Outline Sample
Local Data Audit Policy
How It Works

Concepts

Products

Contacts

Home

Site Index

This sample illustrates the general considerations an organisation needs to undertake in respect of creating the comprehensive archive to which the Codel Audit Trail Protection protocols will add their "assurance layer". Many organisations will already have comprehensive archiving in place and robust security around the storage. They will have least to do to implement the protocols.

The policy should begin by stating the formalities...


(Name of Organisation) agrees to implement a Digital Data Audit Policy with effect from (implementation date).

Data Requiring Audit (DRA)

  1. All Financial Data
  2. All External Contract Data
  3. All other documents and emails which are subject to any security classification above "Unrestricted"
  4. Digital logs of incoming and outgoing voice traffic (Call Logging)
  5. Digital Activity Logs for all Network transactions (Local or External)
  6. All digital records of non digital alarms or security related incidents.
  7. All requests for any of the above which do not originate from the authors of the data or their recognised departments.

Individuals Responsible for items 1 - 4 above

  1. Financial Data
    eg List of names in "Accounts" or reference to Departmental lists
  2. Contracts
    eg List of names in "Legal" or ref to Departmental lists
  3. Classified Documents
    eg List of names or Grades/Job titles or ref to Departmental lists
  4. Call Logging
    eg List of names in "Telesales", "Support" etc or ref to Departmental lists
  5. Digital Logs
    eg IT staff names, Grades/Job titles or ref to Departmental lists
  6. Non Digital Incidents
    eg List (managers etc) responsible for creating digital records of such incidents

Relevant Software Applications

  1. Financial Data
    eg Accounting Software (name, version etc); Spreadsheet Software; Other
  2. Contracts
    eg Word Processors; Email Clients; Other
  3. Classified Documents
    eg Word Processors; Email Clients; Other
  4. Call Logging
    eg Call Logging Software; other
  5. Digital Logs
    eg Network Operating System; Firewall software; Antivirus software; Other
  6. Non Digital Incidents
    eg Word Processors; Other

The Audit Period

Is defined as each working day. Snapshots will be stored by the day and the Audit Hierarchy will be used to create a Master Document Hash for each day as described in the Codel documentation. This MDH will be submitted to the Codel database either last thing each working day or first thing the following day (for the period just completed).

Snapshot Storage

Will take place in a dedicated area on the Company Network to which all relevant individuals will be given Read and Create access, but not Edit access.

Accountability

(The Management hierarchy of responsibility for the implementation and operation of this policy.)

Manual Procedures and Automation

  1. List of Software customised to automate production of snapshot data
  2. List of data and applications where customisation not possible but external software fulfils the snapshot task automatically
  3. List of data and applications where customisation not possible but external software can fulfil the snapshot task manually
  4. List of data and applications where only manual procedures can create the snapshot data.

Exceptions

  1. List any internal workstations where DRA is produced but there is no connection to the corporate network or the Internet
  2. List any individuals who are authorised to produce DRA material from outside corporate premises (eg directors or managers working on Laptops at home or on the road)
  3. Other
  4. Specify procedures designed to deal with these exceptions:
    eg Automation or semi-automation on the individual's laptop or home station;
    Scheduled secure VPN connections to upload snapshot data across the internet
    Scheduled visits - either
    By individual bringing Laptop into IT staff for upload of snapshot data or
    By IT staff visiting individual home to retrieve snapshot data manually (if, for example, VPN connection not possible or bandwidth inadequate for upload)