Information Security Standards


SCO Facilities and Physical Property


Download 377.5 Kb.
bet5/16
Sana02.01.2022
Hajmi377.5 Kb.
#200822
1   2   3   4   5   6   7   8   9   ...   16
Bog'liq
isp manual

SCO Facilities and Physical Property


This manual’s contents are applicable to all SCO owned or leased facilities and physical property entrusted to the SCO.

The Principles of Due Care & Due Diligence


The need for the SCO to keep pace with the ever-changing statutory landscape and technology environment is essential in maintaining information security and business viability. Due care and due diligence practices must be ingrained into the SCO’s culture in order to facilitate the constant self re-evaluation and assessment necessary for statutory and technology industry best practices compliance validation and to initiate necessary changes and seek enhancement opportunities.

The terms “due care” and “due diligence” are used in the fields of finance, securities, and law. These terms describe the “reasonable and prudent person” rule. A prudent person takes due care to insure that everything necessary is done to operate the business by sound business principles and in a legal ethical manner. A prudent person is also diligent (i.e., mindful, attentive, and ongoing) in their due care of the business. In the business world, stockholders, customers, business partners, and government regulators have the expectation that corporate officers will run the business in accordance with accepted business practices and in compliance with laws and other regulatory requirements. In the public sector, constituents and political leaders hold the same expectations of government agency officers. In addition to these expectations being a motivating force for officers, Federal Sentencing Guidelines and State Statutes now make it possible to hold both private and public sector organization officers liable for failing to exercise due care and due diligence in the management of their information privacy/security practices.

The importance of demonstrating “due care” and “due diligence” cannot be expressed enough in government. “Due care” and “due diligence” activities are the foundation for establishing and maintaining the trust of constituents. The SCO Information Security Program Standards Manual’s content aligns with industry standards and complies with statutory and administrative requirements are “due care” and “due diligence” activities.


Download 377.5 Kb.

Do'stlaringiz bilan baham:
1   2   3   4   5   6   7   8   9   ...   16




Ma'lumotlar bazasi mualliflik huquqi bilan himoyalangan ©fayllar.org 2024
ma'muriyatiga murojaat qiling