Core Dimension
General Behavior (GB)
The General Behavior (GB) dimension encompasses the foundational security practices that apply to all employees.
GB1Secure Email Use
GB1.1Phishing resilience
- ✓GB1.1.1Avoids clicking on unknown links or opening mail attachments and deletes them promptly
- ✓GB1.1.2Checks elements like email domain (the part after the "@" symbol), poor grammar or spelling mistakes, etc
- ✓GB1.1.3Enables spam filters on email accounts to identify and filter out phishing emails
GB1.2Secure sending
- ✓GB1.2.1Double checks email addresses before sending
GB1.3Attachments/Link verification
- ✓GB1.3.1Scans attachments with an updated antivirus software before downloading it
- ✓GB1.3.2Enables the display of file extensions on the operating system to identify potential threats
- ✓GB1.3.3Confirms the legitimacy of the attachment with the sender before opening it
- ✓GB1.3.4Only enables macros when opening attachments from trustworthy sources
- ✓GB1.3.5Opens attachments only with applications specifically designed to handle these file types (e.g., opens PDF document with Adobe Acrobat)
- ✓GB1.3.6Hovers over the link to see the actual URL destination before clicking on it
GB1.4Official communication
- ✓GB1.4.1Uses official email address for all work-related communication
GB2Secure Browsing Practices
GB2.1Secure browsing
- ✓GB2.1.1Can identify encrypted and unencrypted websites (e.g., by looking at the https lock icon)
- ✓GB2.1.2Check for the presence of the HTTPS lock to differentiate between encrypted (HTTPS) and unencrypted (HTTP) websites
- ✓GB2.1.3Sticks to trusted and reputable websites by verifying them carefully (typos in the URLs, etc.)
- ✓GB2.1.4Makes credit card purchases only on trustworthy sites
- ✓GB2.1.5Avoids clicking on suspicious pop-ups/ads/links
- ✓GB2.1.6Does not use official SSO for personal website logins
GB2.2Secure downloads
- ✓GB2.2.1Downloads files only from reputable and official sources
- ✓GB2.2.2Double checks buttons by hovering the mouse and checking the destination URL before initiating a download
- ✓GB2.2.3Reads other user reviews for security vulnerabilities before downloading
GB3Responsible Social Media Usage
GB3.1Information sharing on social media
- ✓GB3.1.1Do not share personally identifiable information and excessive information about one's workplace on social platforms (e.g., location, contact details, etc.)
- ✓GB3.1.2Check the accuracy of the post/message before sharing
GB3.2Connection request evaluation
- ✓GB3.2.1Only connects with trusted individuals and verifies their authenticity before accepting requests
GB3.3Engaging with messages
- ✓GB3.3.1Deletes suspicious messages or links
GB4Responsible Device Management
GB4.1Secure mobile device usage
- ✓GB4.1.1Enforcing screen locks (e.g., PIN, fingerprint, or facial recognition), enabling encryption, and using security apps to safeguard device integrity
- ✓GB4.1.2Downloading apps only from trusted sources (e.g., app stores) and reviewing app permissions before installation
- ✓GB4.1.3Following workplace policies related to mobile device security
- ✓GB4.1.4Ensure regular data backups
- ✓GB4.1.5Ensure secure disposal of mobile devices
GB4.2Secure computer usage
- ✓GB4.2.1Adhering to computer usage policies and guidelines set by the organisation
- ✓GB4.2.2Regularly performing system maintenance tasks such as disk cleanup, defragmentation (if applicable), and hardware checks
- ✓GB4.2.3Protecting computers from physical theft or tampering
GB4.3Secure IoT usage
- ✓GB4.3.1Changes the provided default credentials immediately after setting up an IoT device
- ✓GB4.3.2Regularly updates the firmware and software of each IoT devices
- ✓GB4.3.3Creates separate network segments or VLANs (Virtual Local Area Network) for IoT devices
- ✓GB4.3.4Disables IoT devices when not in use
- ✓GB4.3.5Regularly checks and reviews permissions granted to IoT devices
- ✓GB4.3.6Properly researches various IoT devices available in the market before purchasing one
GB4.4Secure disposal of assets
- ✓GB4.4.1Follows organization protocols for the secure disposal of hardware and storage media
GB5Secure Remote Work
GB5.1Secure Wifi usage
- ✓GB5.1.1Avoids connecting to open or unsecured networks
- ✓GB5.1.2Employs a strong and unique WiFi password for own networks
GB5.2Secure VPN usage
- ✓GB5.2.1Uses a trusted VPN service
- ✓GB5.2.2Connects to a VPN while using an unfamiliar network
GB5.3Secure online meetings
- ✓GB5.3.1Double checks the participant list to verify that only intended participants are being invited to the meeting
- ✓GB5.3.2Reviews participants using the waiting room feature before adding them to the meeting
- ✓GB5.3.3Restricts file transfers, chat capabilities as necessary during meetings
- ✓GB5.3.4Asks for consent before recording meetings
GB6Secure AI/LLM Usage
GB6.1Secure usage of research assistants (GPT)
- ✓GB6.1.1Does not copy and paste information as it is from AI/LLM platforms
- ✓GB6.1.2Is careful enough to not divulge highly confidential business information/personally identifiable information to AI/LLM platforms
- ✓GB6.1.3Regularly review permissions
GB6.2Document review
- ✓GB6.2.1Removes personally identifiable information or sensitive data from documents before uploading them to the AI/LLM platforms
GB7Logical Access Control
GB7.1Access credentials management
- ✓GB7.1.1Creates complex passwords with or without enforcement
- ✓GB7.1.2Does not write down passwords or store in a soft copy
- ✓GB7.1.3Creates separate passwords across accounts
- ✓GB7.1.4Pro-actively uses a password manager
- ✓GB7.1.5Changes password diligently when prompted by the system or application
- ✓GB7.1.6Using encryption measures for data protection (TLS, SSL, etc.)
- ✓GB7.1.7Opts for MFA even when it is only an option
- ✓GB7.1.8Selects the most secure MFA option (e.g., OTP generated by app rather than SMS)
- ✓GB7.1.9Select the SSO option for signing-in for all work-related accounts
- ✓GB7.1.10Keeps up-to-date with SSO best practices and guidelines
GB8Physical Access Control
GB8.1Access card management
- ✓GB8.1.1Stores physical access cards in secure places when not in use
- ✓GB8.1.2Does not share own or use others' access cards
- ✓GB8.1.3Promptly reports lost or stolen access cards
- ✓GB8.1.4Makes use of the appropriate channel to report lost or stolen cards
GB8.2Secure access to facilities
- ✓GB8.2.1Use secure and authorized methods (such as biometrics, PINs, or access cards) to authenticate identity before gaining physical access
- ✓GB8.2.2Adhere to the escort policy, ensuring that authorized personnel accompany visitors within secure areas for compliance
- ✓GB8.2.3A systematic approach is followed to register all visitors and issue temporary access credentials when entering secure areas
- ✓GB8.2.4Prioritise safety by not misusing emergency exits for unauthorized access or exit, enhancing safety protocols
- ✓GB8.2.5Lock office doors, filing cabinets, or other secure areas when they are not in use, especially in shared or open spaces
- ✓GB8.2.6Ensure that all security cameras and surveillance systems are operational and avoid tampering with it
GB9Secure Information Management
GB9.1Information categorization
- ✓GB9.1.1Classify information based on its sensitivity
GB9.2Information permissions
- ✓GB9.2.1Sets appropriate file permissions and access levels for documents and folders
- ✓GB9.2.2Double-checks to ensure that the correct file permissions are enabled before sharing the files or folders with others
GB9.3Information sharing
- ✓GB9.3.1Checks recipient addresses before sending files
- ✓GB9.3.2Uses strong passwords to secure the file sharing account
- ✓GB9.3.3Uses only company approved information sharing channels
GB10Choosing Third-Party Services
GB10.1Vendor evaluation
- ✓GB10.1.1Evaluating and assessing potential vendors
GB10.2Secure software installation
- ✓GB10.2.1Avoids downloading software from third-party websites or unverified sources
- ✓GB10.2.2Reads permissions or privileges requested by software to asses whether it aligns with its intended functionality
- ✓GB10.2.3Carefully reviews installation prompts and deselects the optional software
- ✓GB10.2.4Conduct a thorough assessment of the vendor's reputation, security practices, and track record
- ✓GB10.2.5Ensure that vendor contracts include clear security obligations and service level agreements (SLAs)
GB10.3Software security check
- ✓GB10.3.1Updating, maintaining, and upgrading software to ensure it functions correctly
GB11Incident Management
GB11.1Incident detection
- ✓GB11.1.1Establishes baseline behaviors and uses anomaly detection mechanisms to identify deviations
- ✓GB11.1.2Conducts periodic vulnerability assesments and addresses the identified vulnerabilities promptly
- ✓GB11.1.3Identify signs of threats like deepfake, vishing, smishing etc
GB11.2Incident classification
- ✓GB11.2.1Categorise incidents based on their impact and potential harm
- ✓GB11.2.2Inform IT, security team, and management, about the incident's classification and severity
GB11.3Incident reporting
- ✓GB11.3.1Establishes a well-defined process for reporting security incidents within the organization
- ✓GB11.3.2Promptly report security incidents to the IT/Security team
- ✓GB11.3.3Opens multiple incident reporting channels
GB11.4Incident containment
- ✓GB11.4.1Isolating affected systems or networks to prevent further spread of the threat
- ✓GB11.4.2Address vulnerabilities that may have been exploited by the attacker to prevent reinfection
GB12Data Privacy
GB12.1Secure data handling
- ✓GB12.1.1Handle data according to the organizational policies
GB12.2Data subject rights
- ✓GB12.2.1Ensure data subject rights such as the right to access correct or delete their personal data
GB12.3Data protection and privacy compliance
- ✓GB12.3.1Consistently adheres to data protection laws and regulations, including GDPR, PDPA, and other relevant legislation
- ✓GB12.3.2Adhere to regulatory guidelines for complaint resolution
- ✓GB12.3.3Regularly conducts privacy impact assessments and updates data protection policies
GB12.4Legal compliance and reporting
- ✓GB12.4.1Proactively identify, report, and address any potential legal compliance issues or violations to the appropriate authority or compliance officer as required by law
GB13Data Governance and Ethics
GB13.1Adherence to guidelines
- ✓GB13.1.1Complies to data privacy rules and regulations of the land when working with sensitive data
- ✓GB13.1.2Follow organization protocol for software installation, pilot test, etc.
GB13.2Ethical data use
- ✓GB13.2.1Avoids introducing biases into data processing, ensuring fairness and objectivity in decision-making
- ✓GB13.2.2Is transparent about how data is used and ensures the data use aligns with ethical standards
GB14Information Validation
GB14.1Credibility check
- ✓GB14.1.1Cross-checks multiple reliable sources to verify information credibility
- ✓GB14.1.2Contacts official channels for information related to organizations or government entities to verify its authenticity
GB14.2Secure online research
- ✓GB14.2.1Looks for verifiable data, credible research, and reliable sources cited within the information
- ✓GB14.2.2Pays attention to timestamps of articles, posts, videos to ensure the information is relevant