EssaysForStudent.com - Free Essays, Term Papers & Book Notes
Search

McBride Financial Security Policy

By:   •  Essay  •  649 Words  •  December 19, 2009  •  1,650 Views

Page 1 of 3

Essay title: McBride Financial Security Policy

McBride Financial Security Policy

University of Phoenix

CMGT/440

March 26, 2006

Online Loan Application/Application Service Provider Policy

1.0 Purpose

This document is to describe the Information Security Team’s requirements of Online Application Services and Application Service Providers that engage in business with McBride Financial Services.

2.0 Scope

This policy applies to any use of Online Loan Applications (OLA) and any outsourcing to Application Service Providers (ASP) by McBride Financial Services, independent of where hosted.

3.0 Policy

3.1 Requirements of Project Sponsoring Organization

The Online Loan Application or Application Service Provider’s Sponsor must first establish that its project is an appropriate one for the OLA/ASP model, prior to engaging in any additional infrastructure teams within McBride Financial Services or any external Application Service Providers. The department wanting to use an Online Loan Application or any Application Service Providers service must confirm that the Application Service Providers chosen to host the loan applications of McBride Financial Services complies with this policy. The Business Function to be outsourced must be evaluated against the following:

1. The requester must go through the OLA/ASP engagement process with the Information Security Team to ensure affected parties are properly engaged.

2. In the event that McBride Financial Services data or loan applications are to be manipulated by, or hosted at, any ASP's service, the ASP sponsor must have written, explicit permission from the data/application owners. A copy of this permission must be provided to the Information Security.

3. The information to be hosted by an ASP must fall under the "Minimal" or "More Sensitive" categories. Information that falls under the "Most Sensitive" category may not be outsourced to an ASP.

4. If the ASP provides confidential information to McBride Financial Services, the ASP sponsor is responsible for ensuring that any obligations of confidentiality are satisfied. This includes information contained in the ASP's application. McBride Financials legal services should be contacted for further guidance if questions about third-party data arise. Projects that do not meet these criteria may not be deployed to any Application Service Provider.

3.2 Requirements of the Application Service Provider

The Information Security Team has created this document, to make clear the minimum security requirements for

Download as (for upgraded members)  txt (4.2 Kb)   pdf (80.8 Kb)   docx (11.4 Kb)  
Continue for 2 more pages »