Purpose
The purpose of this policy is to establish a set of guidelines for Systems Committee volunteers and other personnel with elevated access rights to guide them in their use of their privileged access. The policy aims to protect the confidentiality, integrity and availability of the OTW’s systems and resources, ensure that access is used responsibly, and that use of privileged access is within the scope of authorized duties.
Scope
This policy covers all OTW volunteers who are given privileged administrative access to Systems Committee managed resources as part of their role, including but not limited to: servers, networking equipment, internal tools or applications, cloud services, data stores, etc.
Policy
Accounts
Where possible, privileged administrative access will be given to individual accounts rather than shared accounts so that actions may be traceable to individual account holders. Where this is not possible or feasible, shared administrative accounts may be created. If a shared account is used, the account’s authentication credentials (e.g. password) must be communicated in a secure fashion (such as 1Password), and the credentials must be rotated whenever a volunteer’s access is revoked.
Authorized Use
Privileged administrative access, whether on an individual account or via a shared account, must only be used to perform duties within the scope of the volunteer’s role. In other words, there must be a justifiable, work-related reason to utilize your privileged access. When such a justification exists, explicit authorization is not required unless the request involves data restoration.
Access to systems, applications or data that is not within the scope of the volunteer’s role must be authorized by the Systems Chair(s) or the chair(s) of the committee that Systems is sharing the tool with.
Authorization for Data Restoration
Requests for restoration of data requires explicit authorization from the appropriate parties:
- OTW internal data restoration (internal wiki, committee backups, etc) – Chair(s) of the committee overseeing the internal tool, or assigned delegates from that committee
- Internal/public data restoration as a result of emergencies or accidental deletion by sysadmins – Systems Chair(s)
- Public service (AO3, Fanlore, etc) data restoration outside of emergencies or accidental deletion by sysadmins – Legal Committee
Confidentiality
While performing assigned duties, volunteers with privileged administrative access will be exposed to potentially sensitive or private information. All such information must be treated as confidential, and volunteers must not share, disclose or discuss it with others unless there is a justifiable, work-related reason to do so, or consent has been provided by the subject of the data.
Any breach of confidentiality must be reported to the Systems Chair(s) immediately.
Providing, Modifying & Revoking Access
Privileged administrative access will be granted to volunteers in roles specifically authorized by the Systems Chair(s). These may be roles in other committees that utilize Systems Committee tools. The level of privileged access may be modified at any time by the discretion of the Systems Chair(s).
Volunteers will have their privileged access revoked when they are no longer in an authorized role. In the case of roles in other committees which utilize Systems’ tools, the other committee’s chair(s) may also request revocation of privileged access at any time. Likewise, the Systems Chair(s) may revoke access at any time. In the event of an emergency, the OTW Board of Directors or Volunteers & Recruiting may request revocation of privileged access, which can be effected by any Systems volunteer.
Access Monitoring & Auditing
All use of privileged access is subject to monitoring, logging and auditing to ensure compliance with this policy. Volunteers are expected to cooperate in the event of an audit or investigation related to their use of privileged access.
Enforcement
Any misuse of privileged access should be reported to the Systems Chair(s), or alternatively through normal OTW reporting protocols. If a volunteer is found to have intentionally used their access in a manner not permitted by this policy, their access will be immediately revoked. Further disciplinary action may be taken in accordance with normal OTW disciplinary procedures. Any disputes regarding the enforcement of this policy may be heard and resolved by the OTW Board of Directors or their designates.