Re: Corporate policy question - Personal Laptops



Hello Tom,

In such a condition you should be following what your company policy
dictates. If your organization has provided the laptops that in such
cases the laptop is your organizations property. Now in the case if
its a personal laptop, it still contain organization's Business
Information. And in such cases it becomes your organizations 'critical
Information asset container'.

The owner of the laptop is the manager/employee. But some information
it holds belongs to your organization. To safe guard your
organization's Critical Information its how your organization frames
the Security policies and procedures.

If the laptop is provided by the organization, wiping of the
organizations Critical Information, can be justified. But if your
organization has let your staff use their personal laptops, then the
matter becomes more complicated. And in such a situation the
agreements that the employee had to sign (Eg NDA) comes handy for the
Organization (to enforce the policies like wiping out Organization's
Critical Information Asset). But do consult your Legal staff....


Regards,

Meenal A. Mukadam
(CEH, MBA Informations Systems & Security)



On Thu, Sep 11, 2008 at 10:53 AM, Tom Yarrish <cdtdelta@xxxxxxxxx> wrote:
Hey all,
Needed some advice on a corporate policy issue. If an employee has a
personal laptop in the office, and that employee is terminated in the
process of a merger, can the company wipe the hard drive of the
personal computer before it's returned to that employee? Here's the
scenario:

Our company is going through a merger, and through the rounds of
"integration" of the two companies, employees that are let go from the
IT department are escorted out of the building immediately, and not
allowed to return. Their manager packs up their personal affects and
ships it to them. In one case, the employee had some personal laptops
in their office, and wants them back (obviously). Are we allowed to
wipe the hard drive of that personal laptop before giving it back to
the employee?

I'm trying to determine if this is even legal or not, so I'm not sure
where to look for advice.

Thanks ahead of time....




--
09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0




--
Meenal A. Mukadam

-------------------------------------------------------------
Far away there in the sunshine
are my highest aspirations.
I may/maynot reach them,
but I can look up and see their beauty,
believe in them and try to follow
where they lead
-------------------------------------------------------------



Relevant Pages

  • Re: [Full-disclosure] Undisclosed breach at major US facility
    ... If the effects of HIPAA, SOx, GLBA et al could be measured in dollars, it has cost corporations millions of dollars in software, hardware and personnel expenses. ... A perfect example of the dichotomy between what should be and what is is the recent theft of a laptop with millions of VA records on it. ... Furthermore, I'm certain that the theft of the laptop never crossed the mind of the employee who took the records home or of his supervisors, who merely winked at the violation of policy, because they were more concerned about getting "extra" work out of the employee than they were about the potential loss of data should the laptop be stolen. ... When passwords finally go away, almost one-half of the security problem will be solved, simply because humans will no longer be making decisions about what constitutes a secure authentication methodology. ...
    (Full-Disclosure)
  • Re: Dial up question
    ... >>>restrict home PC or any other computer from making the same connection via ... >> 1) Employee takes laptop home, dials in to the Internet, allows other computers ...
    (microsoft.public.windowsxp.network_web)
  • Re: Corporate policy question - Personal Laptops
    ... Needed some advice on a corporate policy issue. ... personal laptop in the office, and that employee is terminated in the ... the damages to the laptop's owner. ...
    (Security-Basics)
  • Re: my laptop
    ... You have no idea whether this is a former MS employee or not. ... |> If you *were* a microsoft employee, and this email is indicative of your ... |> | I demand that Microsoft returns my laptop to me immediately. ...
    (microsoft.public.security)
  • Problem Installing XP Pro over W2K Pro
    ... I recently was laid off and took advantage of the offer to buy the laptop, ... etc. that I had used while an employee. ... I wanted to start over with Win XP Pro and, of course, ... I bought a full, retail copy of XP Pro, performed a 'full' install on the ...
    (microsoft.public.windowsxp.security_admin)