O’Melveny is committed to protecting the confidentiality, integrity, and availability of our information systems and client data. This Information Security Policy outlines the protocols, standards, and responsibilities of all personnel when accessing and utilizing O’Melveny's networks and digital resources.
Access to firm systems is permitted only for authorized users and must be authenticated via approved credentials. The following security measures are strictly enforced:
All endpoints (workstations, laptops, mobile devices) connecting to O’Melveny networks must comply with the firm's configuration standards:
Remote access to the firm's private network must utilize secure communication channels:
Only firm-approved VPN clients (GlobalProtect VPN) or secure virtual desktop environments (Citrix VDI) are permitted for remote work. Establishing unencrypted, ad-hoc, or direct remote control sessions to O’Melveny assets from third-party networks is strictly prohibited unless routed through the secure O’Melveny IT Remote Support portal.
All personnel must remain vigilant against social engineering and digital threats. Any potential security incident must be reported immediately:
For questions regarding this policy, system security standards, or to report an incident, contact the Information Security Operations team at security@omm.com or via the IT Service Desk.