Passwords & Access
Device Security (PC, Smart Devices)
Data & Internet
Digital Duty
Final Jeopardy (Cardinal Rules)
100

 You must never share this with anyone, not even IT support.

What is your password?

100

Users must take every precaution to prevent company devices from being this

What is stolen?

100

This type of connection should never be used for work without a company-approved VPN  

What is public/unsecured WiFi?

100

 This must be signed and followed by all employees to maintain digital safety.

 What is the Code of Conduct for Digital Protection (DS_GC01)?

200

The act of using another employee's credentials or circumventing controls to access information you are not authorized to see.

 What is a violation of access control?

200

Users must not do this to the device's security settings (e.g., firewall, encryption) configured by IT services.

What is circumvent/change?

200

This type of information about work should never be posted on social media

What is confidential/sensitive information?

200

This, according to Rule 9, must never be attempted: bypassing security to gain information you are not authorized to see

What is unauthorized access/covert means?

300

This extra layer of security should be activated whenever available to protect accounts.

What is two-factor or multi-factor authentication (2FA/MFA)?

300

Only approved software, as defined in this policy, should be used on company machines

What is the Information Security Policy?

300

Clicking on links or attachments from these sources can lead to a cyber incident

What are unknown or suspicious emails?

300

This is the primary team responsible for maintaining security, but all employees have a responsibility to act safely.

What is IT Services (CSIRT)?

400

This action should be taken immediately upon stepping away from your desk to prevent unauthorized access.

  • What is locking your computer? (Windows key + L).




400

Regularly doing this allows computers to receive the latest security updates and patches

What is restarting your computer/updating?

400

Use only these types of approved platforms to share or store company data

What are company-approved third-party solutions?

400

Using these on public Wi-Fi is mandatory to ensure a secure connection to Air Liquide resources.

What is a VPN (Virtual Private Network)?

500

This must be activated on all accounts that support it to prevent unauthorized login, even if a password is stolen.

What is Multi-Factor Authentication (MFA)?

500

These devices, including USB drives, should not be plugged into Air Liquide equipment unless verified and approved.

What are unauthorized external devices/peripherals?

500

This is the maximum time personal data should be kept, according to Data Protection policy.

What is a limited period of time?

500

This "by Design" principle means security and privacy must be considered at the start of every project

What is Security/Privacy by Design?

500

According to the Code of Conduct, this is the ultimate goal of all 12 digital protection rules: protecting the company's ______, people, and reputation.

What are Digital Assets/Resources?