Skip to main content

Flink Information Security Policy V1.0

LAST REVISION DATE: September 11, 2024

DOCUMENT OWNER : Janko Ulaga / Atharva Shirode

--------------------------------------------------------------------------------------------------------

TABLE OF CONTENTS

--------------------------------------------------------------------------------------------------------

1. Introduction

  1. PURPOSE​

This policy defines the technical controls, and security configurations users and Information Technology (IT) administrators are required to implement in order to ensure the integrity and availability of the data environment at Flink, hereinafter, referred to as Flink. It serves as a central policy document with which all employees and contractors must be familiar and defines actions and prohibitions that all users must follow. The policy provides the IT team within Flink with policies and guidelines concerning the acceptable use of Flink technology equipment, email, Internet connections, future technology resources and information processing.

The policy requirements and restrictions defined in this document shall apply to network infrastructures, databases, external media, encryption, hardcopy reports, films, slides, models, wireless, telecommunication, conversations, and any other methods used to convey knowledge and ideas across all hardware, software, and data transmission mechanisms. This policy must be adhered to by all Flink employees or temporary workers at all locations and by contractors working with Flink as subcontractors.

  1. SCOPE

This policy document defines common security requirements for all Flink personnel and systems that create, maintain, store, access, process or transmit information. This policy also applies to information resources owned by others, such as contractors of Flink, entities in the private sector, in cases where Flink has a legal, contractual or fiduciary duty to protect said resources while in Flink custody. In the event of a conflict, the more restrictive measures apply. This policy covers Flink’s network system which comprises various hardware, software, communication equipment and other devices designed to assist Flink in the creation, receipt, storage, processing, and transmission of information. This definition includes equipment connected to any Flink domain or VLAN, either hardwired or wirelessly, and includes all stand-alone equipment that is deployed by Flink at its office locations or at remote locales.

  1. ACRONYMS / DEFINITIONS

Common terms and acronyms that may be used throughout this document.

CEO – The Chief Executive Officer is responsible for the overall privacy and security practices of the company.

VP Engineering – Vice President Engineering

CST – Confidentiality and Security Team

Encryption – The process of transforming information, using an algorithm, to make it unreadable to anyone other than those who have a specific ā€˜need to know.’

External Media –i.e. flash drives, USB keys, thumb drives.

FAT – File Allocation Table - The FAT file system is relatively uncomplicated and an ideal format for floppy disks and solid-state memory cards. The most common implementations have a serious drawback in that when files are deleted and new files written to the media, their fragments tend to become scattered over the entire media, making reading and writing a slow process.

Firewall – a dedicated piece of hardware or software running on a computer which allows or denies traffic passing through it, based on a set of rules.

FTP – File Transfer Protocol

IT - Information Technology

LAN – Local Area Network – a computer network that covers a small geographic area, i.e. a group of buildings, an office.

NTFS – New Technology File Systems – NTFS has improved support for metadata and the use of advanced data structures to improve performance, reliability, and disk space utilization plus additional

extensions such as security access control lists and file system journaling. The exact specification is a trade secret of Microsoft.

SOW - Statement of Work - An agreement between two or more parties that details the working relationship between the parties and lists a body of work to be completed.

User - Any person authorized to access an information resource.

Privileged Users – system administrators and others specifically identified and authorized by Flinks’

management.

Users with edit/update capabilities – individuals who are permitted, based on job assignment, to add, delete, or change records in a database.

Users with inquiry (read only) capabilities – individuals who are prevented, based on job assignment, from adding, deleting, or changing records in a database. Their system access is limited to reading information only.

VLAN – Virtual Local Area Network – A logical network, typically created within a network device, usually used to segment network traffic for administrative, performance and/or security purposes.

VPN – Virtual Private Network – Provides a secure passage through the public Internet.

WAN – Wide Area Network – A computer network that enables communication across a broad area, i.e. regional, national.

Virus - a software program capable of reproducing itself and usually capable of causing great harm to files or other programs on the computer it attacks. A true virus cannot spread to another computer without human assistance.

  1. APPLICABLE STATUTES / REGULATIONS

The following is a list of the various agencies/organizations whose laws, mandates, and regulations were incorporated into the various policy statements included in this document.

Berlin Data Protection Authority : General Data Protection Regulation, Berlin Data Protection Act.

Each of the policies defined in this document is applicable to the task being performed – not just to specific departments or job titles.

  1. INFORMATION SECURITY OFFICER

This ISO will oversee all ongoing activities related to the development, implementation, and maintenance of Flink’s privacy policies in accordance with applicable federal and state laws. The current ISO for Flink is:

Atharva Shirode, Senior IT Security Specialist

  1. CONFIDENTIALITY / SECURITY TEAM (CST)

Flink has established a Confidentiality / Security Team made up of key personnel whose responsibility it is to identify areas of concern within Flink and act as the first line of defense in enhancing the appropriate security posture.
​
The current members of the CST are:

  1. Janko Ulaga

  2. Atharva Shirode

  3. Cornelius von Cramm

  4. Martin HlavĆ”Ä

The CST will meet quarterly to discuss security issues and to review concerns that arose during the quarter. The CST will identify areas that should be addressed during annual training and review/update security policies as necessary.

The CST will address security issues as they arise and recommend and approve immediate security actions to be undertaken. It is the responsibility of the CST to identify areas of concern within Flink and act as the first line of defense in enhancing the security posture of Flink.

The CST is responsible for maintaining a log of security concerns or confidentiality issues. This log must be maintained on a routine basis, and must include the dates of an event, the actions taken to address the event, and recommendations for personnel actions, if appropriate. This log will be reviewed during the quarterly meetings.

The ISO or other assigned personnel is responsible for maintaining a log of security enhancements and features that have been implemented to further protect all sensitive information and assets held by Flink. This log will also be reviewed during the quarterly meetings.

2. Employee Responsibilities

  1. EMPLOYEE REQUIREMENTS

The first line of defense in data security is the individual employee. Flink employees are responsible for the security of all data which may come to them in whatever format. Flink is responsible for maintaining ongoing training programs to inform all users of these requirements.

Challenge Unrecognized Personnel - It is the responsibility of all Flink personnel to take positive action to provide physical security. If you see an unrecognized person in a restricted Flink location, you should challenge them as to their right to be there. All visitors to Flink offices must sign in at the front desk. All other personnel must be employees of Flink. Any challenged person who does not respond appropriately should be immediately reported to supervisory staff.

Unattended Computers - Unattended computers should be locked by the user when leaving the work area. This feature will be discussed with all employees during yearly security training.

Home Use of Flink Corporate Assets - Only computer hardware and software owned by and installed by Flink is permitted to be connected to or installed on Flink equipment. Personal computers supplied by Flink are to be used solely for business purposes. All employees and contractors must read and understand the list of prohibited activities that are outlined below. Modifications or configuration changes are not permitted on computers supplied by Flink for home use.

Retention of Ownership - All software programs and documentation generated or provided by employees, consultants, or contractors for the benefit of Flink are the property of Flink unless covered by a contractual agreement. Nothing contained herein applies to software purchased by Flink employees at their own expense.
​
​

  1. PROHIBITED ACTIVITIES

Personnel are prohibited from the following activities. The list is not inclusive. Other prohibited activities are referenced elsewhere in this document.

  • Crashing an information system. Deliberately crashing an information system is strictly prohibited. Users may not realize that they caused a system crash, but if it is shown that the crash occurred as a result of user action, a repetition of the action by that user may be viewed as a deliberate act.

  • Attempting to break into an information resource or to bypass a security feature. This includes running password-cracking programs or sniffer programs and attempting to circumvent file or other resource permissions.

  • Introducing, or attempting to introduce, computer viruses, Trojan horses, peer-to-peer (ā€œP2Pā€) or other

malicious code into an information system.

Exception: Authorized information system support personnel, or others authorized by Flink’ ISO, may test the resiliency of a system. Such personnel may test for susceptibility to hardware or software failure, security against hacker attacks, and system infection.

  • Browsing. The willful, unauthorized access or inspection of confidential or sensitive information to which you have not been approved on a "need to know" basis is prohibited. The purposeful attempt to look at or access information to which you have not been granted access by the appropriate approval procedure is strictly prohibited.

  • Personal or Unauthorized Software. Use of personal software is prohibited. All software installed on Flink computers must be approved by Flink.

  • Software Use. Violating or attempting to violate the terms of use or license agreement of any software product used by Flink is strictly prohibited.

  • System Use. Engaging in any activity for any purpose that is illegal or contrary to the policies, procedures or business interests of Flink is strictly prohibited.
    ​

  1. ELECTRONIC COMMUNICATION, EMAIL, INTERNET USAGE

Private use of company IT equipment (Internet, computers, devices and programs), telecommunications equipment (telephones, mail, fax) and photocopiers as well as the associated software is not permitted.
​
You may only use the telephone system privately in urgent cases. The obligation to use the telephone system exclusively for business purposes applies in particular to the use of e-mail and the Internet. If you receive messages with private content on your business e-mail address, please delete them immediately and completely. This also serves to protect your privacy, especially if it is necessary, for example, during your vacation or illness, for colleagues to access the e-mails that come in or go out via your work e-mail address.


You may not install pirated or unlicensed software on any company computer or network. If you want to install software licensed by us, you need our prior consent. Installation is only possible on the hardware provided by us; external distribution or installation on private devices is not permitted. Likewise excluded is the storage or processing of official files or documents on

private hardware or through private software.
​
​

  1. OFFICE INTERNET ACCESS

Office Internet access is provided for Flink employees and is considered a great resource for the organization. This resource is costly to operate and maintain, and must be allocated primarily to those with business, administrative or contract needs.

Many Internet sites, such as games, peer-to-peer file sharing applications, chat rooms, and on-line music sharing applications, could have already been blocked by Flink routers and firewalls. This list is constantly monitored and updated as necessary. Any employee visiting pornographic sites will be disciplined and may be terminated.
​
​

  1. REPORTING SOFTWARE MALFUNCTIONS

If the user, or the user's manager or supervisor, suspects a computer virus infection, Flink’ computer virus policy should be followed, and these steps should be taken immediately:

  • Stop using the computer

  • Do not carry out any commands, including commands to <Save> data.

  • Do not close any of the computer's windows or programs.

  • Do not turn off the computer or peripheral devices.

  • If possible, physically disconnect the computer from networks to which it is attached.

  • Inform the appropriate personnel or ISO as soon as possible. Write down any unusual behavior of the computer (screen messages, unexpected disk access, unusual responses to commands) and the time when they were first noticed.

  • Write down any changes in hardware, software, or software use that preceded the malfunction.

  • Do not attempt to remove a suspected virus!

The ISO should monitor the resolution of the malfunction or incident, and report to the CST the result of the action with recommendations on action steps to avert future similar occurrences.
​
​

  1. REPORT SECURITY INCIDENTS

It is the responsibility of each Flink employee or contractor to report perceived security incidents on a continuous basis to the appropriate supervisor or security person. A User is any person authorized to access an information resource. Users are responsible for the day-to-day, hands-on security of that resource. Users are to formally report all security incidents or violations of the security policy immediately to the ISO. Users should report any perceived security incident to either their immediate supervisor, or to their department head, or to any member of Flink CST. Members of the CST are specified above in this document.

Reports of security incidents shall be escalated as quickly as possible. Each member of Flink CST must inform the other members as rapidly as possible. Each incident will be analyzed to determine if changes in the existing security structure are necessary. All reported incidents are logged and the remedial action indicated. It is the responsibility of the CST to provide training on any procedural changes that may be required as a result of the investigation of an incident.

Security breaches shall be promptly investigated. If criminal action is suspected, Flink’ ISO/DPO shall contact the appropriate law enforcement and investigative authorities immediately.
​
​

  1. TRANSFER OF SENSITIVE/CONFIDENTIAL INFORMATION

When confidential or sensitive information from one individual is received by another individual while conducting official business, the receiving individual shall maintain the confidentiality or sensitivity of the information in accordance with the conditions imposed by the providing individual. All employees must recognize the sensitive nature of data maintained by Flink and hold all data in the strictest confidence. Any purposeful release of data to which an employee may have access is a violation of Flink’ policy and will result in personnel action and may result in legal action.

  1. TRANSFERRING SOFTWARE AND FILES BETWEEN PERSONAL AND CORPORATE DEVICES

Personal software shall not be used on Flink computers or networks. If a need for specific software exists, then a vendor management process is required where the Finance, Legal and IT team should approve the requests. Users shall not use Flink purchased software on non-Flink computers or equipment. Flink proprietary data, including but not limited to IT Systems information, financial information or human resource data, shall not be placed on any computer that is not the property of Flink without written consent of the respective supervisor or department head. It is crucial to Flink to protect all data and, in order to do that effectively we must control the systems in which it is contained. In the event that a supervisor or department head receives a request to transfer Flink data to a non-Flink Computer System, the supervisor or department head should notify the ISO or appropriate personnel of the intentions and the need for such a transfer of data.

All Flink-owned and managed IT and cloud assets are maintained with a wide range of security protections in place, which include features such as virus protection, email file type restrictions, firewalls, anti-hacking hardware and software, etc. Since Flink do not control non-Flink personal computers, Flink cannot be sure of the methods that may or may not be in place to protect Flink sensitive information, hence the need for this restriction.

  1. INTERNET CONSIDERATIONS

Special precautions are required to block Internet (public) access to Flink information resources not intended for public access, and to protect confidential Flink information when it is to be transmitted over the Internet.

The following security and administration issues shall govern Internet usage.

Prior approval of Flink’ ISO or appropriate personnel authorized by Flink shall be obtained before:

  • Flink information (including notices, memoranda, documentation and software) is made available on any Internet-accessible computer (e.g. web or ftp server) or device;

  • Users may not install or download any software (applications, screensavers, etc.). If users have a need for additional software, the user is to contact their supervisor;

  • Confidential or sensitive information - including credit card numbers, telephone calling card numbers, logon passwords, and other parameters that can be used to access goods or services shall be encrypted before being transmitted through the Internet.

  • The encryption software used, and the specific encryption keys (e.g. passwords, passphrases), shall be escrowed with Flink’ ISO or appropriate personnel, to ensure they are safely maintained/stored. The use of encryption software and keys, which have not been escrowed as prescribed above, is prohibited, and may make the user subject to disciplinary action.

  1. DE-IDENTIFICATION / RE-IDENTIFICATION OF PERSONAL IDENTIFIABLE INFORMATION (PII)

All personally identifying information is removed from all data that falls within the definition of PII before it is stored or exchanged.

De-identification is defined as the removal of any information that may be used to identify an individual or of relatives, employers, or household members.

PII includes:

  • Names

  • Addresses

  • All elements of dates directly related to the individual (Dates of birth, marriage, death, etc.)

  • Telephone numbers

  • Email addresses

  • Account numbers, certificate/license numbers

  • Device identifiers and serial numbers

  • Web Universal Resource Locators (URLs)

  • Internet Protocol (IP) address numbers

  • Full face photographic images and any comparable images

Re-identification of confidential information: A cross-reference code or other means of record identification is used to re-identify data as long as the code is not derived from or related to information about the individual and cannot be translated to identify the individual. In addition, the code is not disclosed for any other purpose nor is the mechanism for re-identification disclosed.

3. Identification and Authentication

  1. USER LOGON IDS

Individual users shall have an SAP account. An access control system (Okta) shall identify each user and prevent unauthorized users from entering or using information resources. Security requirements for user identification include:

Flink’ Human Resources Department or appropriate personnel deactivate the account upon the departure of all employees and contractors, at which time accounts are revoked.

Users who desire to obtain access to Flink systems or networks must have a ticket created here. This ticket must be approved by the supervisor or department head of each user requesting access.
​
​

  1. PASSWORDS

User Account Passwords

User IDs and passwords are required in order to gain access to all Flink networks and workstations. All passwords are restricted by a corporate-wide password policy to be of a "Strong" nature. This means that all passwords must conform to restrictions and limitations that are designed to make the password difficult to guess. Users are required to select a password in order to obtain access to any electronic information both at the server level and at the workstation level. When passwords are reset, the user will be automatically prompted to manually change that assigned password.

Password Length – Passwords are required to be a minimum of eight characters.

Content Requirements - Passwords must contain a combination of upper and lower case alphabetic characters, numeric characters, and special characters.

Change Frequency – Passwords must be changed every 180 days. Compromised passwords shall be changed immediately.

Reuse - Previous passwords cannot be reused.

Restrictions on Sharing Passwords - Passwords shall not be shared, written down on paper, or stored within a file or database on a workstation and must be kept confidential.

Restrictions on Recording Passwords - Passwords are masked or suppressed on all online screens, and are never printed or included in reports or logs. Passwords are stored in an encrypted format.
​
​

  1. CONFIDENTIALITY AGREEMENT

We attach great importance to protecting confidential information about our company. You therefore undertake to keep operational matters of a confidential nature secret, in particular company and business secrets, as well as contractual provisions, and to use information in this regard exclusively for operational purposes and not to pass it on to outsiders. The duty of confidentiality remains in force after termination of the employment relationship. It must also be maintained vis-Ć -vis other employees of our company, insofar as they do not require the respective information for their own work.

When handling information that you receive in the course of your work for us, you will comply with the applicable laws, in particular the General Data Protection Regulation and the Federal Data Protection Act. Please do not take any confidential documents into your private possession or remove them from the business premises of our company. Furthermore, it is prohibited to copy these documents without authorization, to hand them over to unauthorized persons or to forward them to the press. The same applies to self-made official records or notes. Upon termination of employment, you will leave all such documents at your place of employment.

In the event of culpable disclosure of confidential documents or information to a company competing with us, you agree to pay liquidated damages in the amount of one gross monthly salary. The assertion of further damages and further rights, in particular injunctive relief, shall remain unaffected
​
​

  1. ACCESS CONTROL

Information resources are protected by the use of access control systems. Access control systems include both internal (i.e. passwords, encryption, access control lists, constrained user interfaces, etc.) and external (i.e. port protection devices, firewalls, host-based authentication, etc.).

Rules for access to resources (including internal and external telecommunications and networks) have been established by the information/application owner or manager responsible for the resources. Access is granted only by creating a ticket here. This form can only be initiated by the appropriate department head and must be signed by the department head and the ISO or appropriate personnel.

This guideline satisfies the "need to know" requirement of local regulations, since the supervisor or department head is the person who most closely recognizes an employee's need to access data. Users may be added to the information system, network, cloud systems only upon the signature of the ISO or appropriate personnel who are responsible for adding the employee to the network in a manner and fashion that ensures the employee is granted access to data only as specifically requested.

Identification and Authentication Requirements

The host security management program shall maintain current user application activity authorizations. Each initial request for a connection or a session is subject to the authorization process previously addressed.
​
​

  1. USER LOGIN ENTITLEMENT REVIEWS

If an employee changes positions at Flink, employee’s new supervisor or department head (or SAP account title change- automation with Okta) shall promptly notify the Information Technology (ā€œITā€) Department of the change of roles by creating a ticket here, both the roles or access that need to be added and the roles.

or access that need to be removed so that employee has access to the minimum necessary data to effectively perform their new job functions. The effective date of the position change should also be noted on the ticket so that the IT Department can ensure that the employee will have appropriate roles, access, and applications for their new job responsibilities. For a limited training period, it may be necessary for the employee who is changing positions to maintain their previous access as well as adding the roles and access necessary for their new job responsibilities.

No less than annually, the IT Lead shall facilitate entitlement reviews with department heads to ensure that all employees have the appropriate roles, access, and software necessary to perform their job functions effectively.
​
​

  1. TERMINATION OF USER LOGON ACCOUNT

Upon termination of an employee, whether voluntary or involuntary, the employee's supervisor or department head shall promptly notify the IT Department by indicating ā€œRemove Accessā€ on the ticket here Or make the necessary changes to SAP account and it would reflect to all systems using IAM tool Okta. The employee’s department head shall be responsible for ensuring that all keys, ID badges, and other access devices as well as Flink equipment and property is returned to Flink prior to the employee leaving Flink on their final day of employment. Please check the offboarding checklist here.

No less than quarterly, the IT Manager or their designee shall provide a list of active user accounts for both network and application access, to department heads for review. Department heads shall review the employee access lists within five (5) business days of receipt. If any of the employees on the list are no longer employed by Flink, the department head will immediately notify the IT Department of the employee’s termination status and submit the ticket here.
​
​
​

4. Network Connectivity

  1. REMOTE CONNECTIONS

Access to Flink information resources including cloud-based services, shall be subject to authorization and authentication by an access control system. Access without prior authorization is prohibited.

Systems that allow public access to host computers, including mission-critical servers, warrants additional security at the operating system and application levels. Such systems shall have the capability to monitor activity levels to ensure that public usage does not unacceptably degrade system responsiveness.

Remote access privileges are granted only upon the request of a department head with the submission of the ticket here and the approval of the ISO or appropriate personnel.

  1. PERMANENT CONNECTIONS

The security of Flink systems can be jeopardized from third party locations if security practices and resources are inadequate. When there is a need to connect to a third party location, a risk analysis should be conducted. The risk analysis should consider the type of access required, the value of the information, the security measures employed by the third party, and the implications for the security of Flink systems. The ISO or appropriate personnel should be involved in the process, design and approval.

  1. EMPHASIS ON SECURITY IN THIRD PARTY CONTRACTS

Access to Flink computer systems or corporate networks should not be granted until a review of the following concerns have been made, and appropriate restrictions or covenants included in a statement of work (ā€œSOWā€) with the party requesting access.

  • Applicable sections of Flink’ Information Security Policy have been reviewed and considered.

  • Policies and standards established in Flink’ information security program have been enforced.

  • A risk assessment of the additional liabilities that will attach to each of the parties to the agreement.

  • The right to audit contractual responsibilities should be included in the agreement or SOW.

  • Arrangements for reporting and investigating security incidents must be included in the agreement.

  • A description of each service to be made available.

  • Each service, access, account, and/or permission made available should only be the minimum necessary for the third party to perform their contractual obligations.

  • A detailed list of users that have access to Flink computer systems must be maintained and auditable.

  • If required under the contract, permission should be sought to screen authorized users.

  • Dates and times when the service is to be available should be agreed upon in advance.

  • Procedures regarding protection of information resources should be agreed upon in advance and a method of audit and enforcement implemented and approved by both parties.

  • The right to monitor and revoke user activity should be included in each agreement.

  • Language on restrictions on copying and disclosing information should be included in all agreements.

  • Responsibilities regarding hardware and software installation and maintenance should be understood and agreed upon in advance.

  • Measures to ensure the return or destruction of programs and information at the end of the contract should be written into the agreement.

  • If physical protection measures are necessary because of contract stipulations, these should be included in the agreement.

  • A formal method to grant and authorize users who will access to the data collected under the agreement should be formally established before any users are granted access.

  • Mechanisms should be in place to ensure that security measures are being followed by all parties to the agreement.

  • A detailed list of the security measures which will be undertaken by all parties to the agreement should be published in advance of the agreement.
    ​

5. Malicious Code

  1. ANTIVIRUS SOFTWARE INSTALLATION

Antivirus software is installed on all Flink personal computers. Virus update patterns are updated daily on Flink workstations. Virus update engines and data files are monitored by appropriate administrative staff that is responsible for keeping all virus patterns up to date.

Remote Deployment Configuration - Through an automated procedure, updates and virus patches may be pushed out to the individual workstations on an as needed basis.

Monitoring/Reporting – A record of virus patterns for all workstations on Flink’ network may be maintained. Appropriate administrative staff is responsible for providing reports for auditing and emergency situations as requested by the ISO or appropriate personnel.
​
​

  1. NEW SOFTWARE DISTRIBUTION

Only software created by Flink application staff, if applicable, or software approved by the ISO or appropriate personnel will be used on internal computers and networks. All new software will be tested by appropriate personnel in order to ensure compatibility with currently installed software and network configuration. In addition, appropriate personnel must scan all software for viruses before installation. This includes shrink-wrapped software procured directly from commercial sources as well as shareware and freeware obtained from the Internet, or on disks.

Although shareware and freeware can often be useful sources of work-related programs, the use and/or acquisition of such software must be approved by the ISO or appropriate personnel. Because the software is often provided in an open distribution environment, special precautions must be taken before it is installed on Flink computers and networks. These precautions include determining that the software does not, because of faulty design, ā€œmisbehaveā€ and interfere with or damage Flink hardware, software, or data, and that the software does not contain viruses, either originating with the software designer or acquired in the process of distribution.

All data and program files that have been electronically transmitted to a Flink computer or network from another location must be scanned for viruses immediately after being received. Contact the appropriate Flink personnel for instructions for scanning files for viruses.

Every USB device is a potential source for a computer virus. Therefore, every USB device must be scanned for virus infection prior to copying information to a Flink computer or network.

Computers shall never be ā€œbootedā€ from a disk or USB device received from an outside source. Users shall always remove any USB device from the computer when not in use. This is to ensure that the USB device is not in the computer when the machine is powered on. A USB device infected with a boot virus may infect a computer in that manner, even if the USB device is not ā€œbootableā€.
​
​

  1. RETENTION OF OWNERSHIP

All software programs and documentation generated or provided by employees, consultants, or contractors for the benefit of Flink are the property of Flink unless covered by a contractual agreement. Employees developing programs or documentation must sign a statement acknowledging Flink ownership at the time of employment. Nothing contained herein applies to software purchased by Flink employees at their own expense.

6. Encryption

  1. DEFINITION

Encryption is the translation of data into a secret code. Encryption is the most effective way to achieve data security. To read an encrypted file, you must have access to a secret key or password that enables you to decrypt it. Unencrypted data is called plain text; encrypted data is referred to as cipher text.

  1. ENCRYPTION KEY

An encryption key specifies the particular transformation of plain text into cipher text, or vice versa during decryption.

If justified by risk analysis, sensitive information and files shall be encrypted before being transmitted through networks. When encrypted data are transferred between agencies, the agencies shall devise a mutually agreeable procedure for secure key management. In the case of conflict, Flink shall establish the criteria in conjunction with the ISO or appropriate personnel. Flink employs several methods of secure data transmission.

  1. SECURE SOCKET LAYER (SSL) WEB

Any hosted system, if applicable, will require access using a secure SSL connection.

7. Building Security

It is the policy of Flink to provide building access in a secure manner. Each site, if applicable, is somewhat unique in terms of building ownership, lease contracts, entranceway access, fire escape requirements, and server room control. However, Flink strives to continuously upgrade and expand its security and to enhance protection of its assets. The following list identifies measures that are in effect at Flink. All other facilities, if applicable, have similar security appropriate for that location.

  • Entrance to the building during non-working hours is controlled by a security guard. Attempted entrance without an Identifying badge results in immediate notification to the police department.

  • The door to the reception area is locked at all times and requires appropriate credentials or escort past the reception or waiting area door(s).

  • The reception area is staffed at all times during the working hours of 9:00 to 18:30.

  • Any unrecognized person in a restricted office location should be challenged as to their right to be there. All visitors must sign in at the front desk, wear a visitor badge, and be accompanied by a Flink staff member. In some situations, non-Flink personnel, who have signed the confidentiality agreement, do not need to be accompanied at all times.

  • Fire Protection: Use of local building codes will be observed. Manufacturer’s recommendations on the fire protection of individual hardware will be followed.

8. Telecommuting

With the increased availability of broadband access and VPNs, telecommuting has become more viable for many organizations. Flink considers telecommuting to be an acceptable work arrangement in certain circumstances. This policy is applicable to all employees and contractors who work either permanently or only occasionally outside of Flink’ office environment. It applies to users who work from their home full time to employees on temporary travel, to users who work from a remote office location, and to any user who connects to Flink’ network, if applicable, from a remote location.

While telecommuting can be an advantage for users and for the organization in general, it presents new risks in the areas of confidentiality and security of data. Workers linked to Flink’ network become an extension of the wide area network and present additional environments that must be protected against the danger of spreading Trojans, viruses, or other malware.
​
​

  1. GENERAL REQUIREMENTS

Telecommuting workers are required to follow all corporate, security, confidentiality, HR, or Code of Conduct policies that are applicable to other employees/contractors.

  • Need to Know: Telecommuting Users will have the access based on the same ā€˜need to know’ as they have when in the office.

  • Password Use: The use of a strong password, changed at least every 365 days, is even more critical in the telecommuting environment. Do not share your password or write it down where a family member or visitor can see it.

  • Training: Personnel who telecommute must complete the same annual privacy training as all other employees.

  • Contract Specific: There may be additional requirements specific to the individual contracts to which an employee is assigned.
    ​

  1. REQUIRED EQUIPMENT

Employees approved for telecommuting must understand that Flink will not provide all equipment necessary to ensure proper protection of information to which the employee has access; however, the following lists define the equipment and environment required:

Flink Provided:

Flink supplied workstation.

If printing, a Flink supplied printer.

If approved by your supervisor/founder, a Flink supplied phone.

Employee Provided:

Broadband connection and fees,

Secure office environment isolated from visitors and family,

A lockable file cabinet or safe to secure documents when away from the home office.
​
​

  1. HARDWARE SECURITY PROTECTIONS

Virus Protection: Home users must never stop the update process for Virus Protection. Virus Protection software is installed on all Flink personal computers and is set to update the virus pattern on a daily basis. This update is critical to the security of all data and must be allowed to complete.

VPN and Firewall Use: Established procedures must be rigidly followed when accessing Flink information of any type. Disabling a virus scanner or firewall is the reason for termination.

Lock Screens: No matter what location, always lock the screen before walking away from the workstation. The data on the screen may contain confidential information. Be sure the automatic lock feature has been set to automatically turn on after 15 minutes of inactivity.
​
​

  1. DATA SECURITY PROTECTION

Data Backup: Backup procedures have been established that encrypt the data. Use only that procedure – do not create one on your own. If there is not a backup procedure established, contact the appropriate Flink personnel for assistance.

Email: Do not send any PII via email unless it is encrypted. If you need assistance with this, contact the ISO or appropriate personnel to ensure an approved encryption mechanism is used for transmission through email.

Non-Flink Networks: Extreme care must be taken when connecting Flink equipment to a home or hotel network. Although Flink actively monitors its security status and maintains organization-wide protection policies to protect the data within all contracts, Flink has no ability to monitor or control the security procedures on non-Flink networks.

Protect Data in Your Possession: View or access only the information that you have a need to see to complete your work assignment. Regularly review the data you have stored to ensure that the amount of customer/client level data is kept at a minimum and that old data is eliminated as soon as possible. Store electronic data only in encrypted work spaces. If your laptop has not been set up with an encrypted work space, contact the ISO or appropriate personnel for assistance.

Hard Copy Reports or Work Papers: Never leave paper records around your work area. Lock all paper records in a file cabinet at night or when you leave your work area.

Data Entry When in a Public Location: Do not perform work tasks which require the use of sensitive corporate information when you are in a public area, i.e. airports, airplanes, hotel lobbies. Computer screens can easily be viewed from beside or behind you.

Sending Data Outside Flink: All external transfer of data must be associated with an official contract, non-disclosure agreement, or appropriate Business Associate Agreement. Do not give or transfer any customer/client level information to anyone outside Flink without the written approval of your supervisor.
​
​

  1. DISPOSAL OF PAPER AND/OR EXTERNAL MEDIA

Disposal of Electronic Media: All external media must be sanitized or destroyed.

  • Do not throw any media containing sensitive, protected information in the trash.

  • Return all external media to your supervisor

  • External media must be wiped clean of all data. The ISO or appropriate personnel has very definitive procedures for doing this – so all external media must be sent to them.

  • The final step in this process is to forward the media for disposal by a certified destruction agency.

9. Specific Protocols and Devices

  1. WIRELESS USAGE STANDARDS AND POLICY

Due to an emergence of wireless access points in hotels, airports, and in homes, it has become imperative that a Wireless Usage policy be developed and adopted to ensure the security and functionality of such connections for Flink employees. This policy outlines the processes and procedures for acquiring wireless access privileges, utilizing wireless access, and ensuring the security of Flink laptops and mobile devices.

All usage of public WiFi networks must happen while being connected to a Flink-issued VPN (if provided).

Software Requirements - The following is a list of minimum software requirements for any Flink laptop that is granted the privilege to use wireless access:

  • The client operating system has to be updated with the latest security patches

  • Antivirus software

  • Full Disk Encryption

  • Appropriate VPN Client, if applicable

  • Latest versions of Chrome

If your laptop does not have all of these software components, please notify your supervisor or department head so these components can be installed.
​
​

  1. USE OF PORTABLE MEDIA AND CLOUD STORAGE SERVICES

Portable media and cloud storage services included within the scope of this policy includes but is not limited to portable storage devices or storage on the cloud.

The purpose of this policy is to guide employees/contractors of Flink in the proper use of portable media or cloud storage services when a legitimate business requirement exists to transfer data to and from Flink.

Every workstation or server that has been used by either Flink employees or contractors is presumed to have sensitive information stored on its hard drive. Therefore procedures must be carefully followed when copying data to or from portable media or cloud storage services to protect sensitive information.

Since portable media, by their very design, are easily lost, care and protection of these devices must be addressed. Since it is very likely that portable media will be provided to a Flink employee by an external source for the exchange of information, it is necessary that all employees have guidance in the appropriate use of media from other companies.

The use of portable media and cloud storage service is common practice within Flink. All users must be aware that sensitive information could potentially be lost or compromised when moved outside of Flink. Transportable media received from an external source could potentially pose a threat to Flink networks.

Sensitive information includes all human resource data, financial data and Flink proprietary information.

Rules governing the use of portable media include:

  • No sensitive information should ever be stored on portable media unless the data is maintained in an encrypted format.

  • All USB keys used to store Flink data or sensitive information must be an encrypted USB key issued by the ISO or appropriate personnel. The use of a personal USB key is strictly prohibited.

  • Users must never connect their portable media to a workstation that is not issued by Flink.

  • Non-Flink workstations and laptops may not have the same security protection standards required by Flink, and accordingly virus patterns could potentially be transferred from the non-Flink device to the media and then back to Flink’ workstation.

Example: Do not copy a work spreadsheet to your USB key and take it home to work on your home PC or do not place it in non-corporate cloud services.

  • Data may be exchanged between Flink workstations/networks and workstations used within Flink. The very nature of data exchange requires that under certain situations data be exchanged in this manner.

Examples of necessary data exchange include: Data provided to auditors via USB key during the course of the audit.

  • Before initial use and before any sensitive information may be transferred to portable media, the media must be sent to the ISO or appropriate personnel to ensure appropriate and approved encryption is used. Copy sensitive information only to the encrypted space in the media. Non-sensitive information may be transferred to the non-encrypted space in the media.

  • Report all loss of portable media to your supervisor or department head. It is important that the CST team is notified either directly from the employee or contractor or by the supervisor or department head immediately.

  • When an employee leaves Flink, all portable media in their possession must be returned to the ISO or appropriate personnel for data erasure that conforms to regulatory standards for data elimination.

When no longer in productive use, all Flink laptops, workstation, or servers must be wiped of data. All portable media must be wiped according to the same standards. Thus all portable media must be returned to IT or appropriate personnel for data erasure when no longer in use.

Rules governing the use of cloud storage services include:

  • Only Flink approved cloud storage services may be used.

  • Users must never upload or download data from unapproved cloud storage services.

  • Data may be shared between Flink authorized users to be used within Flink.

  • It is permissible to share data outside of Flink provided that the user has authorization to do so.

  • File permissions (edit and share) must be reviewed periodically.

10. Disposal of External Media / Hardware

  1. DISPOSAL OF EXTERNAL MEDIA

It must be assumed that any external media in the possession of an employee is likely to contain sensitive information. Accordingly, external media (disks) should be disposed of in a method that ensures that there will be no loss of data and that the confidentiality and security of that data will not be compromised.

The following steps must be adhered to:

  • It is the responsibility of each employee to identify media which should be shredded and to utilize this policy in its destruction.

  • External media should never be thrown in the trash.

  • When no longer needed all forms of external media are to be sent to IT or appropriate personnel for proper disposal.

  • The media will be secured until appropriate destruction methods are used based on NIST 800-88 guidelines.
    ​

  1. REQUIREMENTS REGARDING EQUIPMENT

All equipment to be disposed of will be wiped of all data, and all settings and configurations will be reset to factory defaults. No other settings, configurations, software installation or options will be made. Asset tags and any other identifying logos or markings will be removed.

11. Change Management

Statement of Policy

To ensure that Flink is tracking changes to networks, systems, and workstations including software releases and software vulnerability patching in information systems that contain sensitive information. Change tracking allows the Information Technology (ā€œITā€) Department to efficiently troubleshoot issues that arise due to an update, new implementation, reconfiguration, or other change to the system. Check this process for a detailed explanation- Change Management Process.

Procedure

  1. The IT staff or other designated Flink employee who is updating, implementing, reconfiguring, or otherwise changing the system shall carefully log all changes made to the system.

  2. When changes are tracked within a system, Customers can request changes by contacting their Account Manager or the Customer Success department.

    1. When changes are tracked within a system, i.e. Windows updates in the Add or Remove Programs component, they do not need to be logged on the change management tracking log; however, the employee implementing the change will ensure that the change tracking is available for review if necessary.

  3. The employee implementing the change will ensure that all necessary data backups are performed prior to the change.

  4. The employee implementing the change shall also be familiar with the rollback process in the event that the change causes an adverse effect within the system and needs to be removed.

12. Audit Controls

Statement of Policy

To ensure that Flink implements hardware, software, and/or procedural mechanisms that record and examine activity in information systems that contain sensitive information. Audit Controls are technical mechanisms that track and record computer activities. An audit trail determines if a security violation occurred by providing a chronological series of logged computer events that relate to an operating system, an application, or user activities.

Flink is committed to routinely auditing users’ activities in order to continually assess potential risks and vulnerabilities to sensitive information in its possession. As such, Flink will continually assess potential risks and vulnerabilities to sensitive information in its possession and develop, implement, and maintain appropriate administrative, physical, and technical security measures.

Procedure

  1. See policy entitled Information System Activity Review for the administrative safeguards for auditing system activities.

  2. The Information Technology Services shall enable event auditing on all computers that process, transmit, and/or store sensitive information for purposes of generating audit logs. Each audit log shall include, at a minimum: user ID, login time and date, and scope of data being accessed for each attempted access. Audit trails shall be stored on a separate computer system to minimize the impact of such auditing on business operations and to minimize access to audit trails.

  1. Flink shall utilize appropriate network-based and host-based intrusion detection systems. The Information Technology Services shall be responsible for installing, maintaining, and updating such systems.

13. Information System Activity Review

Statement of Policy

To establish the process for conducting, on a periodic basis, an operational review of system activity including, but not limited to, user accounts, system access, file access, security incidents, audit logs, and access reports. Flink shall conduct on a regular basis an internal review of records of system activity to minimize security violations.

Procedure

  1. See policy entitled Audit Controls for a description of the technical mechanisms that track and record activities on Flink information systems that contain or use sensitive information.

  2. The Information Technology Services shall be responsible for conducting reviews of Flink information systems’ activities. Such person(s) shall have the appropriate technical skills with respect to the operating system and applications to access and interpret audit logs and related information appropriately.

  3. The ISO shall develop a report format to capture the review findings. Such reports shall include the reviewer’s name, date and time of performance, and significant findings describing events requiring additional action (e.g., additional investigation, employee training and/or discipline, program adjustments, modifications to safeguards). To the extent possible, such reports shall be in a checklist format.

  4. Such reviews shall be conducted annually. Audits also shall be conducted if Flink have reason to suspect wrongdoing. In conducting these reviews, the Information Technology Services shall examine audit logs for security-significant events including, but not limited to, the following:

    1. Logins – Scan successful and unsuccessful login attempts. Identify multiple failed login attempts, account lockouts, and unauthorized access.

    2. File accesses – Scan successful and unsuccessful file access attempts. Identify multiple failed access attempts, unauthorized access, and unauthorized file creation, modification, or deletion.

    3. Security incidents – Examine records from security devices or system audit logs for events that constitute system compromises, unsuccessful compromise attempts, malicious logic (e.g., viruses, worms), denial of service, or scanning/probing incidents.

  1. User Accounts – Review of user accounts within all systems to ensure users that no longer have a business need for information systems no longer have such access to the information and/or system.

All significant findings shall be recorded.

1. The Information Technology Services shall forward all completed reports, as well as recommended actions to be taken in response to findings, to the ISO for review. The ISO shall be responsible for maintaining such reports. The ISO shall consider such reports and recommendations in determining whether to make changes to Flink’ administrative, physical, and technical safeguards. In the event a security incident is detected through such auditing, such matter shall be addressed pursuant to the policy entitled Employee Responsibilities (Report Security Incidents).

14. Data Integrity

Statement of Policy

Flink shall implement and maintain appropriate electronic mechanisms to corroborate that sensitive information has not been altered or destroyed in an unauthorized manner.

The purpose of this policy is to protect Flink sensitive information from improper alteration or destruction.

Procedure

To the fullest extent possible, Flink shall utilize applications with built-in intelligence that automatically checks for human errors.

Flink shall acquire appropriate network-based and host-based intrusion detection systems. The ISO shall be responsible for installing, maintaining, and updating such systems.

To prevent transmission errors as data passes from one computer to another, Flink will use encryption, as determined to be appropriate, to preserve the integrity of data.

Flink will check for possible duplication of data in its computer systems to prevent poor data integration between different computer systems.

To prevent programming or software bugs, Flink will test its information systems for accuracy and functionality before it starts to use them. Flink will update its systems when IT vendors release fixes to address known bugs or problems.

  1. Flink will install and regularly update antivirus software on all workstations to detect and prevent malicious code from altering or destroying data.

  2. To prevent exposing magnetic media to a strong magnetic field, workforce members shall keep magnetic media away from strong magnetic fields and heat. For example, computers should not be left in automobiles during the summer months

15. Contingency Plan

Statement of Policy

To establish and implement policies and procedures for responding to an emergency or other occurrence (e.g., fire, vandalism, system failure, natural disaster) that damages systems that contain sensitive information.

Flink is committed to maintaining formal practices for responding to an emergency or other occurrence that damages systems containing sensitive information. Flink shall continually assess potential risks and vulnerabilities to protect sensitive information in its possession, and develop, implement, and maintain appropriate administrative, physical, and technical security measures.

SLAs:

Flink aims to achieve 99.9% availability for all services available to customers. Flink utilizes cloud infrastructure to deliver its product and service.
For IT / Availability issues & GSuite SLAs provide high availability at or above 99.9% availability.
Google cloud platform SLA’s : https://cloud.google.com/terms/sla
Google workspace SLA’s: https://workspace.google.com/terms/sla.html

Flink internal processes and procedures apply to the servers we control inside these cloud environments.

Procedure

  1. Data Backup Plan:

    1. Flink, under the direction of the ISO, shall implement a data backup plan to create and maintain retrievable exact copies of sensitive information.

    1. At the conclusion of each day, Monday through Sunday, an incremental backup of all servers containing sensitive information shall be backed up to the infrastructure provider.

    1. The ISO shall monitor storage and removal of backups and ensure all applicable access controls are enforced.

    1. The ISO shall test backup procedures on an annual basis to ensure that exact copies of sensitive information can be retrieved and made available. Such testing shall be documented by the ISO. To the extent such testing indicates need for improvement in backup procedures, the ISO shall identify and implement such improvements in a timely manner.

  1. Disaster Recovery and Emergency Mode Operations Plan:

    1. The ISO shall be responsible for developing and regularly updating the written disaster recovery and emergency mode operations plan for the purpose of:

      1. Restoring or recovering any loss of sensitive information and/or systems necessary to make sensitive information available in a timely manner caused by fire, vandalism, terrorism, system failure, or other emergency; and

      2. Continuing operations during such time information systems are unavailable. Such a written plan shall have a sufficient level of detail and explanation that a person unfamiliar with the system can implement the plan in case of an emergency or disaster. Copies of the plan shall be maintained on-site and at the off-site locations at which backups are stored or other secure off-site locations.
        ​

    2. The disaster recovery and emergency mode operation plan shall include the following:

      1. Current copies of the information systems inventory and network configuration developed and updated as part of Flink’ risk analysis.

      2. Current copy of the written backup procedures developed and updated pursuant to this policy.

      3. Identification of an emergency response team. Members of such team shall be responsible for the following:

        1. Determining the impact of a disaster and/or system unavailability on Flink’ operations.

        2. In the event of a disaster, securing the site and providing ongoing physical security.

        3. Retrieving lost data.

        4. Identifying and implementing appropriate ā€œwork-aroundsā€ during such time information systems are unavailable.

        5. Taking such steps necessary to restore operations.

      4. Procedures for responding to loss of electronic data including, but not limited to retrieval and loading of backup data or methods for recreating data should backup data be unavailable. The procedures should identify the order in which data is to be restored based on the criticality analysis performed as part of Flink’ risk analysis.

      5. Telephone numbers and/or email addresses for all persons to be contacted in the event of a disaster, including the following:

        1. Members of the immediate response team,

        2. Facilities at which backup data is stored,

        3. Information systems vendors, and

        4. All current workforce members
          ​

    3. The disaster recovery team shall meet on at least an annual basis to:

      1. Review the effectiveness of the plan in responding to any disaster or emergency experienced by Flink;

      2. In the absence of any such disaster or emergency, plan drills to test the effectiveness of the plan and evaluate the results of such drills; and

      3. Review the written disaster recovery and emergency mode operations plan and make appropriate changes to the plan. The ISO shall be responsible for convening and maintaining minutes of such meetings. The ISO also shall be responsible for revising the plan based on the recommendations of the disaster recovery team.
        ​

  2. Business Impact analysis:
    ​

    1. Identify Critical IT Resources: IT systems can be very complex, with numerous components, interfaces, and processes. A system often has multiple missions resulting in different perspectives on the importance of system services or capabilities. Critical IT resources must be identified such as Email Servers, WAN access, LAN Server etc.
      ​

    2. Identify disruption impact: In this step it is important to analyze the critical resources identified in the previous step and determine the impact(s) on IT operations if a given resource were disrupted or damaged.
      ​
      ​

    3. Develop recovery priorities: The outage impact(s) and allowable outage times characterized in the previous step enable the Information Security Officer to develop and prioritize recovery strategies that personnel will implement during contingency plan activation.
      ​
      ​

16. Security Awareness and Training

Statement of Policy

Aim to establish a security awareness and training program for all members of Flink’ workforce, including management. Check the security awareness training here.

All workforce members shall receive appropriate training concerning Flink security policies and procedures. Such training shall be repeated annually for all employees.

Procedure

  1. Security Training Program:

    1. The ISO shall have responsibility for the development and delivery of initial security training. All workforce members shall receive such initial training addressing regulatory requirements including the updates to regulations. Security training shall be provided to all new workforce members as part of the orientation process. Attendance and/or participation in such training shall be mandatory for all workforce members. The ISO shall be responsible for maintaining appropriate documentation of all training activities.

    2. The ISO shall have responsibility for the development and delivery of ongoing security training provided to workforce members in response to environmental and operational changes impacting the security of sensitive information, e.g., addition of new hardware or software, and increased threats.
      ​

  2. Security Reminders:

    1. The ISO shall generate and distribute to all workforce members routine security reminders on a regular basis. Periodic reminders shall address password security, malicious software, incident identification and response, and access control. The ISO may provide such reminders through formal training, email messages, discussions during staff meetings, screensavers, log-in banners, newsletter/intranet articles, posters, promotional items such as coffee mugs, mouse pads, sticky notes, etc. The ISO shall be responsible for maintaining appropriate documentation of all periodic security reminders.

    2. The ISO shall generate and distribute special notices to all workforce members providing urgent updates, such as new threats, hazards, vulnerabilities, and/or countermeasures.
      ​

  3. Protection from Malicious Software:

    1. As part of the aforementioned Security Training Program and Security Reminders, the ISO shall provide training concerning the prevention, detection, containment, and eradication of malicious software. Such training shall include the following:

      1. Guidance on opening suspicious email attachments, email from unfamiliar senders, and hoax email,

      2. The importance of updating anti-virus software and how to check a workstation or other device to determine if virus protection is current,

      3. Instructions to never download files from unknown or suspicious sources,

      4. Recognizing signs of a potential virus that could sneak past antivirus software or could arrive prior to an update to anti-virus software,

      5. The importance of backing up critical data on a regular basis and storing the data in a safe place,

      6. Damage caused by viruses and worms, and

      7. What to do if a virus or worm is detected.
        ​

  4. Password Management:

    1. As part of the aforementioned Security Training Program and Security Reminders, the ISO shall provide training concerning password management. Such training shall address the importance of confidential passwords in maintaining computer security, as well as the following requirements relating to passwords:

      1. Passwords must be changed every 180 days.

      2. A user cannot reuse passwords.

      3. Passwords must be at least twelve characters and contain upper case letters, lower case letters, numbers, and special characters.

      4. Commonly used words, names, initials, birthdays, or phone numbers should not be used as passwords.

      5. A password must be promptly changed if it is suspected of being disclosed, or known to have been disclosed.

      6. Passwords must not be disclosed to other workforce members (including anyone claiming to need a password to ā€œfixā€ a computer or handle an emergency situation) or individuals, including family members.

      7. Passwords must not be written down, posted, or exposed in an insecure manner such as on a notepad or posted on the workstation.

      8. Employees should refuse all offers by software and/or Internet sites to automatically login the next time that they access those resources.

      9. Any employee who is directed by the ISO to change his/her password to conform to the aforementioned standards shall do so immediately.

17. Security Management Process

Statement of Policy

To ensure Flink conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of sensitive information held by Flink.

Flink shall conduct an accurate and thorough risk analysis to serve as the basis for Flink compliance efforts. Flink shall re-assess the security risks to its sensitive information and evaluate the effectiveness of its security measures and safeguards as necessary in light of changes to business practices and technological advancements.

Procedure

  1. The ISO shall be responsible for coordinating Flink’ risk analysis. The ISO shall identify appropriate persons within the organization to assist with the risk analysis.
    ​

  2. The risk analysis shall proceed in the following manner:

    1. Document Flink current information systems.

      1. Update/develop information systems inventory. List the following information for all hardware (i.e., network devices, workstations, printers, scanners, mobile devices) and software (i.e., operating system, various applications): date acquired, location, vendor, licenses, maintenance schedule, and function. Update/develop network diagram illustrating how organization’s information system network is configured.
        ​

      2. For each application identified, identify each licensee (i.e., authorized user) by job title and describe the manner in which authorization is granted.
        ​

      3. For each application identified:

        1. Describe the data associated with that application.

        2. Determine whether the data is created by the organization or received from a third party. If data is received from a third party, identify that party and the purpose and manner of receipt.

        3. Determine whether the data is maintained within the organization only or transmitted to third parties. If data is transmitted to a third party, identify that party and the purpose and manner of transmission.

        4. Define the criticality of the application and related data as high, medium, or low. Criticality is the degree of impact on the organization if the application and/or related data were unavailable for a period of time.

        5. Define the sensitivity of the data as high, medium, or low. Sensitivity is the nature of the data and the harm that could result from a breach of confidentiality or security incident.

        6. For each application identified, identify the various security controls currently in place and locate any written policies and procedures relating to such controls.
          ​

      4. Identify and document threats to the confidentiality, integrity, and availability (referred to as ā€œthreat agentsā€) of sensitive information created, received, maintained, or transmitted by Flink. Consider the following:

        1. Natural threats, e.g., earthquakes, storm damage.

        2. Environmental threats, e.g., fire and smoke damage, power outage, utility problems.

        3. Human threats

          1. Accidental acts, e.g., input errors and omissions, faulty application programming or processing procedures, failure to update/upgrade software/security devices, lack of adequate financial and human resources to support necessary security controls

          2. Inappropriate activities, e.g., inappropriate conduct, abuse of privileges or rights, workplace violence, waste of corporate assets, harassment

          3. Illegal operations and intentional attacks, e.g., eavesdropping, snooping, fraud, theft, vandalism, sabotage, blackmail

          4. External attacks, e.g., malicious cracking, scanning, demon dialing, virus introduction

        4. Identify and document vulnerabilities in Flink information systems. A vulnerability is a flaw or weakness in security policies and procedures, design, implementation, or controls that could be accidentally triggered or intentionally exploited, resulting in unauthorized access to PII, modification of PII, denial of service, or repudiation (i.e., the inability to identify the source and hold some person accountable for an action). To accomplish this task, conduct a self-analysis utilizing the standards and implementation specifications to identify vulnerabilities.
          ​

      5. Determine and document probability and criticality of identified risks.

        1. Assign probability level, i.e., likelihood of a security incident involving identified risk.

          1. "Very Likely" (3) is defined as having a probable chance of occurrence.

          2. "Likely" (2) is defined as having a significant chance of occurrence.

          3. "Not Likely" (1) is defined as a modest or insignificant chance of occurrence.

        2. Assign criticality level.

          1. "High" (3) is defined as having a catastrophic impact on the medical practice including a significant number of medical records which may have been lost or compromised.

          2. "Medium" (2) is defined as having a significant impact including a moderate number of medical records within the practice which may have been lost or compromised.

          3. "Low" (1) is defined as a modest or insignificant impact including the loss or compromise of some medical records.

        3. Determine risk score for each identified risk. Multiply the probability score and criticality score. Those risks with a higher risk score require more immediate attention.
          ​

      6. Identify and document appropriate security measures and safeguards to address key vulnerabilities. To accomplish this task, review the vulnerabilities you have identified in relation to the standards and implementation specifications. Focus on those vulnerabilities with high risk scores, as well as specific security measures and safeguards required by the Security Rule.
        ​

      7. Develop and document an implementation strategy for critical security measures and safeguards.

        1. Determine timeline for implementation.

        2. Determine costs of such measures and safeguards and secure funding.

        3. Assign responsibility for implementing specific measures and safeguards to appropriate person(s).

        4. Make necessary adjustments based on implementation experiences.

        5. Document actual completion dates.
          ​

      8. Evaluate effectiveness of measures and safeguards following implementation and make appropriate adjustments.
        ​
        ​

  3. The ISO shall be responsible for identifying appropriate times to conduct follow-up evaluations and coordinating such evaluations. The ISO shall identify appropriate persons within the organization to assist with such evaluations. Follow-up evaluations shall include the following:

    1. Inspections, reviews, interviews, and analysis to assess adequacy of administrative and physical safeguards. Such evaluation shall include interviews to assess employee compliance; after-hours walk-through inspections to assess physical security, password protection (i.e., not posted), and workstation sessions terminated (i.e., employees logged out); review of latest security policies and procedures for correctness and completeness; and inspection and analysis of training, incident, and media logs for compliance

    2. Analysis to assess adequacy of controls within the network, operating systems and applications. As appropriate, Flink shall engage outside vendors to evaluate existing physical and technical security measures and make recommendations for improvement
      ​

18. Emergency Access ā€œBreak the Glassā€

Policy Summary

Flink has formal, documented emergency access procedures enabling authorized workforce members to obtain required information during an emergency. Flink has a formal, documented emergency access procedure enabling Flink workforce members to access the minimum information necessary to effectively and efficiently resume business operations in the event of a major emergency. Read this policy for more information.

Purpose

This policy reflects Flink’s commitment to have emergency access procedures enabling authorized workforce members to obtain required information during an emergency. Examples: Access to GSuite, Bitbucket, GCP resources.

Definitions

Electronic media means:

  1. Electronic storage media including memory devices in computers (hard drives) and any removable/transportable digital memory medium, such as magnetic tape or disk, optical disk, or digital memory card; or

  2. Transmission media used to exchange information already in electronic storage media. Transmission media include, for example, the internet, extranet (using internet technology to link a business with information accessible only to collaborating parties), leased lines, dial-up lines, private networks, and the physical movement of removable/transportable electronic storage media. Certain transmissions, including of paper, via facsimile, and of voice, via telephone, are not considered to be transmissions via electronic media, because the information being exchanged did not exist in electronic form before the transmission.

Information system means an interconnected set of information resources under the same direct management control that shares common functionality. A system normally includes hardware, software, information, data, applications, communications, and people.

Workforce member means employees, volunteers, and other persons whose conduct, in the performance of work for a covered entity, is under the direct control of such entity, whether or not they are paid by the covered entity. This includes full and part time employees, affiliates, associates, volunteers, and staff from third party entities who provide service to the covered entity.

Policy

  1. Flink has formal, documented emergency access procedures enabling authorized workforce members to obtain required IT access during an emergency. The procedure includes:

    1. Identifying and defining which Flink workforce members authorized to access the IT system during an emergency.

    2. Identifying and defining manual and automated methods to be used by authorized Flink workforce members to access IT systems during a data emergency.

    3. Identify and define appropriate logging and auditing that must occur when authorized Flink workforce members access the IT system during an emergency.

  2. Flink has a formal, documented emergency access procedure enabling Flink workforce members to access the minimum IT system resources necessary for emergency business operations in the event of an emergency. Such access must be authorized by appropriate Flink management or designated personnel.

  3. Regular training and awareness on the emergency access procedure is provided to all Flink workforce members.

  4. All appropriate Flink workforce members have access to a current copy of the procedure and an appropriate number of current copies of the procedure should be kept off-site.

Scope/Applicability

This policy is applicable to all divisions and workforce members that use or disclose electronic protected information for any purposes. This policy’s scope includes all electronic protected information, as described in definitions below.
​
​

Scenario

ā€œBreak the Glassā€ refers to Flink enabling a licensed practitioner to view a sensitive data record, or a portion thereof, under emergency circumstances, when that practitioner does not have the necessary system access privileges.


​Policy Authority/Enforcement

Flink’ ISO is responsible for monitoring and enforcing this policy.

Procedures

Mechanism to Provide Emergency Access to IT systems

  1. This process will bypass formal access procedures and is limited to emergencies.

  2. The CEO, CIO, ISO, or department head may make requests for emergency access in writing.

  3. The request should contain:

    1. The individual being granted the emergency access,

    2. Job title

    3. Reason for emergency access

    4. Date and time granted access

    5. The name of the individual granting access.

  4. The ISO, or designated person, records information about emergency users and the emergency access rights assigned to them.

  5. The system administrator and ISO have created a single administrator account named flink ninja specifically for emergency access. This account is securely stored, and its use is carefully monitored to ensure it is only accessed in critical situations.

  6. The emergency access will be tracked and documented based on capabilities of the IT system. The tracking documentation will be reviewed by the ISO to determine that emergency access was appropriate.

  7. At the conclusion of the event that precipitated the granting of emergency access, the ISO ensures the break glass accounts are disabled, and new ones created in anticipation of the next emergency.

  8. Any inappropriate use of emergency access will be treated as a security incident, and may subject an employee to disciplinary action, up to and including termination.

  9. Documentation concerning emergency access will be retained and maintained for at least six years from the date of creation.

Note:

When using a specific user account that provides full access to all IT systems (an administrator account) consider the following:

  • Creating an extremely complicated password (but one an employee will be able to enter while under the stress of an emergency situation).

  • Securing the password.

  • Periodically changing the password.

Enforcement

Please refer to Sanction Policy for details regarding disciplinary action against employees, contractors, or any individuals who violate this policy.

19. Sanction Policy

Policy

It is the policy of Flink that all workforce members must protect the confidentiality, integrity, and availability of sensitive information at all times. Flink will impose sanctions, as described below, on any individual who accesses, uses, or discloses sensitive information without proper authorization.

Flink will take appropriate disciplinary action against employees, contractors, or any individuals who violate Flink’ information security and privacy policies.

Purpose

To ensure that there are appropriate sanctions that will be applied to workforce members who violate the requirements of Flink’ security policies.

Definitions

Workforce member means employees, volunteers, and other persons whose conduct, in the performance of work for a covered entity, is under the direct control of such entity, whether or not they are paid by the covered entity. This includes full and part time employees, affiliates, associates, volunteers, and staff from third party entities who provide service to the covered entity.

Sensitive information, includes, but not limited to, the following:

  • Sensitive Information – Individually identifiable personal information that is in any form or media, whether electronic or paper.

  • Personnel files – Any information related to the hiring and/or employment of any individual who is or was employed by Flink.

  • Payroll data – Any information related to the compensation of an individual during that individuals’ employment with Flink.

  • Financial/accounting records – Any records related to the accounting practices or financial statements of Flink.

  • Other information that is confidential – Any other information that is sensitive in nature or considered to be confidential.

Availability refers to data or information that is accessible and usable upon demand by an authorized person.

Confidentiality refers to data or information that is not made available or disclosed to unauthorized persons or processes.

Integrity refers to data or information that has not been altered or destroyed in an unauthorized manner.
​
​

Violations

Listed below are the types of violations that require sanctions to be applied. They are stated at levels 1, 2, and 3 depending on the seriousness of the violation.

Level

Description of Violation

1

  • Accessing information that you do not need to know to do your job.

  • Sharing computer access codes (username & password).

  • Leaving the computer unattended while being able to access sensitive information.

  • Disclosing sensitive information with unauthorized persons.

  • Copying sensitive information without authorization.

  • Changing sensitive information without authorization.

  • Discussing sensitive information in a public area or in an area where the public could overhear the conversation.

  • Discussing sensitive information with an unauthorized person.

  • Failing/refusing to cooperate with the ISO and/or authorized designee.

2

  • Second occurrence of any Level 1 offense (does not have to be the same offense).

  • Unauthorized use or disclosure of sensitive information.

  • Using another person's computer access code (username & password).

  • Failing/refusing to comply with a remediation resolution or recommendation.

3

  • Third occurrence of any Level 1 offense (does not have to be the same offense).

  • Second occurrence of any Level 2 offense (does not have to be the same offense).

  • Obtaining sensitive information under false pretenses.

  • Using and/or disclosing sensitive information for commercial advantage, personal gain, or malicious harm.


​Recommended Disciplinary Actions

In the event that a workforce member violates Flink’ privacy and security policies or related state laws governing the protection of sensitive and personal identifiable information, the following recommended disciplinary actions will apply.

Violation Level

Recommended Disciplinary Action

1

  • Verbal or written reprimand

  • Retraining on privacy/security awareness

  • Retraining on Flink privacy and security policies

  • Retraining on the proper use of internal or required forms

2

  • Letter of Reprimand; or suspension

  • Retraining on privacy/security awareness

  • Retraining on Flink privacy and security policies

  • Retraining on the proper use of internal or required forms

3

  • Termination of employment or contract

  • Civil penalties applicable Local law

  • Criminal penalties as provided under Local law

Important Note: The recommended disciplinary actions are identified in order to provide guidance in policy enforcement and are not meant to be all-inclusive. If formal discipline is deemed necessary, Flink shall consult with Human Resources prior to taking action. When appropriate, progressive disciplinary action steps shall be followed allowing the employee to correct the behavior which caused the disciplinary action.

20. Incident Response & Breach Notification Procedures

Purpose

To outline the process for notifying affected individuals of a breach of sensitive information.

Scope

This applies to all employees, volunteers, and other individuals working under contractual agreements with Flink.

Definitions

State Breach – Unauthorized acquisition or reasonable belief of unauthorized acquisition of Personal Information that compromises the security, confidentiality, or integrity of the Personal Information.

Personal Information – Personal Information has many definitions including definitions by statute which may vary from state to state. Most generally, Personal Information is a combination of data elements which could uniquely identify an individual. Please review applicable state data breach statutes to determine what definition of Personal Information is applicable for purposes of the document.

Personal Data Breach – Unauthorized acquisition, access, use, or disclosure of unsecured PII.

Personally Identifiable Information (PII) – Information in any form that consists of a combination of an individual’s name and one or more of the following: email address, Social Security Number, driver’s license or state ID, account numbers, credit card numbers, debit card numbers, personal code, security code, password, personal ID number, photograph, fingerprint, or other information which could be used to identify an individual.

GDPR Breach – Unauthorized acquisition or reasonable belief of unauthorized acquisition of personal information protected by GDPR. This information includes, but is not limited to, government issued ID numbers, financial account numbers or other information posing a risk of identity theft.

Private Information – Information protected by GDPR, Personally Identifiable Information, Personal Information and Protected Information collectively.

Procedure

Reporting a Possible Breach

  1. Any employee who becomes aware of a possible breach of privacy involving Private Information in the custody or control of Flink will immediately inform their supervisor/manager, and the ISO.
    ​

  2. Notification should occur immediately upon discovery of a possible breach or before the end of your shift if other duties interfere, however, in no case should notification occur later than twenty-four (24) hours after discovery.

    1. The supervisor/manager will verify the circumstances of the possible breach and inform the ISO within twenty-four (24) hours of the initial report.
      ​

  3. You may contact the ISO directly..

    1. Provide the ISO with as much detail as possible.

    2. Be responsive to requests for additional information from the ISO.

    3. Be aware that the ISO has an obligation to follow up on any reasonable belief that Private Information has been compromised.

  4. The ISO, in conjunction with Flink’ Legal Counsel, will decide whether or not to notify the President/CEO as appropriate by taking into consideration the seriousness and scope of the breach.

Containing the Breach

  1. The ISO will take the following steps to limit the scope and effect of the breach.

    1. Work with the department(s) to immediately contain the breach. Examples include, but are not limited to:

      1. Stopping the unauthorized practice

      2. Recovering the records, if possible

      3. Shutting down the system that was breached

      4. Mitigating the breach, if possible

      5. Correcting weaknesses in security practices

      6. Notifying the appropriate authorities including the local Police Department if the breach involves, or may involve, any criminal activity

Investigating and Evaluating the Risks Associated with the Breach

  1. To determine what other steps are immediately necessary, the ISO in collaboration with Flink’ Legal Counsel and affected department(s) and administration, will investigate the circumstances of the breach.

    1. A team will review the results of the investigation to determine root cause(es), evaluate risks, and develop a resolution plan.

      1. The Privacy Breach Assessment tool will help aid the investigation.

    2. The ISO, in collaboration with Flink’ Legal Counsel, will consider several factors in determining whether to notify individuals affected by the breach including, but not limited to:

      1. Contractual obligations

      2. Legal obligations – Flink’ Legal Counsel should complete a separate legal assessment of the potential breach and provide the results of the assessment to the ISO and the rest of the breach response team. For more information please refer to this policy.

      3. Risk of identity theft or fraud because of the type of information lost such as social security number, banking information, identification numbers

      4. Risk of physical harm if the loss puts an individual at risk of stalking or harassment

      5. Number of individuals affected

Notification

  1. The ISO will work with the department(s) involved, Flink’ Legal Counsel and appropriate leadership to decide the best approach for notification and to determine what may be required by law.
    ​

  2. If required by law, notification of individuals affected by the breach will occur as soon as possible following the breach.

    1. Affected individuals must be notified without reasonable delay

      1. Notices must be in plain language and include basic information, including:

        1. What happened

        2. Types of sensitive information involved

        3. Steps individuals should take

        4. Steps covered entity is taking

        5. Contact Information

      2. Notices should be sent by email. If insufficient or out-of-date contact information is available, then a substitute notice is required as specified below.

    2. If law enforcement authorities have been contacted, those authorities will assist in determining whether notification may be delayed in order not to impede a criminal investigation.
      ​

  3. The required elements of notification vary depending on the type of breach and which law is implied. As a result, Flink' ISO and Legal Counsel should work closely to draft any notification that is distributed.
    ​

  4. Indirect notification such as website information, posted notices, media will generally occur only where direct notification could cause further harm, or contact information is lacking.

    1. If a breach affects five-hundred (500) or more individuals, or contact information is insufficient, Flink will notify a prominent media outlet that is appropriate for the size of the location with affected individuals, and notice will be provided in the form of a press release.
      ​

  5. Using multiple methods of notification in certain cases may be the most effective approach.


​Business associates must notify Flink if they incur or discover a breach of unsecured PII

  1. Notices must be provided without reasonable delay and in no case later than sixty (60) days after discovery of the breach.

  2. Business associates must cooperate with Flink in investigating and mitigating the breach.

Prevention

  1. Once immediate steps are taken to mitigate the risks associated with the breach, the ISO will investigate the cause of the breach.

    1. If necessary, this will include a security audit of physical, organizational, and technological measures.

    2. This may also include a review of any mitigating steps taken.

  2. The ISO will assist the responsible department to put into effect adequate safeguards against further breaches.

  3. Procedures will be reviewed and updated to reflect the lessons learned from the investigation and regularly thereafter.

  4. The resulting plan will also include audit recommendations, if appropriate.

Compliance and Enforcement

All managers and supervisors are responsible for enforcing these procedures. Employees who violate these procedures are subject to discipline up to and including termination in accordance with Flink' Sanction Policy.

Related Policies

Sanction Policy

Did this answer your question?