You are on page 1of 5

IT - Anti-Virus and

Software Policy
REVISION HISTORY
Version Author Date of Sections Affected
Number Revision
1 XXXX All

AUTHORIZATION
Prepared by Date
Reviewed By

Approved By
Table of contents:

1. SCOPE........................................................................................................................1

2. POLICY STATEMENT............................................................................................1

3. COMPLIANCE WITH THE POLICY...................................................................1

4. VIOLATION OF THE POLICY..............................................................................1

4.1 CONSEQUENCES OF VIOLATION OF THE POLICY..............................1

5. CONTACT ROLE FOR CLARIFICATIONS REGARDING THE POLICY....1


Scope
This policy applies to all users of information assets including COMPANY
employees, employees of temporary employment agencies, vendors, business
partners, and contractor personnel and functional units regardless of geographic
location.

Policy Statement
The purpose of the Anti-virus and Malicious Software Policy is to ensure that there is
an appropriate level of protection to information assets of COMPANY from
malicious code or software that compromises the security of the information or the
information processing assets.

Viruses and Malicious Software are unauthorized programs that replicate themselves
and spread to other computer systems across a network. The symptoms of Virus
infection include considerably slower response time, inexplicable loss of files,
changed modification dates for files, increased file sizes, and total failure of a
computer system.

The management shall control the spread and impact of virus, spyware/malware and
malicious software through the following:
All possible and feasible measure must be taken to prevent the introduction
of Viruses and Malicious Software into COMPANYs information systems.
All possible and feasible measures must be taken to detect Viruses and
Malicious Software on COMPANYs information systems infrastructure.
All virus or malicious activities shall be handled based on the Incident
Management Policy.

Compliance with the Policy


Compliance with the Anti-Virus and Malicious Software Policy is mandatory.
COMPANY Department Heads shall ensure continuous monitoring within their
departments. Compliance with the policy shall be subjected to periodic review by
Head IT.

Violation of the Policy


Any employee who discovers a breach of this policy shall notify the Head IT.
Violations of the policies of COMPANY shall result in disciplinary action by
management.

1 Consequences of violation of the Policy


Disciplinary action shall be consistent with the severity of the incident, as
determined by an investigation, and may include, but not be limited to:
Loss of access privileges to information assets, and
Other actions as deemed appropriate by Management, Human Resources, and
the Legal Department.

You might also like