Document 2jmr87x6MYjEDXmokQ08N2957
Security Aduit Question naire
Louisiana Division October 4, 1993
TO: All Superintendents
RE: SECURITY AUDIT QUESTIONNAIRE
As part of the Division's Consolidated Audit program, the attached questionnaire is a tool for each plant/department to use in evaluating where they are on Security/Emergency Response requirements, and what plans and actions would be required to achieve the Corporate Minimum Requirement.
To explain the compliance portion of the audit, the following numbered breakdown of the questions has been established:
1 - Does Not Exist 2 - Meets 25% of the requirements 3 - Meets 50% of the requirements 4 - Meets 75% of the requirements 5 - Meets 100% of the requirements
The questions listed are there to generate thought and are not intended to be a complete list. Please answer all questions honestly, and refer to the source material for more detail. If you have further questions on this, please contact me.
A1 Lott Security/Emergency Services
Restricted For Use Within Dow
o 4 CONFxt
U.S. AREA CONSOLIDATED AUDIT
SECURITY/EMERGENCY SERVICES
SOURCE: Corporate Security Minimum Requirements
POLICY: The control of Dow assets, process technology, manufacturing know-how and
other proprietary information is a fundamental responsibility of all Dow employees. Supervision
is responsible to develop a line driven Security Program to control these assets, and provide a
secure working environment.
A. Access Control:
Compliance Level (1,2,3,4 or S)
Previous/Current
1. Do all Dow employees wear badges?
4______________
2. Do all Contractor employees wear badges?
5______________
3. Are all visitors (Government, consultants, joint
ventures, plant tours) escorted, and do they have a
pass?
5______________
Explain your process. All visitors must sign in and be escorted unless that visitor has
been properly indoctrinated and the host has determined that they are approved and
qualified to be in the block without an escort.
4. Do control room personnel challenge "strangers"?
5.
5. Do you use the sign-in/out procedure?
6. Do truck drivers wait/deliver in a non
3
sensitive area?
7. Do you have any restricted areas in your block/ unit/plant?
yes_
1. If yes, identify. The cell area is a restricted access area.
2. How many people have access to these
areas? 3. Are your procedures adequate?
All Dow employees, 4__________
8. Do you have adequate locks/locking devices
on doors, gates and storage?
Are these locks part of the site's access
control systems?
9/23/96
DOW CONFIDENTIAL
U.S. AREA CONSOLIDATED AUDIT - SECURITY
9. Do you have adequate after hours access
control?
2.
Explain your process. ___________________________________________
B. Computer Security:
Previous/Current
1. Do you have policies in place to insure data integrity by determining who can access information and change programs?
2. Do you control who has access to your computer systems?
3. Do you have provisions in place to recover data in the event of a disaster which could include physical damage or loss of memory?
4. Is your computer data backed up routinely and do you have remote storage?
5. Are your computer systems password protected? 6. Are passwords deleted as soon as employees
terminate or transfer from the department?
5. 5,
5, 5. 5, 5.
Explain your process.___________________________________________
7. Is the hard disk free of data before the computer is sent out for repairs?
5,
Explain your process.___________________________________________
8. Do you have adequate administrative controls for accessing your computer: Passwords? Virus protection? Maintenance protocol? Remote access policy? Subsidiaries access? Use by non-Dow personnel?
Explain your process. N/A Work Station program.
5. 5, 5. 5. 5, 5
Previous/Current
9/23/96
DOW CC JENUAL
Page 2
D A 0431 CONFrDFNTTAl'
U.S. AREA CONSOLIDATED AUDIT - SECURITY
9. Are any terminals left on line in non-secured areas? 10. Are security breaches reported? 11. Does your electronic data meet the records
retention policy?
5______________ 5______________
4______________
Explain your process. Individual responsibility to comply and annual spot audits for
compliance.
C. Crime and Fraud:
1. Are employees aware of their responsibilities to report any loss or potential loss of Dow assets?
2. Do you have a tool and equipment identification policy?
5. 5.
Explain your process._________________________________________
3. Are serial numbers recorded for high profile equipment (computers, analytical balances, VCR's, TV's, radios, projectors)?
4. Is this equipment adequately secured when not in use?
5. Are employees aware of the consequences of being involved in crime and fraud against Dow?
6. Are potential conflicts of interest known and adequately covered?
5. 5, 5, 5,
D. Data and Informational Transmission Systems
1. Have you considered the sensitivity of TELEX, facsimile and mail information, and are adequate control measures taken?
5.
E. Material Control:
1. Is there adequate separation of authority to deter fraud
9/23/96
DOW CONFIDENTIAL
Previous/Current
Page 3
00 A 043 136 confident T At.
U.S. AREA CONSOLIDATED AUDIT - SECURITY
(i.e., separate individuals to order, receive and authorize payment)?5
2. Is there an inventory and material control system in place for inventory, materials, equipment and scrap?
3. Are measurement systems adequate to control inbound and outbound materials, supplies and products?
5, 5,
F. Proprietary Information Control:
1. Classification
Have all employees been indoctrinated into the program classifying
proprietary information as "Dow Restricted", "Dow
Confidential" and "Dow
Controlled?" yes
Are all pages of documents classified "Dow Confidential" so yes
marked?
Are proper auditing systems established for documents classified "Dow Confidential," covering generation, handling, storage and disposal? Yes
9/23/96
DOW CONFIDENTIAL
Page 4
DO A 040127 CONFTDFNTIAl
U.S. AREA CONSOLIDATED AUDIT - SECURITY
F. Proprietary Information Control, cont.:
2. Do you have written procedures for:
Previous/Current
Indoctrinating all employees as to the proper
generation, handling, storage, and disposal of Dow
Confidential documents by Plant management?
5,___
Have all employees been indoctrinated?
5____
Control of filming and taking photographs
within your plant?
5____
Release of proprietary information outside
of Dow and to Government agencies?
5____
3. Are your control diagrams or programs kept and
disposed of in a secure fashion?
5____
4. Area Piping and Instrument Diagrams:
Released only through the manufacturing Rep.
and returned for disposal when no
longer needed?
5.
Are P&ID's stamped "Dow Confidential -
Do Not Copy"?
5.
Are all copies of P&ID's released traceable
through a document release numbering system?_____________5
Do you control to whom these documents are
released and who they are?
5.
5. Do you have any Government classified contracts/information and property?
Is it stored and handled to meet Government requirements? 6. Are any of your operations subject to the export/
import controls? Movement of information, materials and people across transnational borders. Are controls adequate?
N/A N/A
N/A
9/23/96
DOW CONFIDENTIAL
DO A 043128 CONFIDENTIAL
"5
U.S. AREA CONSOLIDATED AUDIT - SECURITY
F. Proprietary Information Control, cont.:
Previous/Current
7. Are any employees involved in competitive intelligence gathering? If yes, are they aware of the Dow publication, "Guideline for Gathering Competitive Information", Appendix F in the Guideline for Handling Dow Proprietary Information?
8. Have the requirements of the Dow Secrecy Agreement been reviewed with each employee in the past two years?
N/A N/A
5.
G. Travel
1. Are department members engaged in international travel aware of security related information which is available to them from their local Security Department?
H. What are the three major security concerns of your department/area? L After hour access to front office building. 2. After hour access to warehouse area and materials,
I. Do you feel the security program at the site, and in your area in particular, is reasonable and appropriate? Why or why not?
Yes.
9/23/96
DOW CONFIDENTIAL
A 0431?g CONFTDFNTTAl
Page 6
U.S. AREA CONSOLIDATED AUDIT - SECURITY
REFERENCES
Minimum Requirements for SLP&S (Corporate S/LP/S)
Guidelines for Handling of Dow Proprietary Information (Corporate S/LP/S)
Computer Security Policies and Procedures (Corporate S/LP/S)
Guidelines for Gathering Competitive Information (Patent Dept.)
Security ... in Office and Data Handling Areas (CorporateS/LP/S)
The Dow Chemical Company CRI Guidelines (Technical Inform. Service)
Guidelines for Emergency Planning (Corporate S/LP/S)
Trade Secrets and Other Confidential Information at Dow (Patent Dept.)
Records Management Program Handbook (Records Management)
Comptrollers -- Accounting Policy and Procedures (Corporate
Controllers Department)
Industrial Security Manual for Safeguarding Classified Information
Government Department ofDefense)
(U.S.
Faxing Guidelines for Propriety Information
Export/Import Reference Manual (Patent Dept.)
Guidelines for Safety, Loss Prevention and Security Reporting (Corporate S/LP/S)
Office Procedures Manual (Dow USA Headquarters - Bulk Literature
Form Number 16600115)
Local Publications: Common Sense Security for Michigan Division
(Michigan Division Security)
Employees
Document Creation
A 043130 CONFTDFNTTA!
9/23/96
DOW CONFIDENTIAL
Page 7