Thoughts? Oh, yes... How about default deny, and add in only web sites that are approved? Make the approval process fairly easy, but documentable - get the managers involved in the approval process.
That will cut down on most of your problems, right there. On Thu, Jan 14, 2010 at 06:34, James Kerr <[email protected]> wrote: > I know this has been discussed in the past but I'm in the process of making > changes to ours so I was interested in a little input from my peers. We have > always had a policy of not allowing our desktops, email and Internet > connection to be used for personal use at all. That being said we have > always turned a blind eye to occasional personal use through the day. This > has been a problem for us. Now we are looking to change the policy to > reflect that we do allow this type of use. > > We want the staff to know that's its ok but we also want them to know what's > not ok. I was looking to basically say the following. "Some personal > Internet use is allowed but must not interfere with the performance of work > duties and responsibilities. Personal Internet use must be restricted to > reasonable sites and materials such as news or information that might be > considered reasonable if read as a text publication in an office > environment." I’m also going to add that downloading files is not allowed > unless approved by IT and that this includes email attachments from personal > email as well. Any thoughts? > > James > > > > ~ Finally, powerful endpoint security that ISN'T a resource hog! ~ ~ <http://www.sunbeltsoftware.com/Business/VIPRE-Enterprise/> ~
