Difference between revisions of "Internal:Technology access policy amendment"

From Wikimedia District of Columbia
Jump to navigation Jump to search
(Tag)
(copyedits)
Line 4: Line 4:
   
 
2. <u>Standards for Tools</u>. Any tool used by the Corporation to collect or store Sensitive PII ("Sensitive PII Tool") shall adhere to the following standards:
 
2. <u>Standards for Tools</u>. Any tool used by the Corporation to collect or store Sensitive PII ("Sensitive PII Tool") shall adhere to the following standards:
: (a) <u>Individual Access</u>. Access shall only be allocated to individual user accounts, with no shared accounts used. Exceptions may be made for specific tools where the President determines that no feasible alternative exists.
+
: (a) <u>Individual Access</u>. Access shall be allocated to individual user accounts, not accounts shared among individuals. The President may make exceptions for specific tools if the President determines that no feasible alternative exists.
 
: (b) <u>HTTP Connection</u>. Web-based tools shall only be accessed over HTTPS. Tools that do not support access over HTTPS shall not be used by the Corporation.
 
: (b) <u>HTTP Connection</u>. Web-based tools shall only be accessed over HTTPS. Tools that do not support access over HTTPS shall not be used by the Corporation.
 
: (c) <u>Two-Factor Authentication</u>. It is the policy of the Corporation to prefer tools that support two-factor authentication.
 
: (c) <u>Two-Factor Authentication</u>. It is the policy of the Corporation to prefer tools that support two-factor authentication.

Revision as of 20:07, 10 December 2016

Status: Under Review

The Technology Access Policy is amended by striking Article III, Paragraph 2 and inserting:

2. Standards for Tools. Any tool used by the Corporation to collect or store Sensitive PII ("Sensitive PII Tool") shall adhere to the following standards:

(a) Individual Access. Access shall be allocated to individual user accounts, not accounts shared among individuals. The President may make exceptions for specific tools if the President determines that no feasible alternative exists.
(b) HTTP Connection. Web-based tools shall only be accessed over HTTPS. Tools that do not support access over HTTPS shall not be used by the Corporation.
(c) Two-Factor Authentication. It is the policy of the Corporation to prefer tools that support two-factor authentication.
(d) Public-Key Authentication. Accounts on Corporation servers shall only be accessed through public-key authentication.