Facility Access and Physical Security¶
2024.1
Very is a fully remote company with no physical facilities. However we still provide guidelines for remote working.
All workforce members are responsible for reporting any incident of unauthorized visitor and/or unauthorized access to Very’s equipment at the user’s remote workplace.
Controls and Procedures¶
Physical Security¶
Access Requirements Overview¶
-
Workstation Security
- Workstations may only be accessed and utilized by authorized workforce members to complete assigned job/contract responsibilities.
- All workforce members are required to monitor workstations and report unauthorized users and/or unauthorized attempts to access systems/applications as per the System Access Policy.
- All workstations purchased by Very are the property of Very and are distributed to users by the company.
Data Center Security¶
Physical security of data centers is ensured by the cloud infrastructure service provided, AWS.
Clean Desk Policy and Procedures¶
Employees must secure all sensitive/confidential information in their workspace at the conclusion of the work day and when away from their workspace. This includes both electronic and physical information such as:
- computer workstations, laptops, and tablets
- removable storage devices including CDs, DVDs, USB drives, and external hard drives
- printed materials
Computer workstations/laptops must be locked (password protected) when physically unattended. Portable devices such as laptops and tablets should be taken home at the conclusion of the work day.
Removable storage devices and printed documents must be treated as sensitive material and locked in a drawer or similar when not in use. Printed materials must be immediately removed from printers or fax machines. Passwords must not be written down or stored physically.
Keys and access cards used for access to sensitive or restricted information/areas must not be left unattended anywhere in the office.