payment-card information, passwords, confidential business information, or intellectual property, through unencrypted email, chat, file-transfer services, or other unauthorized channels.
Sensitive information should be transmitted only through approved and appropriately secured methods.
Voicemail
Users should not use simple numeric passwords, dates, or other easily guessed information as voicemail PINs.
Sensitive information, including passwords, PII, PHI, payment information, or confidential business information, should not be left in voicemail messages.
Unacceptable Use of Systems
Users must not use organizational systems or resources to:
Send or post discriminatory, harassing, threatening, or abusive messages or images.
Commit fraud or other unlawful activity.
Steal, use, or disclose another person’s password or credentials without authorization.
Download, copy, or distribute copyrighted software, media, or other materials without authorization.
Share confidential information, trade secrets, or proprietary information outside the organization without authorization.
Attempt to gain unauthorized access to systems, networks, accounts, or websites.
Introduce malicious software or otherwise compromise organizational security.
Send chain letters, unauthorized solicitations, or advertisements unrelated to legitimate business purposes.
Represent personal opinions as official statements of the organization without authorization.
Hotspot / Wi-Fi Policy
Company-managed devices should not connect to unknown or public wireless networks. When traveling, users should connect using their cellular hotspot before accessing company resources.
Asset Disposal Policy
Organizations must securely dispose of computers, smartphones, tablets, servers, printers, copiers, IoT devices, removable media, paper documents, and other assets that may contain sensitive information.
Before equipment is discarded, recycled, transferred, or sent for repair, organizational data should be securely removed or protected through appropriate encryption and disposal procedures.
Scanned Documents
Documents containing sensitive information should be scanned and stored only in approved locations with appropriate access controls.
Users should not scan sensitive documents directly to personal email accounts or send them to unauthorized external mailboxes.
Scanned documents containing PII, PHI, financial information, or other sensitive data should be moved promptly to an appropriately secured storage location.
Device Encryption
Portable devices that contain or provide access to sensitive information should use full-device encryption.
Sensitive information should not be stored on unencrypted laptops, tablets, smartphones, removable media, or other portable devices.
Where practical, sensitive information should be stored in approved organizational systems rather than locally on portable devices.
Categorize Data Sensitivity
Organizations should categorize information according to its sensitivity and establish appropriate requirements for storage, access, transmission, and disposal.
Access to sensitive information should follow the principle of least privilege, meaning users receive only the access necessary to perform their job duties.
Auditing
Organizations should periodically review people, processes, and technology to determine whether security policies and controls are being followed.
Auditing may include reviewing user access, administrative activity, security alerts, file access, backups, endpoint security, patch status, and other appropriate controls.
The frequency and scope of audits should be based on organizational size, risk, budget, regulatory requirements, contractual obligations, and available resources.
Patch Management
Falcon IT Services manages security updates and patches for covered systems and devices where technically supported and included in the applicable service agreement.
Users must not interfere with, disable, or circumvent automated update or management systems.
Critical and high-risk security patches should be prioritized and installed within an appropriate timeframe based on risk.
Unsupported or end-of-life operating systems, applications, and hardware should be identified and replaced, upgraded, or otherwise addressed through an approved exception process.
End-of-Life and Unsupported Technology
Organizations should replace or upgrade hardware and software that is no longer supported by the manufacturer or vendor.
Unsupported technology may contain vulnerabilities that can no longer be addressed through normal security updates. Falcon IT Services may recommend replacement or upgrades when equipment or software can no longer be adequately supported or secured.
Backups
Organizations should maintain a backup policy defining the minimum requirements for backup frequency, retention, storage location, and restoration testing.
Backups should be appropriately protected against unauthorized access, deletion, modification, and ransomware.
Organizations should maintain appropriate on-site, off-site, or cloud-based backups based on their business requirements.
The organization should define its Recovery Time Objective (RTO) and Recovery Point Objective (RPO) and periodically test the ability to restore critical data and systems.
By default, Falcon IT Services may configure managed backups using daily backups for seven days, weekly backups for four weeks, and yearly backups for five years. Retention may be increased where compliance or business requirements dictate or reduced based on available storage, resources, and the client’s specific agreement.
AI Policies
Artificial intelligence (AI) tools can improve productivity but may introduce security, privacy, accuracy, intellectual-property, and confidentiality risks.
Organizations should maintain a list of approved AI tools and establish clear rules governing which tools may be used for company business.
Before approving an AI service, organizations should understand how the provider handles submitted information, including data retention, privacy, security, use of submitted data, and whether information may be used to improve or train AI models.
Employees should not enter confidential, proprietary, personal, protected health, payment-card, credential, or other sensitive information into AI tools unless specifically authorized by organizational policy and appropriate security controls are in place.
AI-generated information should be reviewed by a qualified person before being relied upon for business-critical decisions or published externally. AI output may be inaccurate, incomplete, biased, or inappropriate and should not automatically be treated as authoritative.
Organizations should establish procedures for reviewing AI-generated content that is used in public communications, customer-facing materials, software development, legal documents, financial activities, or other critical business processes.
Employees should not grant AI tools access to organizational applications, data, email, cloud services, APIs, or other systems through OAuth, API keys, delegated access, or other authorization mechanisms without prior approval.
AI Wearables
AI-enabled wearables and other devices capable of recording, transmitting, or analyzing audio, video, images, biometric information, or other sensitive data may create privacy and security risks.
Organizations should establish appropriate policies governing the use of such devices on company premises and while conducting company business.
Employees who require wearable technology for a medical or disability-related reason should work with their employer’s HR department to determine appropriate accommodations consistent with applicable law.
Nothing in an organization’s cybersecurity policies should be interpreted to restrict legally protected employee rights, including rights protected by applicable labor laws. Organizations should consult legal counsel when establishing policies concerning workplace recording, privacy, employee communications, or wearable technology.
Shadow IT Policies
Shadow IT refers to technology systems, applications, cloud services, or other technology resources used by employees or departments without appropriate IT approval or oversight.
Employees must not independently subscribe to cloud services, install applications, store company data, transfer company information, or conduct company business using unauthorized systems or accounts.
Employees who need a new application or service should contact the help desk or designated IT contact for review and approval.
Unauthorized email systems, file-storage services, data-transfer services, CRM systems, ERP systems, accounting systems, personal cloud accounts, and similar services should not be used for company business.
New projects involving IT systems, applications, data, or technology should be reviewed by the organization’s IT or security function before implementation.
Financial Transactions Policy
Organizations should establish procedures for initiating financial transactions and making changes to existing payment accounts.
Account changes, payment instructions, wire transfers, and similar requests should never be trusted solely because they originate through email, voicemail, text message, chat, or video conference.
Use an independent verification method, such as calling a known and trusted telephone number, to confirm changes to account numbers, payment instructions, vendors, or other financial information.
Higher-value transactions should require additional verification and, where appropriate, approval by more than one authorized individual.
Organizations should use available banking security features, including MFA and transaction alerts, and should disable online wire-transfer capabilities when they are not required.
Employees responsible for financial transactions should receive specific training on business email compromise, social engineering, invoice fraud, and other financial scams.
Organizations should establish and communicate a written financial transaction policy to employees, vendors, and other parties as appropriate.
Physical Security
Users are responsible for protecting company equipment and information from unauthorized physical access.
Computers and other devices should be locked when unattended. Sensitive documents should not be left exposed, and visitors should not be given unsupervised access to restricted areas, company equipment, or sensitive information.
Lost or stolen company equipment should be reported to the help desk immediately.
Verify Before You Trust
Users should independently verify unusual or unexpected requests involving passwords, MFA codes, payments, wire transfers, account changes, sensitive information, remote access, or other security-sensitive activities.
Do not rely solely on the communication channel through which a request was received. For example, an email requesting a change to payment instructions should be independently verified using a known and trusted telephone number or other established verification method.
When in doubt, contact the help desk before taking action.
Security Incident Reporting
Users should immediately report suspected malware, compromised credentials, lost or stolen devices, suspicious activity, or accidental disclosure of sensitive information to the help desk or the organization’s designated security contact.
Users should not attempt to conceal, delete, or destroy evidence of a suspected security incident. When in doubt, contact the help desk before attempting to resolve a suspected security issue independently.
General Access Management
User access should be limited to the systems and information required to perform assigned job duties.
Access should be reviewed periodically and promptly removed or modified when an employee changes roles or leaves the organization.
Falcon IT Services will implement access changes based on authorization from the client’s designated authorized contact.
Client WISP and Additional Security Requirements
This guide establishes general cybersecurity requirements and best practices for Falcon IT Services’ managed-service clients. It is not intended to replace the client’s Written Information Security Program (WISP) or other organizational policies.
Clients are responsible for maintaining and enforcing a WISP and other policies appropriate to their organization, including policies addressing incident response, business continuity, disaster recovery, regulatory compliance, employee responsibilities, data retention, and other requirements specific to their business.
