Dear all,
The revised UOBT IT Security Policy (version 2.1) was concurred by RCC on 20 Nov 2014 and approved by EXCO on 2 Feb 2015. The revised Policy will supersede the current version with immediate effect.
Compliance with the IT Security Policy applies to every employee, whether on permanent or temporary basis, who uses the Bank’s IT assets. Where there is a need for service providers or third parties to make use of the Bank’s IT assets, the business / support unit authorizing such use must ensure that relevant security policies are made known to them for compliance.
Key changes include the following:
1. New section on End-User Computing (2.10)
2. New section on Cloud Computing (3.5.10 – 3.5.11)
3. Added Threat and Vulnerability Risk Assessment requirement for Data Centre (3.6.10)
4. The prohibition of test data in Production and Disaster Recovery environments (4.2.15)
5. New sections on availability (7.7.5) and recovery (7.9.21) of Critical Systems, notification and reporting of Critical System incidents (7.10.6).
6. Added ORMC authority to approve the deviations from IT Security Policy (1.3.6)
Please disseminate it to your staff for their information and compliance. Security is only as strong as its weakest link. We urge all staff to be security-aware and consciously ensure that all business processes are carried out in a secure manner.
A copy of the updated Policy can be found at http://intranet.uob.co.th/LinkClick.aspx?fileticket=%2fwadyNOXCW8%3d&tabid=3513&mid=4615
Please contact me (Tel: 02-343-2501) should you have any queries on the Policy.