Last Updated at
This Acceptable Usage Policy covers the security and use of all Brain Payroll information and IT equipment. It also includes the use of email, internet, voice and mobile IT equipment. This policy applies to all Brain Payroll's employees, contractors and agents (hereafter referred to as 'individuals').
This policy applies to all information, in whatever form, relating to Brain Payroll business activities, and to all information handled by Brain Payroll relating to other organizations with whom it deals. It also covers all IT and information communications facilities operated by Brain Payroll or on its behalf.
Computer Access Control – Individual's Responsibility
Access to the IT systems is controlled using User IDs, passwords and/or tokens. All User IDs and passwords are to be uniquely assigned to named individuals and consequently, individuals are accountable for all actions on the Brain Payroll IT systems.
Individuals must not:
Respective managers must ensure that individuals are given clear direction on the extent and limits of their authority regarding IT systems and data.
Internet and Email Conditions of Use
Use of Brain Payroll internet and email is intended for business use. Personal use is permitted where such use does not affect the individual's business performance, is not detrimental to Brain Payroll in any way, not in breach of any term and condition of employment and does not place the individual or Brain Payroll in breach of statutory or other legal obligations.
All individuals are accountable for their actions on the internet and email systems.
Individuals must not:
Social media applications must be accessed only for business use and as per project requirements. The afore-mentioned internet usage best practices guidelines apply for social media access as well.
Clear Desk and Clear Screen Policy
To reduce the risk of unauthorized access or loss of information, Brain Payroll enforces a clear desk and screen policy as follows:
Working Off-Site
It is accepted that laptops and mobile devices will be taken off-site. The following controls must be applied:
Mobile Storage Devices
Mobile devices such as memory sticks, CDs, DVDs and removable hard drives must be used only in situations when network connectivity is unavailable or there is no other secure method of transferring data. Only Brain Payroll authorized mobile storage devices with encryption enabled must be used, when transferring sensitive or confidential data.
Software
Employees must use only software that is authorized by Brain Payroll on Brain Payroll computers. Authorized software must be used in accordance with the software supplier's licensing agreements. All software on Brain Payroll computers must be approved and installed by the Brain Payroll IT department.
Individuals must not:
Viruses
The IT department has implemented automated virus detection and virus software updates within the limits. All PCs have antivirus software installed to detect and remove any virus automatically.
Individuals must not:
Telephony (Voice) Equipment Conditions of Use
Use of Brain Payroll invoice equipment is intended for business use. Individuals must not use voice facilities for sending or receiving private communications on personal matters, except in exceptional circumstances. All non-urgent personal communications should be made at an individual's own expense using alternative means of communications.
Individuals must not:
Actions upon Termination of Contract
All Brain Payroll equipment and data, for example laptops and mobile devices including telephones, smartphones, USB memory devices and CDs/DVDs, must be returned to Brain Payroll. All Brain Payroll data or intellectual property developed or gained during the period of employment remains the property of Brain Payroll and must not be retained beyond termination or reused for any other purpose.
Monitoring and Filtering
All data that is created and stored on Brain Payroll computers is the property of Brain Payroll and there is no official provision for individual data privacy, however wherever possible Brain Payroll will avoid opening personal emails.
IT system logging will take place where appropriate, and investigations will be commenced where reasonable suspicion exists of a breach of this or any other policy. Brain Payroll has the right (under certain conditions) to monitor activity on its systems, including internet and email use, to ensure systems security and effective operation, and to protect against misuse.
Any monitoring will be carried out in accordance with audited, controlled internal processes.
It is user's responsibility to report suspected breaches of security policy without delay to their line management, the IT department, the information security department or the IT helpdesk. All breaches of information security policies will be investigated. Where investigations reveal misconduct, disciplinary action may follow in line with Brain Payroll disciplinary procedures.
Let's talk and find them for all your payroll needs