You are on page 1of 3

YMDDIRIEDOLAETH GIG CEREDIGION A CHANOLBARTH CYMRU

CEREDIGION AND MID WALES NHS TRUST

VIRUS PROTECTION POLICY

Author Head of IT Equality Impact Low


Original Date September 2003 Equality assessment No
This Revision November 2005 done
Next Review Date November 2008 Review Body IM&T Steering Group
Approved by IM&T Steering Group Policy Number IMT12
Date of Approval November 2005 Classification IM&T
Virus Protection Policy

Purpose

The IT Security Standards in NHS Wales (currently moving towards BS7799) specify IT Security
Standards for NHS Organizations in Wales, and Virus Protection is a particularly important factor.
Non-compliance with this standard could mean an NHS organization is removed from the DAWN
Wide Area Network.

This Policy has been developed to manage the way in which the Trust complies with this standard.

This Policy supplements the PC Security Policy (IMT07) and provides specific information about
how the Trust manages the potential risk of Virus infection.

Scope

This policy applies to all employees of the Trust in all locations including the Non-Executive
Directors, temporary employees, locums and contracted staff.

Methods of Protection

All PC’s and Files Servers will be protected by Anti-virus software. The current virus protection
software used by the Trust is Sophos Anti-virus.

A member of IT will load the latest version of the software onto all PCs upon installation.
Departments that have purchased (or received) PCs that have not been taken to the IT Department
for installation must ensure that an IT Technician loads the latest version of the Virus software onto
the PC, Laptop or PDA.

PCs will be updated automatically by the central virus software installation servers where possible,
if this is not possible then users will be shown how to update there virus software with the minimum
of intervention of their part.

Where PCs, laptops or PDAs are not connected to either the Trust LAN (or WAN) then virus
protection software must be supplied to them by another means. Users requiring this arrangement
must contact the IT Helpdesk on 5444 for further information.

All removable media that will be used on PCs must first be virus scanned to ensure that there are no
viruses resident on the media.

All E-mail attachments must first be virus scanned before opening, failure to do so could result in a
major security incident.

The IT department recommends that files only be downloaded from the internet if absolutely
necessary. All files downloaded from the internet must be virus scanned prior to opening.

The virus detection software is designed to start-up automatically when the PC starts up; this is to
ensure that the PC is protected at all times.

Virus Protection Policy 1


Any interference with the running of the virus software including shutting it down or removal from
the PC could lead to a serious security incident and may be subject to the Trust’s Disciplinary
procedure.

Virus detection (or suspected infection)

In the event that a virus is found or suspect on a users PC, they should contact the IT Helpdesk
immediately.

The user must follow the instruction of the IT staff, which may involve ceasing all work on the PC
and labelling it so that other people do not attempt to use it.

If the PC is connected to the Network (or via Secure ID) they must disconnect immediately, i.e. if
connected to the Network remove Network cable from the wall or if using Secure ID disconnect the
modem.

The IT department will investigate the incident and will undertake any remedial work to resolve the
issue.

Equality

The Trust recognises the diversity of the local community and those in its employ. Our aim is
therefore to provide a safe environment free from discrimination and a place where all individuals
are treated fairly, with dignity and appropriately to their need. The Trust recognises that equality
impacts on all aspects of its day to day operations and has produced an Equality Policy Statement to
reflect this. All policies and procedures are assessed in accordance with the Equality initial
screening toolkit, the results for which are monitored centrally.

This policy has undergone the initial screening process in line with the Trust’s Race Equality
Scheme and has shown a low level of impact.

Training and awareness

ƒ The requirement of this policy will be brought to the attention of staff via the Trust’s
induction training programme.
ƒ Periodic reminders of this policy will be distributed in line with existing communication
channels in the Trust.
ƒ A copy of this policy will be available to all staff via the Trust’s Intranet web pages.
ƒ Awareness of the policy will be raised through Hysbysrwydd and Team Brief.

8. Review

This policy will be reviewed in 3 years time. Earlier review may be required in response to
exceptional circumstances, organisational change or relevant changes in legislation or guidance.

9. Discipline

Breaches of this policy will be investigated and may result in the matter being treated as a
disciplinary offence under the Trust’s disciplinary procedure.

Virus Protection Policy 2

You might also like