IT Policy

(A pdf copy of this policy (Including Internet and Email) For Employees & Councillors Of Camelford Town Council is available for download here.)

Introduction

Data security is an ever-increasing risk for most organisations including councils. However, the number of breaches which are the result of highly sophisticated attacks from hackers is still very limited; most breaches are still the result of human error or relatively unsophisticated phishing attacks.

This IT security policy helps Camelford Town Council (CTC) to:

  • Meet our legal obligations under the General Data Protection Regulation and other laws
  • Reduce the risk of IT problems
  • Plan for problems and deal with them when they happen
  • Keep working if something does go wrong
  • Protect Council and employee data
  • Keep valuable Council information
  • Ensure proper use of CTC’s internet and email system

Responsibilities

  • Town Clerk is responsibility for the IT security strategy
  • Deputy Town Clerk has operational responsibility for implementing this policy
  • Cloudy IT is the IT partner organisation CTC use to help with our IT support
  • SeaDog IT – website support
  • Andy Lawler, Yetiserve – alarms/CCTV
  • Town Clerk is the Data Protection Officer to advise on data protection laws and best practices

Review Process

CTC will review this policy bi-annually

Information Asset Classification

CTC will only classify information assets which are necessary for the completion of our duties. CTC will also limit access to personal data to only those that need it for processing. In most cases, this will be the Clerk and Deputy Town Clerk.

Information AssetClassification
Employee information (name, address, contact numbers, pay, sick records etc)Employee Confidential
Councillor information (name, address, contact numbers)Unclassified – information is public
Council confidential (Part 2 paperwork – e.g. quotes, tenders, Code of Conduct investigations)Council Confidential
Allotment tenant information (name, address and contact numbers)Resident Confidential

The deliberate or accidental disclosure of any confidential information has the potential to harm the Council. This policy is designed to minimise the risk.

Access Controls

Internally, as far as possible, CTC operate on a “need to share” rather than a “need to know” basis with respect to Council confidential information. This means that our bias and intention is to share information to help people do their jobs rather than raise barriers to access needlessly.

CTC operate in compliance with the GDPR “Right to Access”. This is the right of data subjects to obtain confirmation as to whether CTC are processing their data, where CTC are processing it, and for what purpose. Further, CTC shall provide, upon request, a copy of their personal data, free of charge in an electronic format.

The office of the Town Clerk and Deputy Town Clerk is secured by a door entry system. The code is only known by the Town Clerk, Deputy Town Clerk, the Library/Administration Assistant and Andy Lawler (Yetiserve). Physical files are stored within the office of the Town Clerk and Deputy Town Clerk, and this door is also secured by a door entry system. The code is only known by the Town Clerk, Deputy Town Clerk, the Library Administrator and Andy Lawler (Yetiserve). To protect confidential information, CTC implement the following access controls:

Employee ConfidentialTown Clerk, Deputy Town ClerkPassword protected computers “Staffing folder” on network has security restrictions
Council ConfidentialTown Clerk, Deputy Town Clerk, MayorPassword protected computers
Resident Confidential (Allotment Tenenets)Deputy Town Clerk, Library/Administration AssistantPassword protected computers

Security Software

To protect our data, system and users, CTC use the following systems: Laptop and desktop anti-malware/firewall (Websecure Premium).

Our website is hosted on servers in the UK at a secure data centre within a secure compound with razor-wire fences, 24hr security personnel, CCTC throughout and 24/7 technicians on site. Our server is kept separate from everyone else. Web Application Firewall (WAF) is always on, protecting our website with our application-specific security shield to help guard against exploits.

In addition, we have installed a premium WordPress plugin that provides a wide range of security features such as:

  • Brute Force Attach prevention to lock out any attempts to brute-force guess our WordPress password 5
  • Real Time Threat defence feed – protection from the latest threats, delivered as they emerge. This provides our Firewall and Scan Engine with updated firewall rules, the latest malware signature, malicious IP updates.
  • Malware Scanner – Scan for Malware, Bad URLs, Backdoors and DNS changes.

Where Information is Stored

All documents used by the Clerk and Deputy Clerk are stored on Sharepoint: Council Data/Documents. The Clerk and Deputy Clerk have access to all files. Each computer is password protected.

Email

The Council currently use Office 365 Business Premium. All Councillors have a “Camelford-tc.gov.uk” email. This is in line with GDPR requirements.

Requirements for use The following rules MUST be adhered to by all users within CTC. It is prohibited to:

  1. Send or forward emails containing libellous, defamatory, offensive, racist or obscene remarks. If employees receive an email of this sort, they must notify their Line Manager who will pass this to the Clerk if appropriate.
  2. Forward a sensitive or controversial message without acquiring permission from the sender first.
  3. Forge or attempt to forge email messages.
  4. Disguise or attempt to disguise the employee’s identity when sending mail.
  5. Send email messages using another person’s email address without permission.
  6. Copy a confidential message or attachment belonging to another user without permission of the originator.

Personal use of Internet and email – Councillors and Staff

Because CTC has access to broadband technology, usage is at a flat rate regardless of numbers of emails sent or minutes online. As a result, the organisation permits employees to use their PCs to access the internet and send/receive email for personal/developmental use where necessary.

Employees wishing to use internet/email access for personal/developmental are deemed to have agreed to the following terms and conditions:

  1. This permission only applies to times OUTSIDE recorded working hours.
  2. Personal emails should be clearly marked as such in the subject line.
  3. Unless employees have specific prior permission from the Clerk, they should not give their work email address as one of their contact details for regular extracurricular/social/voluntary commitments outside work.
  4. Do NOT use a work email address for any non-work communication if there is any possibility that the recipient will be influenced (either positively or negatively) by receiving a communication from a staff member of CTC.
  5. To avoid cluttering the system with unwanted adverts or other material, please do not sign up for personal direct mail using a work email address. For example, if employees have used the internet (in their own time) to buy goods or services, and are invited to subscribe to ‘news of other products’ please click ‘no’ or provide a home email address as the point of contact.
  6. When sending personal emails, employees should show the same care as when sending work-related emails.
  7. Jokes or humorous articles are often received from individuals outside the organisation. Users must consider whether anyone is likely to take offence if you pass material on. Passing on offensive material via the work system is a disciplinary matter and may result in legal action or termination of employment. If any doubt, don’t do it! Abuse of this permission will be regarded as a disciplinary offence and will be subject to action laid out in the policies on code of conduct and elsewhere. Abuse of Internet/email access could include, but is not limited to:
  8. Accessing inappropriate web sites;

i. Downloading or distributing obscene, offensive, or indecent material;
ii. Using language or behaviour likely to bring CTC into disrepute;
iii. Using CTC’s official role/status for personal gain;
iv. Using CTC’s role/status to support a specific political or issue-based campaign;
v. Using the equipment to contribute to fraud; and
vi. Using or passing on privileged or confidential information. The personal use of email or Internet access must be completely in accordance with the range of provisions in the current Code of Conduct.

Legal Risks

Email is a business communication tool and users are obliged to use this tool in a responsible, effective and lawful manner. While email seems to be less formal than other written communication, the same laws and guidelines apply. Users should be aware of the legal risks of
email:

If employees send or forward emails with any libellous, defamatory, offensive, racist or obscene remarks, both employee and CTC can be held liable. In addition, it may be considered to have been an infringement of the disciplinary procedure.

If employees unlawfully forward confidential information, the employee and CTC can be held liable.

If employees unlawfully forward or copy messages without permission, the employee and CTC can be held liable for copyright infringement.

If the employee knowingly send an attachment that contains a virus, the employee and CTC can be held liable. Please follow the guidelines in this policy to minimise the legal risks to employees and CTC. If any user disregards the rules set out in this policy, the user will be fully liable and CTC will disassociate itself from the user as far as legally possible.

Before forwarding any emails, you should inform the originator to whom you intend to forward the email and for what purpose. If the email has been sent by a resident who would like to have the email included in correspondence at the next meeting, you should inform the resident that the email will be sent to all Councillors and will be in the public domain. The email address will be redacted and the sender should be advised of this.

Should any member of staff or Councillor receive a suspicious email, they should advise the Town Clerk immediately and are advised not to open the email or attachments.

Electronic Signature and Disclaimer

Employees must ensure that their electronic signature is set up in the following format to appear on outgoing emails:

Name
Job Title
Telephone number
Details of working hours (if part-time)

Employees/Councillors Joining and Leaving

When a new employee joins CTC, CTC will add them to our secure email system. Town Clerk and Deputy Town clerk roles will also have full access to the Public Documents files. New Councillors will be added to our secure email system.

CTC will provide training to new employees and support for existing staff to implement this policy.

This includes an initial introduction to IT security, covering the risks, basic security measures, CTC policies and where to get help.

Employee and Councillor responsibilities

Effective security is a team effort requiring the participation and support of every employee and Councillor. It is the responsibility of employees and Councillors to know and follow these guidelines. Individuals are personally responsible for the secure handling of confidential information that is entrusted to them. They may access, use or share confidential information (e.g. Part 2 paperwork, personal information) only to the extent it is authorised and necessary for the proper performance of their duties. Individuals are responsible for prompt reporting of any theft, loss, unauthorised disclosure of protected information or any breach of this policy to the Town Clerk.

Protecting your own device(s)

It is also your responsibility to use your personal devices (computer, phone tablet etc.) in a secure way. However, CTC will provide training and support to enable you to do so (see below). At a minimum:

  • Remove software that you do not use or need from your computer.
  • Update your operating system and applications regularly.
  • Keep your computer firewall/antivirus switched on.
  • Store files in Council storage locations (Council Data) so that is backed up properly and available in an emergency. For those Councillors using personal computers/laptops, CTC advise that you password protect your Council correspondence.
  • Understand the privacy and security settings on your phone and social media accounts.
  • Have separate user accounts for other people, including other family members, if they use your computer. Ideally, keep your work separate from any family or shared computers.
  • Make sure your computer and phone logs out automatically after 15 minutes and requires a password to log back in.
  • If you need to go away from your desk, log out.

Downloading and Importing Files and Software

Employees must download files only onto those PCs with virus checking software and should check how long downloads will take. If in doubt, employees should check with their Line Manager.

Employees must exercise extreme care when receiving emails with attachments from third parties – particularly unidentified third parties – as these may contain viruses. Data from memory sticks, CDs, and other external devices must only be viewed on PCs with appropriate virus checking software. If in any doubt about whether it is safe and permissable to use these devices, employees should ask their line manager

Public Wifi

A public Wi-Fi does not necessarily provide a secure connection to the internet. Risks include:

Man in the Middle attacks

One of the most common threats on these networks is called a Man in the Middle (MitM) attack. Essentially, a MitM attack is a form of eavesdropping. When a computer makes a connection to the Internet, data is sent from point A (computer) to point B (service/website), and vulnerabilities can allow an attacker to get in between these transmissions and “read” them. So what you thought was private no longer is.

Unencrypted networks

Encryption means that the messages that are sent between your computer and the wireless router are in the form of a “secret code,” so that they cannot be read by anyone who doesn’t have the key to decipher the code. Most routers are shipped from the factory with encryption turned off by default, and it must be turned on when the network is set up. If an IT professional sets up the network, then chances are good that encryption has been enabled. However, there is no surefire way to tell if this has happened.

Malware distribution

Thanks to software vulnerabilities, there are also ways that attackers can slip malware onto your computer without you even knowing. A software vulnerability is a security hole or weakness found in an operating system or software program. Hackers can exploit this weakness by writing code to target a specific vulnerability, and then inject the malware onto your device.

Snooping and sniffing

Wi-Fi snooping and sniffing is what it sounds like. Cybercriminals can buy special software kits and even devices to help assist them with eavesdropping on Wi-Fi signals. This technique can allow the attackers to access everything that you are doing online — from viewing whole webpages you have visited (including any information you may have filled out while visiting that webpage) to being able to capture your login credentials, and even being able to hijack your accounts.

Malicious hotspots

These “rogue access points” trick victims into connecting to what they think is a legitimate networknbecause the name sounds reputable. Say you’re staying at the Camelford Inn and want to connect to the hotel’s Wi-Fi. You may think you’re selecting the correct one when you click on “Cam Inn,” but you haven’t. Instead, you’ve just connected to a rogue hotspot set up by cybercriminals who can now view your sensitive information.

How to stay safe on public Wi-Fi

The best way to know your information is safe while using public Wi-Fi is to use a virtual private network (VPN), like Norton WiFi Privacy, when surfing on your PC, Mac, smartphone or tablet. However, if you must use public Wi-Fi, follow these tips to protect your information.

Don’t:

  • Allow your Wi-Fi to auto-connect to networks
  • Log into any account via an app that contains sensitive information. Go to the website instead and verify they are using HTTPS before logging in
  • Leave your Wi-Fi or Bluetooth on if you are not using them
  • Access websites that hold your sensitive information, such as such as financial or healthcare accounts
  • Log onto a network that isn’t password protected

Do:

  • Disable file sharing
  • Only visit sites using HTTPS
  • Log out of accounts when done using them
  • Use a VPN, like Norton WiFi Privacy, to make sure your public Wi-Fi connections are made private Camelford Town Council/Cornwall Council Wifi

CTC have wifi which is secured, as well as Cornwall Council wifi for library users. These are both secure and regularly tested.

Password Guidelines

  • Change default passwords on computers, phones and all network devices regularly
  • Don’t share your password with other people.
  • Don’t write down passwords next to computers and phones
  • Use strong passwords

Don’t use the same password for multiple critical systems

Be Alert to other security risks

  • While technology can prevent many security incidents, your actions and habits are also important.
  • Use extreme caution when opening email attachments from unknown senders or unexpected attachments from any sender.
  • Be on guard against social engineering, such as attempts by outsiders to persuade you to disclose confidential information, including employee or Council confidential information.
  • Be wary of fake websites and phishing emails. Don’t click on links in emails or social media.
  • Use social media, including personal blogs, in a professional and responsible way, without violating Council policies or disclosing confidential information.
  • Take particular care of your computer and mobile devices when you are away from home or out of the office.
  • If you leave the Council, you will return any Council property, and delete all confidential information from your computer as soon as is practicable. Your email address will automatically be deleted.
  • Where confidential information is stored on paper, it should be kept in a secure place where unauthorised people cannot see it and shredded or put in the confidential waste when no longer required.

Backup, disaster recovery and continuity

Backups are performed live; so, each time a document is edited and saved, it is automatically backed up 3 times a day. Backups are stored on the Cloud.

In the event of an office system recovery needed, you should contact either the Town Clerk or Deputy Clerk who will contact Cloudy IT immediately. For library systems, you should contact Cornwall Council.

Under the GDPR, where a data breach is likely to result in a “risk for the rights and freedoms ofindividuals” CTC must notify the persons affected and the Town Clerk “without undue delay”. CTCwill ensure any breach is reported to the Information Commissioners Office (ICO) within 72 hours.

Inventory of Hardware and Software Used

  • 2 x HP 20-C010na 19.5 All in one computers
  • Office 365 Premium
  • WebSecure Premium (Cloudy IT)
  • Enterprise Mobility and Security E5 (Cloudy IT)
  • Scribe Accounts
  • Flash drive
  • Laptop ASUS
  • Laptop – Deputy Town Clerk
  • 3 x Laptops (Cllrs Scawn, Grigg and Elford)
  • Declaration

The personal use of email or Internet access must be completely in accordance with the range ofprovisions in the current Code of Conduct. I have read and understood CTC’s IT policy and recognise that to misuse it would be regarded as a disciplinary offence, potentially gross misconduct.

I am content to abide by this policy.