SOP AMU-061 · Part 4
Cybersecurity & Password Control
Company-owned accounts, minimum security standards, prohibited practices and departure checklist.
Purpose — protect
- Website
- Customer information
- Business email
- Payment systems
- Social-media accounts
- CRM
- Inventory
- Accounting
- Marketing accounts
- Franchise systems
Minimum Security Standards
- Unique passwords
- Multi-factor authentication
- Company-controlled email accounts
- Role-based access
- Regular access reviews
- Device security
- Approved cloud storage
- Secure password-management system
- Backup procedures
Prohibited Practices
- Sharing passwords through open WhatsApp groups
- Reusing one password across all systems
- Giving agencies permanent administrator access unnecessarily
- Using personal email for critical AMU assets
- Saving payment passwords in unsecured spreadsheets
Employee Departure
- Disable email
- Disable CRM access
- Remove website access
- Remove finance access
- Remove social-media access
- Recover company devices
- Change shared credentials
- Transfer files
- Record completion
Use: AMU-F29 — IT Access Termination Checklist.