Sunday, July 27, 2025

Security Policy Teamhouse



   SF   

  SPECIAL FORCES ASSOCIATION

      Chapter 76 - South Florida 

          “The Green Berets”

 

July 27, 2025                          

Hello Members and Friends of the Association,

From the SFA

 

 

Chapter Leadership and Administrators

 

Please pass the information below on to your chapter members. Not all chapter members are on the Teamhouse. All SFA members should be aware of the security policy whether they use the Teamhouse or not.

 

Thanks for your attention to this matter. 

 

Keith Rutledge

Adjutant, SFA

 


Special Forces Association Information Security Policy

 

Please read this email, especially the part regarding new password requirements going into effect on 1 September 2024.

 

The Special Forces Association regards member data as private and takes precautions to protect that data. As part of that ongoing effort, we are implementing a formal information security policy. This policy is available for you to read in the online Teamhouse.  

The security policy establishes a general approach to information security. The objective is to observe the rights of our members by safeguarding their personal information and providing effective mechanisms for responding to complaints and queries concerning real or perceived non-compliances with the policy.

The information security policy addresses data, programs, systems, facilities, other tech infrastructure, users of technology, and third parties used to provide services to the SFA. Specifically, it addresses the online Teamhouse. Teamhouse is the Club Express hosted application used by SFA and SFA Headquarters.

In accordance with the information security policy, we will take the following actions.

The Adjutant, CISO, and CDMO will perform a “privileged account” audit.

All access to electronic systems will be granted according to the “principle of least privilege.” Granted access will be as granular as possible to support the “principle of least privilege.”

Passwords will migrate to “strong passwords” according to the policy password guidelines in Appendix E of the security policy. All systems in use by SFA will be configured to adhere to the password policy. The Teamhouse is the most widely used system.

 

The Teamhouse Password setting will be configured as below:

  • Require Strong Password - Yes
  • Strong PasswordType - Minimum Length and Diverse Characters (Diverse Characters means a password must have at least one each of a lowercase letter, uppercase letter, number, and symbol)
  • Minimum Password Length - 10
  • Require Periodic Password Change - Yes
  • Require change every 365 days (once per year)
  • Enable Two Factor Authentication (2FA) -No

In Teamhouse, if you previously haven't had a "strong" password, you'll need to change it at your next login after the new policy takes place.  The process is simple, with prompts describing the new password requirements and guiding you through the change.

The password requirement will change on September 1st, 2025. On your first login to the online Teamhouse after that, you will be required to change your password to a password that meets the requirements listed above.

 

Additional requirements listed in the security policy are:

  • Hard drives that store SFA information (all types) must be encrypted.
  • Emails with member information must be encrypted.
  • Files that contain member information must be encrypted before transmission.

“Opt Out” requests (all types) by members will be honored. We will not share member data with our partner for members who opt out of data sharing.

  • The Executive Director, Adjutant, CISO, and CDMO will conduct a bi-annual (twice per year) access review and report the results to the NBO.
  • Workstations that access SFA systems must be configured with screensavers that lock after 3 minutes and require a password.
  • Annual security awareness training is required for:
    • National Board Officers
    • Members of the Security Working Group
    • The SFA Executive Director and staff
    • Members of the IT Committee
    • All Systems Administrators

This training will be highly recommended for:

    • Chapter Administrators
    • Coordinators

The training will be available and recommended to members.

The Adjutant, Executive Director, CISO, and CDMO will implement a Cybersecurity Incident Response Plan. The CISO will monitor and audit IT security.

Implementation of the security policy will begin upon approval of the Special Forces Association National Board of Officers and after member notification. This email is the member notification.

 

Keith Rutledge

Adjutant, Special Forces Association

864/404-0972

 

 

Joe Pruett on behalf of

Ed Pijuan

President