# Update Email Passwords Regularly

Use strong, unique passwords and change them periodically.

# Report Suspicious Emails

Notify your IT team or email provider about phishing attempts.

# Dos and Don’ts

- Do not change any hardware configuration, settings in the operating systems or any applications installed on their desktops.
- Do not install any software or applications on your desktops/ laptops that is not authorized by the CMES’s IT team or is not essential to CMES’s business.
- USB ports, Compact Disk (CD)/ DVD, memory card access are disabled by default. If the user needs to enable them, approval from the user’s manager and IT team shall be required.
- Take appropriate measures for physical protection of laptops such as not leaving laptops unattended in public places or while travelling.
- Do not connect removable media such as CD/ DVD, USB drives, and other portable storage media from an unknown source to a CMES system.
- Removable media containing sensitive or confidential information shall be stored in encrypted format by using CMES approved tool.
- Removable media containing sensitive information must not be left out in the open or allowed to be vulnerable to opportunistic theft.

# Clear Desk and Clear Screen

- Ensure that desks and other work areas are kept clear of papers and any storage media when unattended.
- All workstations shall have password-locked screen savers enabled to activate after 5 minutes of inactivity.

# Anti-virus/ Anti-malware

- Users shall not disable the installed anti-virus agent or change its settings defined during installation.
- Users shall report to the IT team for unpatched systems or any virus that is detected in the system and not cleaned by the anti-virus software.