Security Quotient
Core Dimension

General Behavior (GB)

The General Behavior (GB) dimension encompasses the foundational security practices that apply to all employees.

GB1Secure Email Use

GB1.1Phishing resilience

  • GB1.1.1Avoids clicking on unknown links or opening mail attachments and deletes them promptly
  • GB1.1.2Checks elements like email domain (the part after the "@" symbol), poor grammar or spelling mistakes, etc
  • GB1.1.3Enables spam filters on email accounts to identify and filter out phishing emails

GB1.2Secure sending

  • GB1.2.1Double checks email addresses before sending

GB1.3Attachments/Link verification

  • GB1.3.1Scans attachments with an updated antivirus software before downloading it
  • GB1.3.2Enables the display of file extensions on the operating system to identify potential threats
  • GB1.3.3Confirms the legitimacy of the attachment with the sender before opening it
  • GB1.3.4Only enables macros when opening attachments from trustworthy sources
  • GB1.3.5Opens attachments only with applications specifically designed to handle these file types (e.g., opens PDF document with Adobe Acrobat)
  • GB1.3.6Hovers over the link to see the actual URL destination before clicking on it

GB1.4Official communication

  • GB1.4.1Uses official email address for all work-related communication

GB2Secure Browsing Practices

GB2.1Secure browsing

  • GB2.1.1Can identify encrypted and unencrypted websites (e.g., by looking at the https lock icon)
  • GB2.1.2Check for the presence of the HTTPS lock to differentiate between encrypted (HTTPS) and unencrypted (HTTP) websites
  • GB2.1.3Sticks to trusted and reputable websites by verifying them carefully (typos in the URLs, etc.)
  • GB2.1.4Makes credit card purchases only on trustworthy sites
  • GB2.1.5Avoids clicking on suspicious pop-ups/ads/links
  • GB2.1.6Does not use official SSO for personal website logins

GB2.2Secure downloads

  • GB2.2.1Downloads files only from reputable and official sources
  • GB2.2.2Double checks buttons by hovering the mouse and checking the destination URL before initiating a download
  • GB2.2.3Reads other user reviews for security vulnerabilities before downloading

GB3Responsible Social Media Usage

GB3.1Information sharing on social media

  • GB3.1.1Do not share personally identifiable information and excessive information about one's workplace on social platforms (e.g., location, contact details, etc.)
  • GB3.1.2Check the accuracy of the post/message before sharing

GB3.2Connection request evaluation

  • GB3.2.1Only connects with trusted individuals and verifies their authenticity before accepting requests

GB3.3Engaging with messages

  • GB3.3.1Deletes suspicious messages or links

GB4Responsible Device Management

GB4.1Secure mobile device usage

  • GB4.1.1Enforcing screen locks (e.g., PIN, fingerprint, or facial recognition), enabling encryption, and using security apps to safeguard device integrity
  • GB4.1.2Downloading apps only from trusted sources (e.g., app stores) and reviewing app permissions before installation
  • GB4.1.3Following workplace policies related to mobile device security
  • GB4.1.4Ensure regular data backups
  • GB4.1.5Ensure secure disposal of mobile devices

GB4.2Secure computer usage

  • GB4.2.1Adhering to computer usage policies and guidelines set by the organisation
  • GB4.2.2Regularly performing system maintenance tasks such as disk cleanup, defragmentation (if applicable), and hardware checks
  • GB4.2.3Protecting computers from physical theft or tampering

GB4.3Secure IoT usage

  • GB4.3.1Changes the provided default credentials immediately after setting up an IoT device
  • GB4.3.2Regularly updates the firmware and software of each IoT devices
  • GB4.3.3Creates separate network segments or VLANs (Virtual Local Area Network) for IoT devices
  • GB4.3.4Disables IoT devices when not in use
  • GB4.3.5Regularly checks and reviews permissions granted to IoT devices
  • GB4.3.6Properly researches various IoT devices available in the market before purchasing one

GB4.4Secure disposal of assets

  • GB4.4.1Follows organization protocols for the secure disposal of hardware and storage media

GB5Secure Remote Work

GB5.1Secure Wifi usage

  • GB5.1.1Avoids connecting to open or unsecured networks
  • GB5.1.2Employs a strong and unique WiFi password for own networks

GB5.2Secure VPN usage

  • GB5.2.1Uses a trusted VPN service
  • GB5.2.2Connects to a VPN while using an unfamiliar network

GB5.3Secure online meetings

  • GB5.3.1Double checks the participant list to verify that only intended participants are being invited to the meeting
  • GB5.3.2Reviews participants using the waiting room feature before adding them to the meeting
  • GB5.3.3Restricts file transfers, chat capabilities as necessary during meetings
  • GB5.3.4Asks for consent before recording meetings

GB6Secure AI/LLM Usage

GB6.1Secure usage of research assistants (GPT)

  • GB6.1.1Does not copy and paste information as it is from AI/LLM platforms
  • GB6.1.2Is careful enough to not divulge highly confidential business information/personally identifiable information to AI/LLM platforms
  • GB6.1.3Regularly review permissions

GB6.2Document review

  • GB6.2.1Removes personally identifiable information or sensitive data from documents before uploading them to the AI/LLM platforms

GB7Logical Access Control

GB7.1Access credentials management

  • GB7.1.1Creates complex passwords with or without enforcement
  • GB7.1.2Does not write down passwords or store in a soft copy
  • GB7.1.3Creates separate passwords across accounts
  • GB7.1.4Pro-actively uses a password manager
  • GB7.1.5Changes password diligently when prompted by the system or application
  • GB7.1.6Using encryption measures for data protection (TLS, SSL, etc.)
  • GB7.1.7Opts for MFA even when it is only an option
  • GB7.1.8Selects the most secure MFA option (e.g., OTP generated by app rather than SMS)
  • GB7.1.9Select the SSO option for signing-in for all work-related accounts
  • GB7.1.10Keeps up-to-date with SSO best practices and guidelines

GB8Physical Access Control

GB8.1Access card management

  • GB8.1.1Stores physical access cards in secure places when not in use
  • GB8.1.2Does not share own or use others' access cards
  • GB8.1.3Promptly reports lost or stolen access cards
  • GB8.1.4Makes use of the appropriate channel to report lost or stolen cards

GB8.2Secure access to facilities

  • GB8.2.1Use secure and authorized methods (such as biometrics, PINs, or access cards) to authenticate identity before gaining physical access
  • GB8.2.2Adhere to the escort policy, ensuring that authorized personnel accompany visitors within secure areas for compliance
  • GB8.2.3A systematic approach is followed to register all visitors and issue temporary access credentials when entering secure areas
  • GB8.2.4Prioritise safety by not misusing emergency exits for unauthorized access or exit, enhancing safety protocols
  • GB8.2.5Lock office doors, filing cabinets, or other secure areas when they are not in use, especially in shared or open spaces
  • GB8.2.6Ensure that all security cameras and surveillance systems are operational and avoid tampering with it

GB9Secure Information Management

GB9.1Information categorization

  • GB9.1.1Classify information based on its sensitivity

GB9.2Information permissions

  • GB9.2.1Sets appropriate file permissions and access levels for documents and folders
  • GB9.2.2Double-checks to ensure that the correct file permissions are enabled before sharing the files or folders with others

GB9.3Information sharing

  • GB9.3.1Checks recipient addresses before sending files
  • GB9.3.2Uses strong passwords to secure the file sharing account
  • GB9.3.3Uses only company approved information sharing channels

GB10Choosing Third-Party Services

GB10.1Vendor evaluation

  • GB10.1.1Evaluating and assessing potential vendors

GB10.2Secure software installation

  • GB10.2.1Avoids downloading software from third-party websites or unverified sources
  • GB10.2.2Reads permissions or privileges requested by software to asses whether it aligns with its intended functionality
  • GB10.2.3Carefully reviews installation prompts and deselects the optional software
  • GB10.2.4Conduct a thorough assessment of the vendor's reputation, security practices, and track record
  • GB10.2.5Ensure that vendor contracts include clear security obligations and service level agreements (SLAs)

GB10.3Software security check

  • GB10.3.1Updating, maintaining, and upgrading software to ensure it functions correctly

GB11Incident Management

GB11.1Incident detection

  • GB11.1.1Establishes baseline behaviors and uses anomaly detection mechanisms to identify deviations
  • GB11.1.2Conducts periodic vulnerability assesments and addresses the identified vulnerabilities promptly
  • GB11.1.3Identify signs of threats like deepfake, vishing, smishing etc

GB11.2Incident classification

  • GB11.2.1Categorise incidents based on their impact and potential harm
  • GB11.2.2Inform IT, security team, and management, about the incident's classification and severity

GB11.3Incident reporting

  • GB11.3.1Establishes a well-defined process for reporting security incidents within the organization
  • GB11.3.2Promptly report security incidents to the IT/Security team
  • GB11.3.3Opens multiple incident reporting channels

GB11.4Incident containment

  • GB11.4.1Isolating affected systems or networks to prevent further spread of the threat
  • GB11.4.2Address vulnerabilities that may have been exploited by the attacker to prevent reinfection

GB12Data Privacy

GB12.1Secure data handling

  • GB12.1.1Handle data according to the organizational policies

GB12.2Data subject rights

  • GB12.2.1Ensure data subject rights such as the right to access correct or delete their personal data

GB12.3Data protection and privacy compliance

  • GB12.3.1Consistently adheres to data protection laws and regulations, including GDPR, PDPA, and other relevant legislation
  • GB12.3.2Adhere to regulatory guidelines for complaint resolution
  • GB12.3.3Regularly conducts privacy impact assessments and updates data protection policies

GB12.4Legal compliance and reporting

  • GB12.4.1Proactively identify, report, and address any potential legal compliance issues or violations to the appropriate authority or compliance officer as required by law

GB13Data Governance and Ethics

GB13.1Adherence to guidelines

  • GB13.1.1Complies to data privacy rules and regulations of the land when working with sensitive data
  • GB13.1.2Follow organization protocol for software installation, pilot test, etc.

GB13.2Ethical data use

  • GB13.2.1Avoids introducing biases into data processing, ensuring fairness and objectivity in decision-making
  • GB13.2.2Is transparent about how data is used and ensures the data use aligns with ethical standards

GB14Information Validation

GB14.1Credibility check

  • GB14.1.1Cross-checks multiple reliable sources to verify information credibility
  • GB14.1.2Contacts official channels for information related to organizations or government entities to verify its authenticity

GB14.2Secure online research

  • GB14.2.1Looks for verifiable data, credible research, and reliable sources cited within the information
  • GB14.2.2Pays attention to timestamps of articles, posts, videos to ensure the information is relevant