Defines how access control to information systems covers all stages in the user access lifecycle. Key points include: individual unique logins, two-factor authentication (Duo), least privilege principle, account lockout after 5 failed attempts, privileged account documentation, quarterly audits of access control logs.
LeadsOnline retains customer data indefinitely, unless and until removal is requested by the customer. This data is critical to supporting law enforcement investigations and is safeguarded throughout its lifespan within LeadsOnline systems, including encryption at rest and immutability protections that prevent unauthorized alteration or deletion. Customers seeking removal of their data must submit a request in writing via email to support@leadsonline.com. Requests will be reviewed and processed in accordance with the retention and removal terms set forth in the customer's applicable contract and Service Level Agreement (SLA), which govern the specific timelines, conditions, and any exceptions applicable to that customer relationship.
Requirements: minimum 10 alphanumeric characters, at least one uppercase letter, one lowercase letter, one number, and one special character. Cannot be the same as the last 10 passwords. Passwords must be stored using a password manager.
Establishes rules for granting, controlling, monitoring, and removing physical access to facilities, property and equipment. Key requirements include: compliance with building codes, clearly marked restricted areas, manager approval for access, security team approval for sensitive facilities, and quarterly access reviews.
Establishes a systematic approach to identifying, evaluating, and addressing vulnerabilities. Includes regular scans, risk assessment, remediation, notification, patch management, third-party software assessment every two weeks, and periodic review and reporting.