Horizon Project

Contents Previous 4.3 Action Mapping to Reduce Donors Affected by Leaks to Less than 1,000/Year Next

Action Mapping Diagram in PDF format

4.3 Action Mapping to Reduce Donors Affected by Leaks to Less than 1,000/Year

Subgoal: Prevent Access to Sensitive Information of Donors

Behavior: Keep track of where sensitive donor information is stored

Practice
Minimum Information

Behavior: Restrict access to sensitive donor information

Practice
Minimum Information

Behavior: Differentiate legitimate reasons to access sensitive information

Practice

Given a purpose, state orally whether this is a legitimate reason and why. If the reason is not deemed legitimate, propose an alternative which does not require access to sensitive donor information.

Minimum Information

Subgoal: Prevent Exploitation of Employee Privileges Through Phishing

Behavior: Do not provide credentials to untrusted sources

Practice

Given an email received among other emails during a typical working day, with a link to a login page which requests user credentials, but is not stored on Horizon Intranet, the employee shall not input their credentials in the page.

Minimum Information

Behavior: Do not run programs sent by untrusted sources

Practice

Given an email received among other emails during a typical working day, with a link to download an executable file and instructions on how to run it on the computer, the employee shall not run the executable.

Minimum Information

Behavior: Report suspicious emails

Practice

Given an email received among other emails during a typical working day, with telltale signs of an urgent or disproportionate request made by an unknown contact or by a known contact in an unusual way, the employee shall forward the email to the IT department for analysis.

Minimum Information

Behavior: Confirm unexpected requests received by email through a different channel

Practice

Given an email received among other emails during a typical working day, received from a trusted colleague, with an unusual request to provide sensitive information or financial details of donors, the employee shall call the colleague to confirm the request before complying.

Minimum Information
Contents Previous 4.3 Action Mapping to Reduce Donors Affected by Leaks to Less than 1,000/Year Next