Welcome to - COMPLETE | ED
Additional text has been added to aid users who may be using screen readers to view this site. If you are reading this text on your screen then either, the style sheet (CSS) file has failed to load, in which case you should refresh your screen or, your browser may not support style sheets. Find out more about which browsers support style sheets on the World Wide Web Consortium website.
What follows is a few links to some of the important site pages and then a login portal. If you wish to skip this you can.
|
Security Practices
CUNA Mutual Group takes information security very seriously. This page is meant to give an overview of the practices that we follow in order to protect both our computer systems and the data that has been entrusted to us. Access ControlManagement has established a security policy which has been communicated to all employees. The policy covers the following general concepts:
Access to CUNA Mutual’s online services and business functions is secured by a unique user ID and password. These passwords must be changed regularly and must adhere to restrictive parameters to decrease the risk of unauthorized access to data and business applications. A limited number of individuals have the authority to maintain these parameters and setup new user accounts. Physical SecurityAll computer hardware and storage media is located in an environmentally controlled, limited access facility, commonly known as the computer room. Individual access is subject to management approval based on the individual's job responsibilities. A key card system is in use that requires the use of a key card to gain access to the building, and both a key card and a PIN to access the computer room. All key cards contain pictures of the key card user. Regular audits are conducted to validate user access. The key card system logs all activity from the card readers. The system records the card number swiped, date and time, and action performed. These logs are reviewed periodically by Computer Operations management. CUNA Mutual monitors all facilities through digital video surveillance. CUNA Mutual's computer room contains a pre-action FM-200 fire suppression system with integrated smoke and heat detection. The system is centrally monitored on a 24/7 basis by onsite security staff. Power to the computer room is protected by a generator with two independent power feeds. If the generator itself fails, two UPS units provide power for approximately 45 minutes to allow for controlled shutdown of equipment. The generator and UPS units are configured to provide as much redundancy in power delivery routes as possible. Air handlers have adequate dust filtering systems, and static electricity is controlled by maintaining a maximum humidity level. All moving devices are enclosed to protect them from exposure to elements. Data EncryptionCUNA Mutual can support multiple mechanisms for encryption. Systems accepting data over the Internet are placed in the application hosting environment, separated from the Internet and the corporate network. CUNA Mutual utilizes industry standard encryption in all areas of transmission to ensure confidentiality of information. A minimum encryption level has been established for both transmission of data and credentials and storage. Malicious Content ManagementWe attempt to ensure that all files coming in to the CUNA Mutual network are scanned for viruses and other malicious software. Anti-virus software has been deployed on our mail, application and database servers, as well as on all desktops. Live updates features are utilized to ensure virus "signatures" remain current, or can be deployed real-time as signatures become available during a crisis. In addition, incident response procedures have been developed to contain any virus outbreaks should they arise. Intrusion Detection Capabilities and FirewallsIntrusion Detection systems are in place to monitor all network traffic both to and from the Internet. These systems are designed to alert and intercept or block suspicious activities as deemed appropriate. In addition, our networks are also protected by firewalls which further serve to filter and block suspicious traffic that is detected. Data Backup and Business ContinuityOur procedures require that all production data be backed up on a regularly scheduled basis. The backups are done centrally. The data backup process is automated and monitored for any error situations. CUNA Mutual utilizes an industry trusted 3rd party records storage and management service for our off-site storage needs. This off-site storage facility provides highly secure transportation and destruction services and features 24/7 security and access control to their facilities. The records center is designed to offer extensive protection from flood or fire and is staffed by highly trained personnel.
Incident ResponseCUNA Mutual has established a process for evaluating and responding to security events and potential incidents. A core team from our Legal, Compliance, Security and Risk Management areas is available in the event an incident involving our electronic systems is detected. This team is charged with:
Independent Security AssessmentsCUNA Mutual employs the services of various external consulting and auditing firms to test our defenses and report on any vulnerability detected. In addition, CUNA Mutual Group has passed the X-Force™ security certification requirements defined by IBM Internet Security Systems (ISS). In order to become qualified for the ISS X-Force Security Program, CUNA Mutual’s security controls and practices must meet or exceed ISS’ best practices security criteria, based upon the ISO 17799 standard. ISS performs the following tests to evaluate and verify that best practices are in place:
Our enterprise certification has been in place since 2001. This certification requires at least quarterly external vulnerability and penetration assessments, annual internal vulnerability and penetration assessment (Internal LAN and Wireless), annual desktop risk assessment, quarterly war dial assessment, and annual security governance review. We are proud of our ISS certification, and certification is not a function of simply letting ISS technicians attempt to break into our systems. Our team works closely with the ISS security analysts to identify potential security threats, and then take the appropriate actions in order to minimize the perceived risks. In addition, our specialists and the ISS consultants strive to ensure that proper procedures are in place to keep our site protected from these perceived threats. |
|