In Part 1, we covered the foundational cybersecurity policies every business should have, including information security, passwords, access control, employee onboarding and offboarding, acceptable use, incident response, business continuity, backups, and security awareness training.
Now let’s look at the policies that address the technology and processes surrounding your business’s day-to-day security.
11. Remote Access Policy
Remote work creates additional security considerations.
A remote-access policy should address:
- VPN requirements
- MFA
- Company versus personal computers
- Wi-Fi security
- Remote desktop access
- Approved cloud applications
- Protection of company information outside the office
- Lost or stolen devices
Remote access should be provided only when necessary and should be appropriately secured.
12. Mobile Device Policy
Phones and tablets often contain access to email, company applications, files, and authentication systems.
A mobile-device policy should establish requirements for:
- Screen locks
- Encryption
- MFA
- Device management
- Approved applications
- Remote wipe
- Lost or stolen devices
- Company versus personal devices
Mobile devices should be treated as an extension of your company’s IT environment—not as personal devices that happen to access company data.
13. Security Monitoring & Logging Policy
Security tools are only effective if someone is paying attention to what they report.
A Security Monitoring & Logging Policy establishes what security events should be monitored, how alerts are handled, and how long important logs should be retained.
It should address:
- Monitoring servers, workstations, and network devices
- Monitoring authentication and administrative activity
- Detection of suspicious or unusual activity
- Security alerts and escalation procedures
- Log collection and retention
- Review of failed login attempts and account activity
- Monitoring for malware and ransomware activity
- Investigation and documentation of security events
- Regular review of security controls
For smaller businesses, this doesn’t necessarily mean having someone watching a screen 24 hours a day. Managed security monitoring can provide continuous monitoring and alerting, with trained personnel investigating significant events and escalating them when necessary.
The objective is simple: know what’s happening in your environment before a small security event becomes a major incident.
14. Network Access & Security Policy
Your network is the gateway between your employees, devices, applications, and the internet. A Network Access & Security Policy establishes how that access should be protected.
The policy should address:
- Firewall and network security requirements
- Secure Wi-Fi configuration
- Separate guest and business networks
- VPN and remote access
- Network segmentation
- Administrative access to network equipment
- Approved devices and connections
- Wireless security standards
- Protection of network infrastructure
- Requirements for reviewing network access
The goal is to ensure that only authorized users and trusted devices can access business resources—and that sensitive systems aren’t unnecessarily exposed.
15. Vendor and Third-Party Access Policy
Your employees aren’t the only people who may have access to your systems.
IT providers, software vendors, accountants, consultants, and other third parties may have access to sensitive information.
A vendor-access policy should address:
- How third-party access is approved
- What access vendors receive
- How vendor accounts are secured
- Remote access
- When access is removed
- Security requirements for critical vendors
Vendor access should be reviewed periodically to make sure old accounts and unnecessary permissions aren’t lingering.
16. Data Classification and Protection Policy
Not all information is equally sensitive.
Your business should identify information that requires additional protection, such as:
- Customer information
- Employee records
- Financial information
- Passwords and credentials
- Intellectual property
- Contracts
- Personally identifiable information
A simple classification system—such as Public, Internal, Confidential, and Restricted—can help employees understand how information should be handled.
17. Patch Management Policy
Unpatched software is a common entry point for attackers.
Your policy should establish expectations for:
- Operating system updates
- Application updates
- Network equipment firmware
- Security patches
- Monitoring unsupported software
The policy should also define how quickly critical vulnerabilities should be addressed.
18. Endpoint Protection Policy
Every computer, laptop, and mobile device that connects to your business environment should have appropriate security protections in place.
An Endpoint Protection Policy should establish requirements for:
- Antivirus/endpoint detection and response (EDR)
- Firewall protection
- Full-disk encryption
- Malware and ransomware protection
- Protection against unauthorized software
- Procedures for lost or stolen devices
The policy should also specify what happens when a device falls out of compliance. For example, a computer without current security software or required updates may need to be restricted from accessing company resources until the problem is corrected.
Modern endpoint protection goes beyond traditional antivirus. Endpoint Detection and Response (EDR) can continuously monitor devices for suspicious activity and provide IT or security personnel with the ability to investigate and respond to threats.
For businesses, the goal is simple: every device that can access company data should be known, managed, protected, and monitored.
19. Security Policy Review
A security policy isn’t useful if it is written once and forgotten.
Policies should be reviewed periodically—at least annually—and whenever there is a significant change to the business, technology environment, or regulatory requirements.
The review should determine:
- Is the policy still accurate?
- Are employees following it?
- Have systems or applications changed?
- Have new threats emerged?
- Have regulatory or contractual requirements changed?
Documenting the review is important as well.
You Don’t Need to Do Everything at Once
For a small or midsize business, the list above may look overwhelming. The good news is that you don’t have to create every policy on day one. MC Services can provide starter templates for each policy. We are a SOC-2 certified MSP with a background in cybersecurity.
A good starting point is these eleven essential policies:
- Information Security Policy
- Password & Authentication Policy
- Access Control Policy
- Onboarding & Offboarding Policy
- Incident Response Policy
- Business Continuity & Disaster Recovery Policy
- Backup Policy
- Endpoint Protection Policy
- Network Access & Security Policy
- Security Monitoring & Logging Policy
- Security Awareness Policy
These policies establish the basic framework for protecting your people, systems, and data.
From there, additional policies can be added as your organization becomes more mature or as specific requirements arise.
Policies Are Only the Beginning
Having a policy sitting in a folder doesn’t make a business secure.
The real value comes from putting those policies into practice.
If your policy says employees must use MFA, MFA should actually be enabled. If your policy says terminated employees have their accounts disabled, there should be a documented process to make sure it happens. If your policy says backups are tested, someone should actually perform and document a restore test.
Security policies should become part of your normal business processes—not just documents created for an audit.
For many businesses, the first step is simply asking:
“If something went wrong tomorrow, would we know what to do?”
If the answer is no, it’s time to start building your security program.
Check http://mcservices.com/cyber for a survey to get your organization’s security score.