You are using an unsupported browser. Please update your browser to the latest version on or before July 31, 2020.
You are viewing the article in preview mode. It is not live at the moment.
Home > Company Policies > Information Technology > Access Control & Security Policy
Access Control & Security Policy
print icon

Purpose

  • To define the appropriate use and logical access controls, within the Information Technology (IT) resources, which are owned by the SSMC.
  • To ensure the confidentiality, security, and integrity of the information of processes on behalf of its employees and Clients.

Policy Statement

  • SSMC implements access control across all its IT systems and services to provide authorized, granular and appropriate user access and to ensure appropriate preservation of data Confidentiality, Integrity and Availability in accordance with the Information Security Management Policy.
  • Access Control systems are in place (wherever needed) to protect the interests of all users of systems, center premises by providing a safe, secure, and readily accessible environment in which they work.

Responsibility

  • IT Director: Ensure that procedure is implemented and adhered to in all business units.
  • Department Heads (HOD): Ensure procedure is followed by all staff in their department.
  • Infrastructure Engineer: Ensure internet access group designs are up to date and followed by SSMC Staff.
  • Network Engineer Officer: Ensure SSMC network domain access rights are designed and implemented as per the management requirement.
  • System Engineer Officer: Ensure SSMC Systems access rights are designed and implemented as per the management requirement.
  • Users: Users are expected to understand and follow the proper access procedure when requesting for any type of IT services access like internet, email, File-Share, or information system access like HID/ERP, Helpdesk Portal, SS Ops Dashboard, etc.
  • Applications Manager: approve and ensure appropriate roles and access rights are granted and monitoring of Application Specialist’s administrations.
  • ERP/HIS Application Specialists: Provide the access to the SSMC HQ and Ops Staff/Other Staff approved by management as per the job requirements. Providing of access to the vendors for applications support.
  • HR Department: Provides the joining list of new employees and the list of the employees who have resigned or changed their job designations to IT department.

Procedure

Network Domain and Information System Access Security

SSMC network domain and information system is password protected.

  • The IT Infrastructure manager is the designated owner of SSMC Network Domain, and the IT Applications manager is the designated owner of all SSMC information systems / applications.
  • IT must have a designated network / information systems(s) administrators who is responsible for the day-to-day administration of the domain / information system including the creation and management of network domain and information system access accounts for authorized users.
  • Access must be controlled using individual user access accounts. IT Services shall use its on generic accounts to run the services.
  • Based on the job role of the user and actual needs, access rights to information systems are granted on granular level and according to approved list of roles and access right of IT applications.
  • Third Party Access Accounts can be created, if required:
    • Where there is a business need and with the approval of a SSMC network domain and information systems owner.
    • Third party maybe granted access to the SSMC network (Guest) and information systems, after acknowledgment of the IT acceptable usage policy.

Account Registration

Creation of User Accounts

  • HR department notifies respective HOD, and IT helpdesk with the list and profile details of the new joining employees.
  • IT training will be arranged by respective designated trainer to the new employee.
  • IT will ensure that the domain/application access is provided as per the job function of the new employee and approved access rights.
  • Upon network domain and information system account creation, the user credentials with appropriate access rights are shared with the employee and upon successful completion of the training and or orientation.

Changes on Access Privileges

  • Existing users who require additional access privileges or changes on network access or information system must obtain their line manager approval and submit the request to IT to validate, approve and action the access request.
  • HR must inform IT of changes to employee’s designations to ensure that IT remove or provide appropriate access rights according to the new role and designation.

Deactivation of User Accounts

  • HR must notify IT helpdesk with details of employees leaving the organization in a timely manner.
  • The IT helpdesk, network administrator and respective applications specialists will ensure that the user account is deactivated.
  • The access accounts of users taking career breaks, going on maternity leave or those on long-term sick leave for periods more than 6 months, accounts must be suspended (subject to HOD approval) until such a time as they return to work. Requests for account suspensions must be made in writing by the user’s line manager to the IT helpdesk.

Account Privileges

The creation of user access accounts with special privileges such as administrators must be rigorously controlled and restricted by the information systems and network domain owners and to only those IT employees who are responsible for the management and maintenance of SSMC information systems or domain network.

  • Account Management Requests from users for password resets must only be performed once the user’s identity have been verified by the appropriate information system / network administrator.
  • Security Access to all information systems and networks must be controlled via strong password authentication schemes. (Refer to IT Password Policy & Privacy Policy)

Monitoring & Review

  • Network domain and Information systems owners must continually monitor access to network and information systems. They must perform at least yearly reviews of the network domain and information systems users they are responsible for to ensure:
  • Each user access account and privileges assigned to that account are appropriate and relevant to that user’s current role or job function.
  • The network services, information system and the information processed by the systems is only accessed and used by authorized users for legitimate reasons.
  • User access accounts, which have been inactive for 60 consecutive days or more, must be suspended unless instructed otherwise by the user’s line manager.
  • Suspended user accounts, which have not been reactivated within a 12-month period, should be marked for deletion, unless instructed otherwise by the user’s line manager.

Appendices

References

Joint Commission International: Joint Commission International Accreditation for Hospitals Sixth Edition, USA: Joint Commission Resources; 2017. MOI

Abbreviations and Definitions

SSMC-DKP: SmartSalem Medical Centre Dubai Knowledge Park

SSMC-IMC: SmartSalem Medical Centre Index Mall

SMC-CW: SmartSalem Medical Centre City Walk

SSMC-HQ: SmartSalem Medical Centre Head Quarter

Feedback
0 out of 0 found this helpful

scroll to top icon