Document aBOLOeagnboL1604pXeO5dQoa
DO A 0P76P3 CONFTDFNTT Al...
Louisiana Division October 4, 1993
TO: All Superintendents
RE: SECURITY AUDIT QUESTIONNAIRE
As part of the Division's Consolidated Audit program, the attached questionnaire is a tool for each plant/department to use in evaluating where they are on Security/Emergency Response requirements, and what plans and actions would be required to achieve the Corporate Minimum Requirement.
To explain the compliance portion of the audit, the following numbered breakdown of the questions has been established:
1 - Does Not Exist 2 - Meets 25% of the requirements 3 - Meets 50% of the requirements 4 - Meets 75% of the requirements 5 - Meets 100% of the requirements
The questions listed are there to generate thought and are not intended to be a complete list. Please answer all questions honestly, and refer to the source material for more detail. If you have further questions on this, please contact me.
A1 Lott Security/Emergency Services
Restricted For Use Within Dow
DO A
CONF T
denttal
U.S. AREA CONSOLIDATED AUDIT
SECURITY/EMERGENCY SERVICES
SOURCE: Corporate Security Minimum Requirements
POLICY: The control of Dow assets, process technology, manufacturing know-how and other proprietary information is a fundamental responsibility of all Dow employees. Supervision is responsible to develop a line driven Security Program to control these assets, and provide a secure working environment.
A. Access Control:
Compliance Level (1,23,4 or 5)
Previous/Currem
1. Do all Dow employees wear badges? 2. Do all Contractor employees wear badges? 3. Are all visitors (Government, consultants, joint
ventures, plant tours) escorted, and do they have a pass? Explain your process.________________________
4. Do control room personnel challenge "strangers"? 5. Do you use the sign-in/out procedure? 6. Do truck drivers wait/deliver in a non
sensitive area? 7. Do you have any restricted areas in your block/
unit/plant? 1. If yes, identify. __________________________ 2. How many people have access to these
areas? 3. Are your procedures adequate? 8. Do you have adequate locks/locking devices on doors, gates and storage? Are these locks part of the site's access control systems?
8/2/94
DOW CONFIDENTIAL
Page 1
DO o
C0^1DFNTTAL
U.S. AREA CONSOLIDATED AUDIT - SECURITY
9. Do you have adequate after hours access control?
Explain your process.
Previous/Current
_______1
B. Computer Security:
Previous/CuTrem
1. Do you have policies in place to insure data integrity by determining who can access information and change programs?
2. Do you control who has access to your computer systems?
3. Do you have provisions in place to recover data in the event of a disaster which could include physical damage or loss of memory?
4. Is your computer data backed up routinely and do you have remote storage?
5. Are your computer systems password protected? 6. Are passwords deleted as soon as employees
terminate or transfer from the department?
Explain your process. ______________
7. Is the hard disk free of data before the computer is sent out for repairs?
Explain your process. _______ _________________ _
8. Do you have adequate administrative controls for accessing your computer: Passwords? Virus protection? Maintenance protocol? Remote access policy? Subsidiaries access? Use by non-Dow personnel?
Explain your process. ________
8/2/94
DOW CONFIDENTIAL
Page 2
DO A 0 CONFTDFNTTAl.
U.S. AREA CONSOLIDATED AUDIT - SECURITY
Previous/Current
9. Are any terminals left on line in non-secured areas? 10. Are security breaches reported? 11. Does your electronic data meet the records
retention policy? Explain your process.______________________________
C. Crime and Fraud:
1. Are employees aware of their responsibilities to report any loss or potential loss of Dow assets?
2. Do you have a tool and equipment identification policy?
Explain your process.
_____ ____________
3. Are serial numbers recorded for high profile equipment (computers, analytical balances, VCR's, TV's, radios, projectors)?
4. Is this equipment adequately secured when not in use?
5. Are employees aware of the consequences of being involved in crime and fraud against Dow?
6. Are potential conflicts of interest known and adequately covered?
D. Data and Informational Transmission Systems
1. Have you considered the sensitivity of TELEX, facsimile and mail information, and are adequate control measures taken?
8/2/94
DOW CONFIDENTIAL
Page 3
DO A 027C27 oonftdfnttai
U.S. AREA CONSOLIDATED AUDIT - SECURITY
E. Material Control:
Previous/Current
1. Is there adequate separation of authority to deter fraud
(i.e,, separate individuals to order, receive and authorize payment)? ____
2. Is there an inventory and material control system
in place for inventory, materials, equipment and
scrap?
___
3. Are measurement systems adequate to control
inbound and outbound materials, supplies and
products?
___
F. Proprietary Information Control:
1. Classification
Have all employees been indoctrinated into the program classifying proprietary information as "Dow Restricted", "Dow Confidential" and "Dow Controlled?"
Are all pages of documents classified "Dow Confidential" so marked ?
Are proper auditing systems established for documents classified "Dow Confidential," covering generation, handling, storage and disposal?
8/2/94
DOW CONFIDENTIAL
DO A 027678 OONFTDFNTTAI
Page 4
U.S. AREA CONSOLIDATED AUDIT - SECURITY
F. Proprietary Information Control, cont.:
2. Do you have written procedures for:
Previous/Current
Indoctrinating all employees as to the proper
generation, handling, storage, and disposal of Dow
Confidential documents by Plant management?
Have all employees been indoctrinated?
Control of filming and taking photographs
within your plant?
_____________
Release of proprietary information outside
of Dow and to Government agencies?
3. Are your control diagrams or programs kept and
disposed of in a secure fashion?
_____________
4. Area Piping and Instrument Diagrams:
Released only through the manufacturing Rep.
and returned for disposal when no
longer needed?
_____________
Are P&ID's stamped "Dow Confidential -
Do Not Copy"?
_____________
Are all copies of P&ID's released traceable
through a document release numbering system?
Do you control to whom these documents are
released and who they are?
_____________
5. Do you have any Government classified
contracts/information and property?
Is it stored and handled to meet Government
requirements?
_____________
6. Are any of your operations subject to the export/
import controls? Movement of information,
materials and people across transnational borders.
Are controls adequate?
_____________
8/2/94
DOW CONFIDENTIAL
Page 5
00 A 027629 CONFIDENTIAL
U.S. AREA CONSOLIDATED AUDIT - SECURITY
F. Proprietary Information Control, cont.:
Previous/Current
7. Are any employees involved in competitive
intelligence gathering?
_________
If yes, are they aware of the Dow publication,
"Guideline for Gathering Competitive Information",
Appendix F in the Guideline for Handling Dow
Proprietary Information?
_____________
8. Have the requirements of the Dow Secrecy
Agreement been reviewed with each employee
in the past two years?
_____________
G. Travel
1. Are department members engaged in international travel aware of security related information which is available to them from their local Security Department?
_______ |
H. What are the three major security concerns of your department/area?
I. Do you feel the security program at the site, and in your area in particular, is reasonable and appropriate? Why or why not?
8/2/94
DOW CONFIDENTIAL
Page 6
00 A 037630 CONFIDENTIAL
U.S. AREA CONSOLIDATED AUDIT - SECURITY
REFERENCES
Minimum Requirements for SLP&S (Corporate S/LP/S)
Guidelines for Handling of Dow Proprietary Information (Corporate
S/LP/S)
Computer Security Policies and Procedures (Corporate S/LP/S)
Guidelines for Gathering Competitive Information (Patent Dept.)
Security ... in Office and Data Handling Areas (Corporate S/LP/S)
The Dow Chemical Company CRI Guidelines (Technical Inform. Service)
Guidelines for Emergency Planning (Corporate S/LP/S)
Trade Secrets and Other Confidential Information at Dow (Patent
Dept.)
Records Management Program Handbook (Records Management)
Comptrollers -- Accounting Policy and Procedures (Corporate
Controllers Department)
Industrial Security Manual for Safeguarding Classified Information
(U.S. Government Department of Defense)
Faxing Guidelines for Propriety Information
Export/Import Reference Manual (Patent Dept.)
Guidelines for Safety, Loss Prevention and Security Reporting
(Corporate S/LP/S)
Office Procedures Manual (Dow USA Headquarters -- Bulk Literature
Form Number 16600115)
Local Publications: Common Sense Security for Michigan Division Employees (Michigan Division Security)
Document Creation
8/2/94
DOW CONFIDENTIAL
Page 7
00 A 027631 CONFIDENTIAL