You are using an unsupported browser. Please update your browser to the latest version on or before July 31, 2020.
You are viewing the article in preview mode. It is not live at the moment.
End User Policy
print icon

Purpose

  • To provide the end users in SSMC Clinics, with guidelines for acceptable usage and support of IT assets and resources.

Policy Statement

  1. IT End User Policy is a core component of SSMC IT department and end user support; it is the intellectual capital, best practice policies and standards resulting in efficient, accountable, and cost-effective use of IT Assets and resources.
    1. The principles underlying effective manual for organizations are:
    2. Information is a vital asset that must be managed and, where appropriate, shared to maximize investments.
    3. Information and technology are key components in delivering cost-effective services to the employees.
    4. Information and technology have the potential, when planned and managed properly, to improve productivity and reduce costs to management.
    5. Information and technology are strategic enablers of quality IT service delivery.
    6. The management and business principles applied to other department resources should be applied to information and technology resources.

Responsibilities

  • The owner of the IT End User Policy document is the IT Director, who shall be responsible for compliance, update, and maintenance of the IT End User Policy.
  • This policy is directed to and applies to all SSMC employees and associates, responsible for managing, or accessing information technology for best business practice, which supports the Service of IT department. This policy establishes the acceptability by SSMC departments and vendors to use the IT Assets/Resources that are supported by the IT department.
  • Head of Departments: To ensure business needs and utilization of required IT assets in their departments.
  • Procurement Department: to purchase the approved IT Assets.
  • CTO/Relevant Chief Officer’s: to provide approval decision on any exceptions of IT asset requests.

Procedure

List of IT Assets and Resources

Standard hardware

List of IT equipment or hardware that can be requested from IT department through related IT Service request process including (but not limited to) following assets:

IT Assets
Laptop, Computer, Tablets & Docking Station
Desktop Computer, Monitor, Keyboard & Mouse
Printer & Multi-Function Printers/Copiers
Mobile Phones

Standard Applications

Application
Microsoft 365 Suite
Anti-Virus Software
Chrome & Mozilla
HOD Approved Software(If Applicable)

Exclusion

The exclusions are any IT assets and resources outside of the above scope of software and hardware as it explicitly states what is included in the scope.

Conflicting standards

  1. Any standard IT policy, procedure or other document that might overrule or conflict with this standard must be brought to the attention of the IT Director.
  2. All possible discrepancies or conflicts with this standard must be approved by the IT Director or his nominee. Discussion can be extended with CTO to resolve discrepancies or conflicts with other standards.
  3. Once reviewed all documents shall be updated to resolve the discrepancies or conflicts. Before the resolution.

IT Asset Usage

  1. End user computing policy includes end user department’s desktops, Laptop, Printer etc., inclusive of all IT Assets/resources given to the individual to perform their services. Please note that any Handheld devices, including smart phones, Tablet are also included if provided.
  2. This also includes desktop level software, Operating System, standard software packages like MS Office and business-related applications.
  3. Department Head (HOD) will act as the first levels of scrutiny in case any of the IT assets are required e.g.: Laptop, Mobile phones etc. (With appropriate business justification). Therefore, Users need to make a request according to their actual needs and eligibility for availing the IT assets/services with the appropriate approvals. All requests shall be raised electronically using the Helpdesk System (FreshService)
  4. The Approval Committee will review the request and endorse his approval on the request, IT Service desk team is responsible for allocating IT Assets, Software installation, ID’s and all configurations.

Note: The IT Service Desk team is responsible for allocating the IT assets, judging the suited configuration / model available with IT.

New Asset allocation

  1. Users of all business units need to raise their IT assets requests through IT Service desk and obtain required HOD & Management approval. Post approvals, the IT will raise the purchases of the Assets and/or start the allocation from the stocks or procurement, as applicable.
  2. In case of fresh procurement, time frame depends on the procurement policies and processes. Thus, the IT team suggests the requester to raise the requests at least 2 weeks prior.

Evaluation, Acquisition, Testing, Acceptance and Deployment of IT software/hardware assets

  1. Capital funds are spent judiciously, such that favorable price/performance benefits are achieved. The acquisition should address the identified business problems and do so economically. However, there is no mandate to select the lowest cost alternative, since other indirect costs associated with an incomplete selection may offset any initial savings. When two applications are comparable in their ability to solve the business issues, the lowest cost may become a significant factor in the final recommendation.
  2. By developing general standards for hardware and operating systems, acquisitions can potentially exploit hardware and operating systems already licensed for other applications, thus reducing additional capital outlay.
  3. Favorable license terms, warranties, and vendor support commitments for software are obtained.
  4. Hardware / software recommended for purchase demonstrates a history of reliability, for example, acceptable failure rates within the computer industry.
  5. Reliable local service for hardware /software can be obtained over the anticipated life of the equipment / software.
  6. Recommended hardware /software demonstrates favorable performance indicators relative to other widely used equipment / software.
  7. Appropriate business risk is used to evaluate the reliability and viability of vendors and their products and services.
  8. IT prepare the Scope of work including a technical requirement and obtain the functional requirements from the clinical / business team for the required software / hardware
  9. The scope of work will be shared with all the shortlisted suppliers and their responses will be evaluated against detailed evaluation criteria and comparison sheets.
  10. IT will raise a Purchase Request followed by a Purchase Order and its contents are then recorded in a spreadsheet maintained by the procurement specialist along with the details of the vendor quotation and the necessary cost and technical and functional comparison, along with the PO for approval.
  11. A project management plan for system implementation will be developed and followed during the implementation. All related stakeholders especially clinical / business teams will be engaged actively throughout the project lifecycle including business requirement gathering, solution design, training, testing and final acceptance of the system and all phases of the project will be documented and approved by the management.
  12. To ensure continual service improvement, continuous system evaluation and improvement process will take place after the go-live phase of any software or hardware project.

Asset Lost / Damage

The responsibility and care of an IT Asset is as much the responsibility of the allotted end user as it is of the IT Department. In the unfortunate event of an IT asset being damaged/ lost, the following necessary steps should be undertaken:

  1. The user must raise an Incident immediately, inform the IT Team with the appropriate Information/Data Security for the Asset.
  2. IT Team will authorize the concern team for de-activate/lock the Asset.
  3. If the user requires the asset again, he/she will follow the Service Request procedure.
  4. If it is found that the asset was damaged partially or completely due to the misuse of end user and repairing of the assets require sending it to external service center or paying new spare parts, the party causing the incident shall bear all cost of repairing.

Installation of end user computing facilities

  1. The installation of the end user computing facilities must be carried out and inspected by an IT desktop support engineer from the service desk.
  2. The desktop support engineer should make sure:
    1. The hardware matches the purchase list.
    2. The licenses of the software to be installed are in place.
    3. The facilities to be installed are below the standard.
    4. The operating system and standard software are installed properly with related security settings in place.
    5. Antivirus software is installed and has been properly setup to ensure the system signatures and engines are up-to-date.
    6. Business applications are installed properly with related security settings in place.
IT Asset No. of Years
Desktop Computer, Monitor, Keyboard and Mouse 5 Years
Printer, Scanner & Multi-Function Printers/Copiers 5 Years
Mobile Smart Phone, Tablets 3 Years

Note: User must take the exception request approvals from CTO in case of early replacement for the above assets and submit to the IT Service desk.

IT Acceptable Usage Guidelines

Clear Desk and Clear Screen

  1. Computer terminals and systems must not be left logged on when unattended, Screen-Lock, Screen- Saver password or other controls should be used to protect them when not in use and all active sessions should be terminated when finished.
  2. Computer media, like CDs, flash memory sticks, external hard drive containing confidential business and patient information should not be left unattended. They should be stored in suitable locked cabinets when not in use, especially after working hours.
  3. Printed files and other papers (non-electronic format) that contain sensitive or confidential information must be protected from unauthorized access. Users should not leave any such papers unattended on printer trays, photocopiers, fax machines or their desks.
  4. Restricted and ‘Confidential’ information and classified storage media must be locked (ideally in a fire-resistant safe or cabinet) when not required.

Use of Storage Media

  1. All information storage media (e.g., Flash Memories, and external Hard Drive etc.) containing sensitive or confidential data must be physically secured, when not in use.
  2. You are not supposed to use USB drives (which are the main source of viruses). When needed the usage of such media, staff should approach the IT Helpdesk to ensure cleanness of the same from any viruses / malicious programs and make necessary file transfer.

Visitor Access to IT department

  1. All visitors must be requested to wait at the IT department and the employee being visited should accompany the visitor to the meeting / training rooms.
  2. Visitors Laptop and external storage devices must not be allowed to connect to SSMC’s main network, unless authorized by the IT Network engineer.
  3. Employees should avoid taking the visitor to their workstations, if possible.

Software Usage

  1. All users of software on SSMC’s must strictly abide by “Copyright Laws” and restrictions specified by the software vendor.
  2. Only approved and licensed software must be installed on SSMC supplied computer equipment.
  3. No unlicensed software, shareware (beyond its period of free use), public domain software or pirated software should be used on SSMC’s computer equipment.
  4. Software, once installed on a system, must not be copied other than for backup purposes.
  5. Software must be used for official purposes only.
  6. Employees shall comply with terms and conditions for software and information obtained from public networks.

Safeguarding of medical records

  1. Important records must be protected from loss or destruction, users should always use OneDrive to save critical business files. Individual functions are responsible for identifying data needed for regulatory compliance where applicable. Files stored in Desktops/My Documents (in Local computers) are not backed up and the end user is fully responsible for any loss of that data.
  2. Records should be stored and retained based on the retention period given by data owners as required and as per the UAE policy.
  3. Extra precautions should be taken to store the records required to meet statutory requirements.
  4. Records must be destroyed in a safe and secure manner on completion of their retention period and according to the hospital information and medical records retention policy.

System and Network Activities

The following activities are strictly prohibited, with no exceptions:

  1. Introduction of malicious programs into the network or server (e.g., viruses, worms, Trojan horses, e-mail bombs, etc.).
  2. Revealing your account password to others or allowing use of your account by others. This includes family and other household members when work is being done at home.
  3. Port scanning or security scanning is expressly prohibited unless prior authorization from IT Management.
  4. Executing any form of network monitoring which will intercept data not intended for the employee's host unless this activity is a part of the employee's normal job or duty.
  5. Using any program/script/command, or sending messages of any kind, with the intent to interfere with, or disable, a user's terminal session, via any means, locally or via the Internet/Intranet/Extranet.
  6. Providing information about, or lists of, SSMC employees to parties outside SSMC.
  7. Network connection and use of mobile devices, individual computers / laptops unless authorized by respective Department Head and IT Management.
  8. Using SSMC’s computing asset to actively engage in procuring or transmitting material that is in violation of sexual harassment or hostile workplace laws in the user's local jurisdiction.
  9. Using a SSMC’s computing asset to engage in procuring or transmitting pornographic material in violation of local and international laws
  10. Making fraudulent offers of products, items, or services originating from any SSMC’s account.
  11. Making statements about warranty, expressly or implied, unless it is a part of normal job duties.

Account & Password Usage

  1. Each SSMC user will be provided with a login ID and Password upon joining.
  2. A login ID / Password must not be shared with colleagues or friends.
  3. A password must not be written on paper.
  4. A password must not be easy to guess (e.g., cannot be the login name).
  5. The usage of password breakers is not allowed.
  6. It is strictly prohibited to access other user’s accounts.
  7. Password must be changed whenever the system prompts for a change.
  8. “User Must change the Password at Next Logon” setting should be enabled whenever new User ID Created by the IT system administrator.
  9. The login-in ID and password will be deactivated upon the HR notification to IT department of leaving staff or upon completing the IT clearance form for the employee by IT department.

Prevention of misuse of information processing facilities

  1. The information processing systems and facilities must be used for the business purposes only.
  2. Usage of the information system and facilities, other than for business purposes, must be considered as improper use of the facilities.
  3. If such activity is identified by monitoring or other means, it should be brought to the attention of the IT Director for appropriate action.
  4. SSMC Telephones usage should be limited to official purpose only. All the calls are monitored, and reports are generated.

IT Security Incidents and Weaknesses

  1. Users shall report any IT incident/weaknesses directly to IT Team.
  2. All users shall be made aware to report any malfunction or other anomalous system behavior as security incident.
  3. All users shall be advised not to attempt to prove suspected security weaknesses.
  4. Testing weaknesses shall be considered as a potential misuse of the system and violation of policy.
  5. The suspected weaknesses encountered by users (employees, third party staff and contractors) shall be reported to the identified point of contact.

Usage guidelines for portable devices

  1. The SSMC and its subsidiary companies that own the portable device or laptop are responsible for the physical equipment and must ensure that an appropriate level of security is maintained on the hardware and the information contained therein.
  2. Individuals (employee, contractor, and consultant) assigned the use of a SSMC owned or leased portable devices or laptops are accountable for the physical security of the machines and the information contained therein while the device is in their possession.
  3. Any questionable incidence of device loss or theft will be investigated and may result in disciplinary action being taken against the bearer.
  4. The following standards apply whether the laptop is in use at work, at home or while traveling.
    1. All losses of computing equipment must be reported to the IT Help Desk.
    2. All Laptop computers containing SSMC data – including customer information, access control lists, transactional records and other sensitive records – must be secured according to this standard.
    3. Laptop Configuration Operating System and Communications Software
    4. All portables and laptops will utilize the SSMC standard operating system, which must include the current configuration for lockdown. No user may be an administrator of their device.
    5. All portables and laptops will connect to the SSMC network utilizing an authorized remote access connection only in compliance with the SSMC IT Security Policy.
    6. Virus protection software must be operational on the computer and must comply with the current standard for Virus Protection Software. Automatic scan for viruses must be enabled in compliance with the Virus Protection Policy and Standard defined in the IT Security Policy.
    7. Users who are not normally connected to the network are required to perform manual virus signature updates once a week.
    8. Any detected viruses are to be reported immediately to the IT Helpdesk.
    9. User Ids and passwords are not to be encoded in any auto logon script, saved on the local file system, or retained automatically by the operating system. Passwords and Pins are not to be located on the portable device, nor kept in the same container as the portable or laptop.

End User Support & Training

Support

  1. Whenever a user has a problem on their computing resources, they should always contact the IT Team and raise a Support ticket using the Service Desk Software.
  2. Local users should have a proper description of the problem, required screen shots to resolve the IT issues first time correctly.
  3. Major applications and Hardware’s are purchased with:
    1. Vendor’s maintenance or support
    2. User guides and/or other related documentation
  4. The IT Service Desk team will only be allowed to take remote access of the Desktop and Laptop using a secured session and tool.
  5. End users will be notified by the IT Service Desk before taking control of the IT Asset.
  6. Access permission to be given by the end user to the IT Service desk for the duration of his support.

Training

Training or technical briefing should be arranged upon request from end users whenever possible. Business users, administrators and decision makers will be provided with one-to-one training on how to use the IT systems to generate required reports and data required for running their operations.

Mobile Computing and Communication

  1. Employees are required to take special care of the mobile computing resources such as, but not limited to, laptops, mobile phones, handheld computing devices like Tablets, iPad, etc. that are issued by the organization, to prevent any compromise and/ or destruction of business information.

Penalty Actions

  1. Any discovery of violation of the above standards should be reported to both Business and IT management.
  2. Problems should be rectified, and warnings should be dispatched to the user immediately.

7.13.3 If anyone has further attempted on the violation, management should consider taking disciplinary actions.

Appendices

References

Abbreviations and Definitions

SSMC-DKP: SmartSalem Medical Centre Dubai Knowledge Park

SSMC-IMC: SmartSalem Medical Centre Index Mall

SSMC-CW: SmartSalem Medical Centre City Walk

SSMC-HQ: SmartSalem Medical Centre Head Quarter

Feedback
0 out of 0 found this helpful

scroll to top icon