{"id":3600,"date":"2020-01-23T12:35:11","date_gmt":"2020-01-23T12:35:11","guid":{"rendered":"https:\/\/nissa.gov.ly\/%d8%b3%d9%8a%d8%a7%d8%b3%d8%a9-%d8%a7%d9%84%d8%a3%d8%b7%d8%b1%d8%a7%d9%81-%d8%a7%d9%84%d8%ab%d8%a7%d9%84%d8%ab%d8%a9\/"},"modified":"2020-04-19T20:35:18","modified_gmt":"2020-04-19T20:35:18","slug":"third-party-policy","status":"publish","type":"page","link":"https:\/\/nissa.gov.ly\/en\/main-services\/third-party-policy\/","title":{"rendered":"Third Party Policy"},"content":{"rendered":"<div>\n<p>        <img decoding=\"async\" src=\"wp-content\/uploads\/download-pdf.svg\" alt=\"\"><\/p>\n<h6>You can National Information Security &#038; Safety Authority policies as pdf by clicking on this link<\/h6>\n<p><a href=\"wp-content\/uploads\/NISSA_Policy_Manual_v1.0-1.pdf\">Download<span style=\"padding-right:10px;\" uk-icon=\"arrow-down\"><\/span><\/a><\/p>\n<\/div>\n<h3><b>Third Party Access Policy<\/b><\/h3>\n<ul>\n<li>\n<h4>Introduction<\/h4>\n<div>\n<p><span style=\"font-weight: 400;\">This policy outlines procedures governing third-party access to <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> owned systems, network and applications.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">A third party is an organization or individual (non-permanent employee) external to the <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\">\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The policy covers the following aspects of third party relationships: <\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Third party risk assessments.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Agreement and Contracts.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Network service provision.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Authorization of connections.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Security of access by non-permanent employees (both physical and logical).<\/span><\/li>\n<\/ul>\n<\/div>\n<\/li>\n<li>\n<h4>Purpose<\/h4>\n<div>\n<p><span style=\"font-weight: 400;\">The purpose of this policy is to define standards for all Third Parties seeking to access the <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> systems or network for the purpose of transacting business related to <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\">.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This policy is designed to minimize the potential exposure to the <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> from risks associated with Third Party Access.<\/span><\/p>\n<\/div>\n<\/li>\n<li>\n<h4>Scope<\/h4>\n<div>\n<p><span style=\"font-weight: 400;\">This policy applies to all <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> Staff seeking to provide access to the <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> system, network or devices attached to the network to Third parties, and to all Third Parties whether they are vendors, contractors, consultant or outsourced professionals.<\/span><\/p>\n<\/div>\n<\/li>\n<li>\n<h4>Policy<\/h4>\n<div>\n<ol>\n<li><span style=\"font-weight: 400;\">A Non-disclosure agreement is essential and must be signed contracting with a third party, and the role and responsibilities of the third party should be clearly defined in the agreement.<\/span><\/li>\n<\/ol>\n<ul>\n<li><span style=\"font-weight: 400;\">Third party access to <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> system and network facilities will be given only after the signing of a formal contract defining the terms for the connection which should contain all security requirements by which the third party is to abide.<\/span><\/li>\n<li><span style=\"font-weight: 400;\">All new connection requests between third parties and <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> require that the third party and <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> representatives agree to and sign the Agreement. <\/span><\/li>\n<\/ul>\n<p>2. <span style=\"font-weight: 400;\">Pre-Requisites: All new connectivity will go through a security review and approval with the Information Security department.<\/span>\u2028<\/p>\n<ul>\n<li><span style=\"font-weight: 400;\">The reviews are to ensure that all access matches the business requirements in a best possible way, and that the principle of least access is followed.All third parties must follow the information security requirements that determine the minimum level of security the <b>(Organization)<\/b> requires to be achieved by the third party. These set out the security measures that must be implemented and maintained by the <b>(Organization)<\/b> in relation to all aspects of information security and all associated supporting processes.<\/span><\/li>\n<li><span style=\"font-weight: 400;\">All third parties must ensure that they do not breach any of the information security management system statements at any time during their contract with the <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\">.<\/span><\/li>\n<\/ul>\n<p>3. <span style=\"font-weight: 400;\">Establishing Connectivity<\/span>:\u2028<\/p>\n<ul>\n<li><span style=\"font-weight: 400;\">All connectivity established must be based on the least-access principle, in accordance with the approved business requirements and the security review. <\/span><\/li>\n<\/ul>\n<p>4. <span style=\"font-weight: 400;\">Modifying or Changing Connectivity and Access<\/span>:\u2028<\/p>\n<ul>\n<li><span style=\"font-weight: 400;\">All changes in access must be accompanied by a valid business justification, and are subject to security review. Changes are to be implemented via <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> change management process.<\/span><\/li>\n<\/ul>\n<p>5. <span style=\"font-weight: 400;\">Permitted Third Party Access <\/span>:\u2028<\/p>\n<ul>\n<li><span style=\"font-weight: 400;\">Third Party Access to the <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\">\u2019s systems or\u00a0 network should be made only for the purposes agreed in the contract, this shall be applied to <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> partner not employed directly by the <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> who has remote or direct access to the <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\">\u2019s systems and network.<\/span><\/li>\n<li><span style=\"font-weight: 400;\">Third party access must be permitted only to the facilities, services and data, which are required to perform the specified tasks, as outlined to the IT appropriate Network Manager\/Administrator in the original request for access.<\/span><\/li>\n<\/ul>\n<p>6. <span style=\"font-weight: 400;\">Third Party Workstations <\/span>:\u2028<br \/><span style=\"font-weight: 400;\">Where Third Parties use PC\u2019s \/ Laptops or any other devises not owned or managed by the <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> to access the resources on the <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\">\u2019s network and systems, Third Parties must ensure the following:<\/span><\/p>\n<ul>\n<li><span style=\"font-weight: 400;\">Operating Systems should be fully up-to-date with patches.<\/span><\/li>\n<li><span style=\"font-weight: 400;\">Anti-virus software should be fully up-to-date with patches and virus definitions.<\/span><\/li>\n<li><span style=\"font-weight: 400;\">Anti-spyware\/malware software should be fully up-to-date with patches and malware definitions.<\/span><\/li>\n<\/ul>\n<p>7. <span style=\"font-weight: 400;\">Remote Access by Third Parties<\/span>: \u2028<\/p>\n<ul>\n<li><span style=\"font-weight: 400;\">Responsibilities for security management and administration of third party access will be assigned clearly to both <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> and the third party.\u00a0 An appropriate level of management and technical support will be provided by both parties to ensure that compliance with this policy is achieved.<\/span><\/li>\n<li><span style=\"font-weight: 400;\">For each party connection, the following positions must be appointed:<\/span><\/li>\n<li><span style=\"font-weight: 400;\">A Head of Service Area or delegated authority who will be responsible for permitting third party access by authorizing the connection on a written authorization form.<\/span><\/li>\n<li><span style=\"font-weight: 400;\">A System Owner who will have overall responsibility for each third party connection to ensure that the policy and standards are applied.\u00a0 They are also responsible for confirming whether third party access to their systems would be permitted and may prohibit third party access to certain sensitive systems.<\/span><\/li>\n<\/ul>\n<p>8. <span style=\"font-weight: 400;\">Incident Reporting: Third Parties shall report to management any incident affecting information security and privacy, and all observed and suspected security weaknesses in or threats to Information Technology Assets.<\/span><br \/>9. <span style=\"font-weight: 400;\">Terminating Access:<\/span><\/p>\n<ul>\n<li><span style=\"font-weight: 400;\">When access is no longer required, the responsible<\/span> <span style=\"font-weight: 400;\">of access and connection in <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> must terminate the access. <\/span><\/li>\n<li><span style=\"font-weight: 400;\">The responsible<\/span> <span style=\"font-weight: 400;\">of connection must conduct an audit of their respective connections on an annual basis to ensure that all existing connections are still needed, and that the access provided meets the needs of the connection. <\/span><\/li>\n<li><span style=\"font-weight: 400;\">Connections that are found to be depreciated, and\/or are no longer being used to conduct <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> business, will be terminated immediately. <\/span><\/li>\n<li><span style=\"font-weight: 400;\">All Third party and external users, if defined on the system, should have a mandatory expiry date.<\/span><\/li>\n<\/ul>\n<\/div>\n<\/li>\n<\/ul>\n<h3><b>Non-disclosure \/ Confidentiality Agreement Guideline<\/b><\/h3>\n<ul>\n<li>\n<h4>Introduction<\/h4>\n<div>\n<p><span style=\"font-weight: 400;\">Confidentiality Agreements are must be signed when <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> is considering entering into a business relationship with a third party and where there is a need to understand or evaluate each other\u2019s business processes, some of which might be proprietary or otherwise sensitive in nature.<\/span><br \/><b><\/b><\/p>\n<\/div>\n<\/li>\n<li>\n<h4>Purpose<\/h4>\n<div>\n<p><span style=\"font-weight: 400;\">The purpose of this guideline is to ensure a consistent process for the signing and retention of the <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> Information Confidentiality Agreement by all individuals having access to <\/span><b>(Organization) <\/b><span style=\"font-weight: 400;\">confidential information.<\/span><\/p>\n<\/div>\n<\/li>\n<li>\n<h4>Scope<\/h4>\n<div>\n<p><span style=\"font-weight: 400;\">This guideline applies to <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> and to all Third Parties whether they are vendors, contractors, consultant or outsourced professionals.<\/span><\/p>\n<\/div>\n<\/li>\n<li>\n<h4>Statement of Guidelines<\/h4>\n<div>\n<ol>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">All third parties are required to sign an Information Confidentiality Agreement at the initial start of their contractual relationship, acknowledging they understand and will adhere to this policy.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Where a Third Part has direct or indirect access to data or information owned by the <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\">, this information must not be divulged or distributed to anyone.<\/span><\/li>\n<li style=\"font-weight: 400;\"><b>(Organization)<\/b><span style=\"font-weight: 400;\"> is committed to ensuring confidential services to all third parties. The confidentiality is between the third parties and the organization, not the members of staff delivering a particular service.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Documents which contain personal information including but not limited to names, addresses or telephone numbers, medical records, financial records of <\/span><b>(Organization)<\/b><span style=\"font-weight: 400;\"> staff must be carefully controlled and must not be released or disclosed to any unauthorized individuals or sources.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">The agreement should at least address the following:<\/span><\/li>\n<\/ol>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">The names of the contracting parties.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Which party of the contracting entities is obligated to protect the secrecy of the disclosed information, whether it is the receiving party or the disclosing one or both (Unilateral or Bilateral). Furthermore, NDAs could have more than two parties, therefore such NDAs should address which parties are to be obligated.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Defining what is to be confidential.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">The term (in years) the agreement is binding.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">The term and conditions (in years) of the confidentiality, i.e. the time period of confidentiality.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Information that to be excluded from the NDA. Such as having a prior knowledge of the information, being in public domain, or subsequently gained from other parties.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Restrictions regarding the transfer of confidential information.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Required actions that should be taken with the confidential information upon NDA\u2019s ending.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">The responsibilities of the recipient concerning the confidential information:<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Using the information only for the agreed upon purposes.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">To reveal it only to people with a need to know the information for those purposes.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">To use appropriate efforts (not less than reasonable efforts) to keep the information secure. Reasonable efforts are often defined as a standard of care relating to confidential information that is no less rigorous than that which the recipient uses to keep its own similar information secure.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">To ensure that anybody to whom the information is revealed further abides by obligations restricting use, restricting disclosure, and ensuring security at least as protective as the agreement.<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Types of allowed disclosure \u2013 such as those required by law or court order. <\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">The parties should choose the law and jurisdiction that is governing their agreement.<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<\/div>\n<\/li>\n<\/ul>\n<div>\n<p>    <base>\n<\/div>\n<p><!-- {\"type\":\"layout\",\"children\":[{\"name\":\"Section1\",\"type\":\"section\",\"props\":{\"width\":\"default\",\"padding\":\"\",\"style\":\"default\",\"header_overlay\":\"\",\"animation\":\"\",\"image_size\":\"cover\",\"image_position\":\"center-center\",\"vertical_align\":\"middle\",\"title_position\":\"top-left\",\"title_rotation\":\"left\",\"title_breakpoint\":\"xl\",\"image_effect\":\"\",\"text_color\":\"\",\"width_expand\":\"\",\"height\":\"\",\"header_transparent\":\"\"},\"children\":[{\"name\":\"\",\"type\":\"row\",\"props\":{\"layout\":\"3-4,1-4\",\"breakpoint\":\"m\",\"fixed_width\":\"large\",\"width\":\"\",\"width_expand\":\"\",\"height\":\"\",\"margin\":\"\",\"column_gap\":\"\",\"row_gap\":\"\",\"order_last\":true},\"children\":[{\"name\":\"\",\"type\":\"column\",\"props\":{\"image_position\":\"center-center\",\"media_overlay_gradient\":\"\"},\"children\":[{\"type\":\"panel\",\"props\":{\"link_text\":\"Download<span style=\\\"padding-right:10px;\\\" uk-icon=\\\"arrow-down\\\"><\\\/span>\",\"title_hover_style\":\"reset\",\"title_element\":\"h6\",\"title_align\":\"top\",\"title_grid_width\":\"auto\",\"title_grid_breakpoint\":\"m\",\"meta_style\":\"meta\",\"meta_align\":\"below-title\",\"icon_ratio\":4,\"image_align\":\"left\",\"image_grid_width\":\"auto\",\"image_grid_breakpoint\":\"m\",\"image_svg_color\":\"emphasis\",\"link_style\":\"default\",\"margin\":\"medium\",\"panel_style\":\"card-default\",\"panel_content_padding\":\"\",\"panel_size\":\"\",\"title_style\":\"h6\",\"title_decoration\":\"\",\"title_font_family\":\"\",\"title_color\":\"primary\",\"title_grid_column_gap\":\"\",\"title_grid_row_gap\":\"\",\"title_margin\":\"\",\"meta_color\":\"\",\"meta_margin\":\"\",\"content_style\":\"\",\"content_margin\":\"\",\"image_transition\":\"\",\"image_border\":\"\",\"image_box_shadow\":\"\",\"image_hover_box_shadow\":\"\",\"image_box_decoration\":\"\",\"icon_color\":\"\",\"image_grid_column_gap\":\"\",\"image_grid_row_gap\":\"\",\"image_margin\":\"\",\"link_type\":\"\",\"link_size\":\"\",\"link_margin\":\"\",\"position\":\"\",\"position_z_index\":\"\",\"maxwidth\":\"\",\"maxwidth_breakpoint\":\"\",\"block_align\":\"\",\"block_align_breakpoint\":\"\",\"block_align_fallback\":\"\",\"text_align\":\"\",\"text_align_breakpoint\":\"\",\"text_align_fallback\":\"\",\"animation\":\"\",\"visibility\":\"\",\"title\":\"You can National Information Security & Safety Authority policies as pdf by clicking on this link\",\"content\":\"\",\"image\":\"wp-content\\\/uploads\\\/download-pdf.svg\",\"link\":\"wp-content\\\/uploads\\\/NISSA_Policy_Manual_v1.0-1.pdf\",\"css\":\"\"},\"name\":\"call to action\"},{\"name\":\"\",\"type\":\"headline\",\"props\":{\"title_element\":\"h3\",\"title_style\":\"h3\",\"title_decoration\":\"bullet\",\"text_align\":\"\",\"text_align_breakpoint\":\"\",\"text_align_fallback\":\"\",\"maxwidth\":\"\",\"margin\":\"medium\",\"animation\":\"\",\"visibility\":\"\",\"content\":\"<b>Third Party Access Policy<\\\/b>\",\"title_color\":\"\",\"maxwidth_breakpoint\":\"\",\"block_align\":\"\",\"title_font_family\":\"\",\"position\":\"\",\"position_z_index\":\"\",\"block_align_breakpoint\":\"\",\"block_align_fallback\":\"\",\"css\":\".el-element {\\npadding-top: 60px; \\n    margin-top: -20px !important;\\n}\"}},{\"type\":\"grid\",\"props\":{\"show_title\":true,\"show_meta\":true,\"show_content\":true,\"show_image\":true,\"show_link\":true,\"grid_default\":\"1\",\"grid_medium\":\"\",\"filter_style\":\"tab\",\"filter_all\":true,\"filter_position\":\"top\",\"filter_align\":\"left\",\"filter_grid_width\":\"auto\",\"title_element\":\"h4\",\"title_align\":\"top\",\"title_grid_width\":\"1-3\",\"meta_style\":\"meta\",\"meta_align\":\"below-title\",\"icon_ratio\":4,\"image_align\":\"top\",\"image_grid_width\":\"1-2\",\"image_svg_color\":\"emphasis\",\"link_text\":\"Read more\",\"link_style\":\"default\",\"margin\":\"default\",\"item_animation\":\"\",\"grid_small\":\"\",\"grid_large\":\"\",\"grid_xlarge\":\"\",\"filter_margin\":\"\",\"title_display\":\"\",\"content_display\":\"\",\"panel_style\":\"\",\"panel_content_padding\":\"\",\"panel_size\":\"\",\"item_maxwidth\":\"\",\"title_style\":\"h4\",\"title_decoration\":\"\",\"title_color\":\"\",\"title_margin\":\"\",\"meta_color\":\"\",\"meta_margin\":\"\",\"content_style\":\"\",\"content_margin\":\"\",\"image_border\":\"\",\"image_box_shadow\":\"\",\"image_hover_box_shadow\":\"\",\"image_box_decoration\":\"\",\"icon_color\":\"\",\"image_margin\":\"\",\"link_type\":\"\",\"link_size\":\"\",\"link_margin\":\"\",\"text_align\":\"\",\"text_align_breakpoint\":\"\",\"text_align_fallback\":\"\",\"maxwidth\":\"\",\"maxwidth_breakpoint\":\"\",\"visibility\":\"\",\"block_align\":\"\",\"title_hover_style\":\"reset\",\"grid_column_gap\":\"\",\"grid_row_gap\":\"\",\"grid_divider\":false,\"filter_grid_column_gap\":\"\",\"filter_grid_row_gap\":\"\",\"filter_grid_breakpoint\":\"m\",\"title_grid_column_gap\":\"\",\"title_grid_row_gap\":\"\",\"title_grid_breakpoint\":\"m\",\"image_grid_column_gap\":\"\",\"image_grid_row_gap\":\"\",\"image_grid_breakpoint\":\"m\",\"title_font_family\":\"\",\"image_transition\":\"\",\"position\":\"\",\"position_z_index\":\"\",\"block_align_breakpoint\":\"\",\"block_align_fallback\":\"\"},\"children\":[{\"type\":\"grid_item\",\"props\":{\"title\":\"Introduction\",\"content\":\"\n\n<p><span style=\\\"font-weight: 400;\\\">This policy outlines procedures governing third-party access to <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> owned systems, network and applications.<\\\/span><\\\/p>\\n\n\n<p><span style=\\\"font-weight: 400;\\\">A third party is an organization or individual (non-permanent employee) external to the <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\">\\u00a0<\\\/span><\\\/p>\\n\n\n<p><span style=\\\"font-weight: 400;\\\">The policy covers the following aspects of third party relationships: <\\\/span><\\\/p>\\n\n\n<ul>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Third party risk assessments.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Agreement and Contracts.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Network service provision.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Authorization of connections.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Security of access by non-permanent employees (both physical and logical).<\\\/span><\\\/li>\\n<\\\/ul>\"}},{\"type\":\"grid_item\",\"props\":{\"title\":\"Purpose\",\"content\":\"\n\n<p><span style=\\\"font-weight: 400;\\\">The purpose of this policy is to define standards for all Third Parties seeking to access the <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> systems or network for the purpose of transacting business related to <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\">.\\u00a0<\\\/span><\\\/p>\\n\n\n<p><span style=\\\"font-weight: 400;\\\">This policy is designed to minimize the potential exposure to the <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> from risks associated with Third Party Access.<\\\/span><\\\/p>\"}},{\"type\":\"grid_item\",\"props\":{\"title\":\"Scope\",\"content\":\"\n\n<p><span style=\\\"font-weight: 400;\\\">This policy applies to all <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> Staff seeking to provide access to the <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> system, network or devices attached to the network to Third parties, and to all Third Parties whether they are vendors, contractors, consultant or outsourced professionals.<\\\/span><\\\/p>\"}},{\"type\":\"grid_item\",\"props\":{\"title\":\"Policy\",\"content\":\"\n\n<ol>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">A Non-disclosure agreement is essential and must be signed contracting with a third party, and the role and responsibilities of the third party should be clearly defined in the agreement.<\\\/span><\\\/li>\\n<\\\/ol>\\n\n\n<ul>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">Third party access to <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> system and network facilities will be given only after the signing of a formal contract defining the terms for the connection which should contain all security requirements by which the third party is to abide.<\\\/span><\\\/li>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">All new connection requests between third parties and <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> require that the third party and <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> representatives agree to and sign the Agreement. <\\\/span><\\\/li>\\n<\\\/ul>\\n\n\n<p>2. <span style=\\\"font-weight: 400;\\\">Pre-Requisites: All new connectivity will go through a security review and approval with the Information Security department.<\\\/span>\\u2028<\\\/p>\\n\n\n<ul>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">The reviews are to ensure that all access matches the business requirements in a best possible way, and that the principle of least access is followed.All third parties must follow the information security requirements that determine the minimum level of security the <b>(Organization)<\\\/b> requires to be achieved by the third party. These set out the security measures that must be implemented and maintained by the <b>(Organization)<\\\/b> in relation to all aspects of information security and all associated supporting processes.<\\\/span><\\\/li>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">All third parties must ensure that they do not breach any of the information security management system statements at any time during their contract with the <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\">.<\\\/span><\\\/li>\\n<\\\/ul>\\n\n\n<p>3. <span style=\\\"font-weight: 400;\\\">Establishing Connectivity<\\\/span>:\\u2028<\\\/p>\\n\n\n<ul>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">All connectivity established must be based on the least-access principle, in accordance with the approved business requirements and the security review. <\\\/span><\\\/li>\\n<\\\/ul>\\n\n\n<p>4. <span style=\\\"font-weight: 400;\\\">Modifying or Changing Connectivity and Access<\\\/span>:\\u2028<\\\/p>\\n\n\n<ul>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">All changes in access must be accompanied by a valid business justification, and are subject to security review. Changes are to be implemented via <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> change management process.<\\\/span><\\\/li>\\n<\\\/ul>\\n\n\n<p>5. <span style=\\\"font-weight: 400;\\\">Permitted Third Party Access <\\\/span>:\\u2028<\\\/p>\\n\n\n<ul>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">Third Party Access to the <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\">\\u2019s systems or\\u00a0 network should be made only for the purposes agreed in the contract, this shall be applied to <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> partner not employed directly by the <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> who has remote or direct access to the <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\">\\u2019s systems and network.<\\\/span><\\\/li>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">Third party access must be permitted only to the facilities, services and data, which are required to perform the specified tasks, as outlined to the IT appropriate Network Manager\\\/Administrator in the original request for access.<\\\/span><\\\/li>\\n<\\\/ul>\\n\n\n<p>6. <span style=\\\"font-weight: 400;\\\">Third Party Workstations <\\\/span>:\\u2028<br \\\/><span style=\\\"font-weight: 400;\\\">Where Third Parties use PC\\u2019s \\\/ Laptops or any other devises not owned or managed by the <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> to access the resources on the <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\">\\u2019s network and systems, Third Parties must ensure the following:<\\\/span><\\\/p>\\n\n\n<ul>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">Operating Systems should be fully up-to-date with patches.<\\\/span><\\\/li>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">Anti-virus software should be fully up-to-date with patches and virus definitions.<\\\/span><\\\/li>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">Anti-spyware\\\/malware software should be fully up-to-date with patches and malware definitions.<\\\/span><\\\/li>\\n<\\\/ul>\\n\n\n<p>7. <span style=\\\"font-weight: 400;\\\">Remote Access by Third Parties<\\\/span>: \\u2028<\\\/p>\\n\n\n<ul>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">Responsibilities for security management and administration of third party access will be assigned clearly to both <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> and the third party.\\u00a0 An appropriate level of management and technical support will be provided by both parties to ensure that compliance with this policy is achieved.<\\\/span><\\\/li>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">For each party connection, the following positions must be appointed:<\\\/span><\\\/li>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">A Head of Service Area or delegated authority who will be responsible for permitting third party access by authorizing the connection on a written authorization form.<\\\/span><\\\/li>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">A System Owner who will have overall responsibility for each third party connection to ensure that the policy and standards are applied.\\u00a0 They are also responsible for confirming whether third party access to their systems would be permitted and may prohibit third party access to certain sensitive systems.<\\\/span><\\\/li>\\n<\\\/ul>\\n\n\n<p>8. <span style=\\\"font-weight: 400;\\\">Incident Reporting: Third Parties shall report to management any incident affecting information security and privacy, and all observed and suspected security weaknesses in or threats to Information Technology Assets.<\\\/span><br \\\/>9. <span style=\\\"font-weight: 400;\\\">Terminating Access:<\\\/span><\\\/p>\\n\n\n<ul>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">When access is no longer required, the responsible<\\\/span> <span style=\\\"font-weight: 400;\\\">of access and connection in <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> must terminate the access. <\\\/span><\\\/li>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">The responsible<\\\/span> <span style=\\\"font-weight: 400;\\\">of connection must conduct an audit of their respective connections on an annual basis to ensure that all existing connections are still needed, and that the access provided meets the needs of the connection. <\\\/span><\\\/li>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">Connections that are found to be depreciated, and\\\/or are no longer being used to conduct <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> business, will be terminated immediately. <\\\/span><\\\/li>\\n\n\n<li><span style=\\\"font-weight: 400;\\\">All Third party and external users, if defined on the system, should have a mandatory expiry date.<\\\/span><\\\/li>\\n<\\\/ul>\"}}]},{\"name\":\"\",\"type\":\"headline\",\"props\":{\"title_element\":\"h3\",\"title_style\":\"h3\",\"title_decoration\":\"bullet\",\"text_align\":\"\",\"text_align_breakpoint\":\"\",\"text_align_fallback\":\"\",\"maxwidth\":\"\",\"margin\":\"medium\",\"animation\":\"\",\"visibility\":\"\",\"content\":\"<b>Non-disclosure \\\/ Confidentiality Agreement Guideline<\\\/b>\",\"title_color\":\"\",\"maxwidth_breakpoint\":\"\",\"block_align\":\"\",\"title_font_family\":\"\",\"position\":\"\",\"position_z_index\":\"\",\"block_align_breakpoint\":\"\",\"block_align_fallback\":\"\",\"css\":\".el-element {\\npadding-top: 60px; \\n    margin-top: -20px !important;\\n}\"}},{\"type\":\"grid\",\"props\":{\"show_title\":true,\"show_meta\":true,\"show_content\":true,\"show_image\":true,\"show_link\":true,\"grid_default\":\"1\",\"grid_medium\":\"\",\"filter_style\":\"tab\",\"filter_all\":true,\"filter_position\":\"top\",\"filter_align\":\"left\",\"filter_grid_width\":\"auto\",\"title_element\":\"h4\",\"title_align\":\"top\",\"title_grid_width\":\"1-3\",\"meta_style\":\"meta\",\"meta_align\":\"below-title\",\"icon_ratio\":4,\"image_align\":\"top\",\"image_grid_width\":\"1-2\",\"image_svg_color\":\"emphasis\",\"link_text\":\"Read more\",\"link_style\":\"default\",\"margin\":\"default\",\"item_animation\":\"\",\"grid_small\":\"\",\"grid_large\":\"\",\"grid_xlarge\":\"\",\"filter_margin\":\"\",\"title_display\":\"\",\"content_display\":\"\",\"panel_style\":\"\",\"panel_content_padding\":\"\",\"panel_size\":\"\",\"item_maxwidth\":\"\",\"title_style\":\"h4\",\"title_decoration\":\"\",\"title_color\":\"\",\"title_margin\":\"\",\"meta_color\":\"\",\"meta_margin\":\"\",\"content_style\":\"\",\"content_margin\":\"\",\"image_border\":\"\",\"image_box_shadow\":\"\",\"image_hover_box_shadow\":\"\",\"image_box_decoration\":\"\",\"icon_color\":\"\",\"image_margin\":\"\",\"link_type\":\"\",\"link_size\":\"\",\"link_margin\":\"\",\"text_align\":\"\",\"text_align_breakpoint\":\"\",\"text_align_fallback\":\"\",\"maxwidth\":\"\",\"maxwidth_breakpoint\":\"\",\"visibility\":\"\",\"block_align\":\"\",\"title_hover_style\":\"reset\",\"grid_column_gap\":\"\",\"grid_row_gap\":\"\",\"grid_divider\":false,\"filter_grid_column_gap\":\"\",\"filter_grid_row_gap\":\"\",\"filter_grid_breakpoint\":\"m\",\"title_grid_column_gap\":\"\",\"title_grid_row_gap\":\"\",\"title_grid_breakpoint\":\"m\",\"image_grid_column_gap\":\"\",\"image_grid_row_gap\":\"\",\"image_grid_breakpoint\":\"m\",\"title_font_family\":\"\",\"image_transition\":\"\",\"position\":\"\",\"position_z_index\":\"\",\"block_align_breakpoint\":\"\",\"block_align_fallback\":\"\"},\"children\":[{\"type\":\"grid_item\",\"props\":{\"title\":\"Introduction\",\"content\":\"\n\n<p><span style=\\\"font-weight: 400;\\\">Confidentiality Agreements are must be signed when <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> is considering entering into a business relationship with a third party and where there is a need to understand or evaluate each other\\u2019s business processes, some of which might be proprietary or otherwise sensitive in nature.<\\\/span><br \\\/><b><\\\/b><\\\/p>\"}},{\"type\":\"grid_item\",\"props\":{\"title\":\"Purpose\",\"content\":\"\n\n<p><span style=\\\"font-weight: 400;\\\">The purpose of this guideline is to ensure a consistent process for the signing and retention of the <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> Information Confidentiality Agreement by all individuals having access to <\\\/span><b>(Organization) <\\\/b><span style=\\\"font-weight: 400;\\\">confidential information.<\\\/span><\\\/p>\"}},{\"type\":\"grid_item\",\"props\":{\"title\":\"Scope\",\"content\":\"\n\n<p><span style=\\\"font-weight: 400;\\\">This guideline applies to <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> and to all Third Parties whether they are vendors, contractors, consultant or outsourced professionals.<\\\/span><\\\/p>\"}},{\"type\":\"grid_item\",\"props\":{\"title\":\"Statement of Guidelines\",\"content\":\"\n\n<ol>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">All third parties are required to sign an Information Confidentiality Agreement at the initial start of their contractual relationship, acknowledging they understand and will adhere to this policy.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Where a Third Part has direct or indirect access to data or information owned by the <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\">, this information must not be divulged or distributed to anyone.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> is committed to ensuring confidential services to all third parties. The confidentiality is between the third parties and the organization, not the members of staff delivering a particular service.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Documents which contain personal information including but not limited to names, addresses or telephone numbers, medical records, financial records of <\\\/span><b>(Organization)<\\\/b><span style=\\\"font-weight: 400;\\\"> staff must be carefully controlled and must not be released or disclosed to any unauthorized individuals or sources.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">The agreement should at least address the following:<\\\/span><\\\/li>\\n<\\\/ol>\\n\n\n<ul>\\n\n\n<li style=\\\"list-style-type: none;\\\">\\n\n\n<ul>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">The names of the contracting parties.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Which party of the contracting entities is obligated to protect the secrecy of the disclosed information, whether it is the receiving party or the disclosing one or both (Unilateral or Bilateral). Furthermore, NDAs could have more than two parties, therefore such NDAs should address which parties are to be obligated.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Defining what is to be confidential.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">The term (in years) the agreement is binding.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">The term and conditions (in years) of the confidentiality, i.e. the time period of confidentiality.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Information that to be excluded from the NDA. Such as having a prior knowledge of the information, being in public domain, or subsequently gained from other parties.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Restrictions regarding the transfer of confidential information.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Required actions that should be taken with the confidential information upon NDA\\u2019s ending.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">The responsibilities of the recipient concerning the confidential information:<\\\/span><\\\/li>\\n<\\\/ul>\\n<\\\/li>\\n<\\\/ul>\\n\n\n<ul>\\n\n\n<li style=\\\"list-style-type: none;\\\">\\n\n\n<ul>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Using the information only for the agreed upon purposes.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">To reveal it only to people with a need to know the information for those purposes.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">To use appropriate efforts (not less than reasonable efforts) to keep the information secure. Reasonable efforts are often defined as a standard of care relating to confidential information that is no less rigorous than that which the recipient uses to keep its own similar information secure.<\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">To ensure that anybody to whom the information is revealed further abides by obligations restricting use, restricting disclosure, and ensuring security at least as protective as the agreement.<\\\/span><\\\/li>\\n<\\\/ul>\\n<\\\/li>\\n<\\\/ul>\\n\n\n<ul>\\n\n\n<li style=\\\"list-style-type: none;\\\">\\n\n\n<ul>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">Types of allowed disclosure \\u2013 such as those required by law or court order. <\\\/span><\\\/li>\\n\n\n<li style=\\\"font-weight: 400;\\\"><span style=\\\"font-weight: 400;\\\">The parties should choose the law and jurisdiction that is governing their agreement.<\\\/span><\\\/li>\\n<\\\/ul>\\n<\\\/li>\\n<\\\/ul>\"}}]},{\"type\":\"html\",\"props\":{\"id\":\"irc_footer\",\"content\":\"<base>\"},\"name\":\"Stop Sidebar element\"}]},{\"type\":\"column\",\"props\":{\"image_position\":\"center-center\",\"media_overlay_gradient\":\"\",\"vertical_align\":\"\",\"style\":\"\",\"text_color\":\"\",\"padding\":\"\"},\"children\":[{\"type\":\"wordpress_area\",\"props\":{\"layout\":\"stack\",\"breakpoint\":\"m\",\"content\":\"builder-1\",\"column_gap\":\"\",\"row_gap\":\"\",\"position\":\"\",\"position_z_index\":\"\",\"margin\":\"\",\"maxwidth\":\"\",\"maxwidth_breakpoint\":\"\",\"block_align\":\"\",\"block_align_breakpoint\":\"\",\"block_align_fallback\":\"\",\"text_align\":\"\",\"text_align_breakpoint\":\"\",\"text_align_fallback\":\"\",\"animation\":\"\",\"visibility\":\"\"}}]}]}]}],\"version\":\"1.22.8\",\"props\":[]} --><\/p>\n","protected":false},"excerpt":{"rendered":"<p>You can National Information Security &#038; Safety Authority policies as pdf by clicking on this link Download Third Party Access Policy Introduction This policy outlines procedures governing third-party access to (Organization) owned systems, network and applications. A third party is an organization or individual (non-permanent employee) external to the (Organization)\u00a0 The policy covers the following [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":3574,"parent":3668,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_acf_changed":false,"footnotes":""},"class_list":["post-3600","page","type-page","status-publish","has-post-thumbnail","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Third Party Policy - \u0627\u0644\u0647\u064a\u0626\u0629 \u0627\u0644\u0648\u0637\u0646\u064a\u0629 \u0644\u0623\u0645\u0646 \u0648\u0633\u0644\u0627\u0645\u0629 \u0627\u0644\u0645\u0639\u0644\u0648\u0645\u0627\u062a<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/nissa.gov.ly\/en\/main-services\/third-party-policy\/\" \/>\n<meta property=\"og:locale\" content=\"ar_AR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Third Party Policy - \u0627\u0644\u0647\u064a\u0626\u0629 \u0627\u0644\u0648\u0637\u0646\u064a\u0629 \u0644\u0623\u0645\u0646 \u0648\u0633\u0644\u0627\u0645\u0629 \u0627\u0644\u0645\u0639\u0644\u0648\u0645\u0627\u062a\" \/>\n<meta property=\"og:description\" content=\"You can National Information Security &#038; Safety Authority policies as pdf by clicking on this link Download Third Party Access Policy Introduction This policy outlines procedures governing third-party access to (Organization) owned systems, network and applications. A third party is an organization or individual (non-permanent employee) external to the (Organization)\u00a0 The policy covers the following [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/nissa.gov.ly\/en\/main-services\/third-party-policy\/\" \/>\n<meta property=\"og:site_name\" content=\"\u0627\u0644\u0647\u064a\u0626\u0629 \u0627\u0644\u0648\u0637\u0646\u064a\u0629 \u0644\u0623\u0645\u0646 \u0648\u0633\u0644\u0627\u0645\u0629 \u0627\u0644\u0645\u0639\u0644\u0648\u0645\u0627\u062a\" \/>\n<meta property=\"article:modified_time\" content=\"2020-04-19T20:35:18+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/nissa.gov.ly\/gavedug\/placeholder.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1153\" \/>\n\t<meta property=\"og:image:height\" content=\"645\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u0648\u0642\u062a \u0627\u0644\u0642\u0631\u0627\u0621\u0629 \u0627\u0644\u0645\u064f\u0642\u062f\u0651\u0631\" \/>\n\t<meta name=\"twitter:data1\" content=\"7 \u062f\u0642\u0627\u0626\u0642\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/nissa.gov.ly\\\/en\\\/main-services\\\/third-party-policy\\\/\",\"url\":\"https:\\\/\\\/nissa.gov.ly\\\/en\\\/main-services\\\/third-party-policy\\\/\",\"name\":\"Third Party Policy - \u0627\u0644\u0647\u064a\u0626\u0629 \u0627\u0644\u0648\u0637\u0646\u064a\u0629 \u0644\u0623\u0645\u0646 \u0648\u0633\u0644\u0627\u0645\u0629 \u0627\u0644\u0645\u0639\u0644\u0648\u0645\u0627\u062a\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/nissa.gov.ly\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/nissa.gov.ly\\\/en\\\/main-services\\\/third-party-policy\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/nissa.gov.ly\\\/en\\\/main-services\\\/third-party-policy\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/nissa.gov.ly\\\/wp-content\\\/uploads\\\/placeholder.png\",\"datePublished\":\"2020-01-23T12:35:11+00:00\",\"dateModified\":\"2020-04-19T20:35:18+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/nissa.gov.ly\\\/en\\\/main-services\\\/third-party-policy\\\/#breadcrumb\"},\"inLanguage\":\"ar\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/nissa.gov.ly\\\/en\\\/main-services\\\/third-party-policy\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"ar\",\"@id\":\"https:\\\/\\\/nissa.gov.ly\\\/en\\\/main-services\\\/third-party-policy\\\/#primaryimage\",\"url\":\"https:\\\/\\\/nissa.gov.ly\\\/wp-content\\\/uploads\\\/placeholder.png\",\"contentUrl\":\"https:\\\/\\\/nissa.gov.ly\\\/wp-content\\\/uploads\\\/placeholder.png\",\"width\":1153,\"height\":645},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/nissa.gov.ly\\\/en\\\/main-services\\\/third-party-policy\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/nissa.gov.ly\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Main services\",\"item\":\"https:\\\/\\\/nissa.gov.ly\\\/en\\\/main-services\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Third Party Policy\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/nissa.gov.ly\\\/#website\",\"url\":\"https:\\\/\\\/nissa.gov.ly\\\/\",\"name\":\"\u0627\u0644\u0647\u064a\u0626\u0629 \u0627\u0644\u0648\u0637\u0646\u064a\u0629 \u0644\u0623\u0645\u0646 \u0648\u0633\u0644\u0627\u0645\u0629 \u0627\u0644\u0645\u0639\u0644\u0648\u0645\u0627\u062a\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/nissa.gov.ly\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/nissa.gov.ly\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"ar\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/nissa.gov.ly\\\/#organization\",\"name\":\"\u0627\u0644\u0647\u064a\u0626\u0629 \u0627\u0644\u0648\u0637\u0646\u064a\u0629 \u0644\u0623\u0645\u0646 \u0648\u0633\u0644\u0627\u0645\u0629 \u0627\u0644\u0645\u0639\u0644\u0648\u0645\u0627\u062a\",\"url\":\"https:\\\/\\\/nissa.gov.ly\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"ar\",\"@id\":\"https:\\\/\\\/nissa.gov.ly\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/nissa.gov.ly\\\/wp-content\\\/uploads\\\/apple-touch-icon.png\",\"contentUrl\":\"https:\\\/\\\/nissa.gov.ly\\\/wp-content\\\/uploads\\\/apple-touch-icon.png\",\"width\":180,\"height\":180,\"caption\":\"\u0627\u0644\u0647\u064a\u0626\u0629 \u0627\u0644\u0648\u0637\u0646\u064a\u0629 \u0644\u0623\u0645\u0646 \u0648\u0633\u0644\u0627\u0645\u0629 \u0627\u0644\u0645\u0639\u0644\u0648\u0645\u0627\u062a\"},\"image\":{\"@id\":\"https:\\\/\\\/nissa.gov.ly\\\/#\\\/schema\\\/logo\\\/image\\\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Third Party Policy - \u0627\u0644\u0647\u064a\u0626\u0629 \u0627\u0644\u0648\u0637\u0646\u064a\u0629 \u0644\u0623\u0645\u0646 \u0648\u0633\u0644\u0627\u0645\u0629 \u0627\u0644\u0645\u0639\u0644\u0648\u0645\u0627\u062a","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/nissa.gov.ly\/en\/main-services\/third-party-policy\/","og_locale":"ar_AR","og_type":"article","og_title":"Third Party Policy - \u0627\u0644\u0647\u064a\u0626\u0629 \u0627\u0644\u0648\u0637\u0646\u064a\u0629 \u0644\u0623\u0645\u0646 \u0648\u0633\u0644\u0627\u0645\u0629 \u0627\u0644\u0645\u0639\u0644\u0648\u0645\u0627\u062a","og_description":"You can National Information Security &#038; Safety Authority policies as pdf by clicking on this link Download Third Party Access Policy Introduction This policy outlines procedures governing third-party access to (Organization) owned systems, network and applications. A third party is an organization or individual (non-permanent employee) external to the (Organization)\u00a0 The policy covers the following [&hellip;]","og_url":"https:\/\/nissa.gov.ly\/en\/main-services\/third-party-policy\/","og_site_name":"\u0627\u0644\u0647\u064a\u0626\u0629 \u0627\u0644\u0648\u0637\u0646\u064a\u0629 \u0644\u0623\u0645\u0646 \u0648\u0633\u0644\u0627\u0645\u0629 \u0627\u0644\u0645\u0639\u0644\u0648\u0645\u0627\u062a","article_modified_time":"2020-04-19T20:35:18+00:00","og_image":[{"width":1153,"height":645,"url":"https:\/\/nissa.gov.ly\/gavedug\/placeholder.png","type":"image\/png"}],"twitter_card":"summary_large_image","twitter_misc":{"\u0648\u0642\u062a \u0627\u0644\u0642\u0631\u0627\u0621\u0629 \u0627\u0644\u0645\u064f\u0642\u062f\u0651\u0631":"7 \u062f\u0642\u0627\u0626\u0642"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/nissa.gov.ly\/en\/main-services\/third-party-policy\/","url":"https:\/\/nissa.gov.ly\/en\/main-services\/third-party-policy\/","name":"Third Party Policy - \u0627\u0644\u0647\u064a\u0626\u0629 \u0627\u0644\u0648\u0637\u0646\u064a\u0629 \u0644\u0623\u0645\u0646 \u0648\u0633\u0644\u0627\u0645\u0629 \u0627\u0644\u0645\u0639\u0644\u0648\u0645\u0627\u062a","isPartOf":{"@id":"https:\/\/nissa.gov.ly\/#website"},"primaryImageOfPage":{"@id":"https:\/\/nissa.gov.ly\/en\/main-services\/third-party-policy\/#primaryimage"},"image":{"@id":"https:\/\/nissa.gov.ly\/en\/main-services\/third-party-policy\/#primaryimage"},"thumbnailUrl":"https:\/\/nissa.gov.ly\/gavedug\/placeholder.png","datePublished":"2020-01-23T12:35:11+00:00","dateModified":"2020-04-19T20:35:18+00:00","breadcrumb":{"@id":"https:\/\/nissa.gov.ly\/en\/main-services\/third-party-policy\/#breadcrumb"},"inLanguage":"ar","potentialAction":[{"@type":"ReadAction","target":["https:\/\/nissa.gov.ly\/en\/main-services\/third-party-policy\/"]}]},{"@type":"ImageObject","inLanguage":"ar","@id":"https:\/\/nissa.gov.ly\/en\/main-services\/third-party-policy\/#primaryimage","url":"https:\/\/nissa.gov.ly\/gavedug\/placeholder.png","contentUrl":"https:\/\/nissa.gov.ly\/gavedug\/placeholder.png","width":1153,"height":645},{"@type":"BreadcrumbList","@id":"https:\/\/nissa.gov.ly\/en\/main-services\/third-party-policy\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/nissa.gov.ly\/"},{"@type":"ListItem","position":2,"name":"Main services","item":"https:\/\/nissa.gov.ly\/en\/main-services\/"},{"@type":"ListItem","position":3,"name":"Third Party Policy"}]},{"@type":"WebSite","@id":"https:\/\/nissa.gov.ly\/#website","url":"https:\/\/nissa.gov.ly\/","name":"\u0627\u0644\u0647\u064a\u0626\u0629 \u0627\u0644\u0648\u0637\u0646\u064a\u0629 \u0644\u0623\u0645\u0646 \u0648\u0633\u0644\u0627\u0645\u0629 \u0627\u0644\u0645\u0639\u0644\u0648\u0645\u0627\u062a","description":"","publisher":{"@id":"https:\/\/nissa.gov.ly\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/nissa.gov.ly\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ar"},{"@type":"Organization","@id":"https:\/\/nissa.gov.ly\/#organization","name":"\u0627\u0644\u0647\u064a\u0626\u0629 \u0627\u0644\u0648\u0637\u0646\u064a\u0629 \u0644\u0623\u0645\u0646 \u0648\u0633\u0644\u0627\u0645\u0629 \u0627\u0644\u0645\u0639\u0644\u0648\u0645\u0627\u062a","url":"https:\/\/nissa.gov.ly\/","logo":{"@type":"ImageObject","inLanguage":"ar","@id":"https:\/\/nissa.gov.ly\/#\/schema\/logo\/image\/","url":"https:\/\/nissa.gov.ly\/gavedug\/apple-touch-icon.png","contentUrl":"https:\/\/nissa.gov.ly\/gavedug\/apple-touch-icon.png","width":180,"height":180,"caption":"\u0627\u0644\u0647\u064a\u0626\u0629 \u0627\u0644\u0648\u0637\u0646\u064a\u0629 \u0644\u0623\u0645\u0646 \u0648\u0633\u0644\u0627\u0645\u0629 \u0627\u0644\u0645\u0639\u0644\u0648\u0645\u0627\u062a"},"image":{"@id":"https:\/\/nissa.gov.ly\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/nissa.gov.ly\/batisur\/wp\/v2\/pages\/3600","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/nissa.gov.ly\/batisur\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/nissa.gov.ly\/batisur\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/nissa.gov.ly\/batisur\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/nissa.gov.ly\/batisur\/wp\/v2\/comments?post=3600"}],"version-history":[{"count":0,"href":"https:\/\/nissa.gov.ly\/batisur\/wp\/v2\/pages\/3600\/revisions"}],"up":[{"embeddable":true,"href":"https:\/\/nissa.gov.ly\/batisur\/wp\/v2\/pages\/3668"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/nissa.gov.ly\/batisur\/wp\/v2\/media\/3574"}],"wp:attachment":[{"href":"https:\/\/nissa.gov.ly\/batisur\/wp\/v2\/media?parent=3600"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}