13.07.2015 Views

FCA Employee Handbook - Financial Conduct Authority

FCA Employee Handbook - Financial Conduct Authority

FCA Employee Handbook - Financial Conduct Authority

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

12. Security of <strong>FCA</strong> Assets, Information andDataClear Desk PolicyThe Clear Desk Policy serves as a basic reminder to staff to secure sensitive or valuablematerial, whilst providing guidance on procedures that should be followed.The procedural guidance contained within this document enhances/supports other <strong>FCA</strong> policiescovering records management, staff confidentiality agreements, employee informationsecurity, Data Protection and Emergency Planning procedures.The Clear Desk Policy will complement, not replace, other existing policies. The <strong>FCA</strong> Clear DeskPolicy relates to all material, whether personal or corporate, that is held within the premises ofthe <strong>Financial</strong> <strong>Conduct</strong> <strong>Authority</strong>. The policy allocates responsibilities and provides proceduraladvice to ensure that the aim is achieved.It also identifies courses of action in relation to non-compliance and suspected securitybreaches. The policy covers all premises in which the <strong>FCA</strong> operates.AimThe aim of the Clear Desk Policy is to ensure that <strong>FCA</strong> records and property are afforded theappropriate level of physical protection in direct proportion to the impact on the businessactivities and reputation.ObjectivesThe objectives of the Clear Desk Policy are as follows:To protect sensitive information from public disclosure - Not only information which hasbeen annotated with a <strong>FCA</strong> security classification, or is covered under the auspices of theData Protection Act 1998, but also information that could potentially embarrass or damagethe reputation of the <strong>FCA</strong> if publicly disclosed.To prevent inappropriate access to sensitive information.To protect business critical information from damage or loss as a result of fire, smoke,water and explosion. To protect information which, although not sensitive is essential to normal functionality –Information such as reference material that can be replaced easily but with a time delay.To protect information that would be difficult or could not be replaced.To ensure that material is stored in a way that enhances Business Continuity Planning inrelation to post incident start up, clearance, salvage and reclamation.To prevent loss or theft of personal property and <strong>FCA</strong> portable property such as laptopsand mobile phones.To quantify the consequences of loss of information or <strong>FCA</strong> property resulting throughnegligence of a member of staff or, as a result of deliberate acts of attempted theft of anymaterial held within the confines of <strong>FCA</strong>.Responsibilities<strong>FCA</strong> <strong>Employee</strong> <strong>Handbook</strong> 2013 187

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!