IT Service Portal
Service Desk: +1 (213) 430-7000
Back to IT Service Portal

Information Security Policy

Document ID: OMM-IT-SEC-004 • Effective Date: August 27, 2026 • Version 4.2

O’Melveny is committed to protecting the confidentiality, integrity, and availability of our information systems and client data. This Information Security Policy outlines the protocols, standards, and responsibilities of all personnel when accessing and utilizing O’Melveny's networks and digital resources.

1. Access Controls & Authentication

Access to firm systems is permitted only for authorized users and must be authenticated via approved credentials. The following security measures are strictly enforced:

  • Password Complexity: All network passwords must be at least 12 characters in length, including uppercase and lowercase letters, numerals, and special characters. Passwords must not contain names, dictionary words, or sequential numbers.
  • Password Rotations: Passwords must be updated every 90 days. Reuse of the previous 10 passwords is prohibited.
  • Multi-Factor Authentication (MFA): MFA via Duo Security is mandatory for all remote connections, including VPN, virtual desktops, and web-based email. Users must enroll their primary mobile device or utilize a firm-issued hardware token.

2. Device Security & Patching

All endpoints (workstations, laptops, mobile devices) connecting to O’Melveny networks must comply with the firm's configuration standards:

  • Laptops and workstations must run firm-approved endpoint detection and response (EDR) software.
  • Local drive encryption (BitLocker) must remain active on all corporate laptops at all times.
  • Critical security updates and operating system patches will be pushed automatically and must be installed promptly. Postponing required system restarts is permitted for a maximum of 48 hours.

3. Remote Access & VPN Use

Remote access to the firm's private network must utilize secure communication channels:

Only firm-approved VPN clients (GlobalProtect VPN) or secure virtual desktop environments (Citrix VDI) are permitted for remote work. Establishing unencrypted, ad-hoc, or direct remote control sessions to O’Melveny assets from third-party networks is strictly prohibited unless routed through the secure O’Melveny IT Remote Support portal.

4. Security Incident Reporting

All personnel must remain vigilant against social engineering and digital threats. Any potential security incident must be reported immediately:

  • Phishing Emails: Suspicious emails received in Outlook should be reported immediately using the "Report Phishing" button. Do not forward the message, reply to the sender, or click on any embedded links or attachments.
  • Lost/Stolen Devices: If a firm-issued laptop, phone, or token is lost or stolen, report it to the IT Service Desk within 2 hours to facilitate remote wipe procedures.

Security Inquiries

For questions regarding this policy, system security standards, or to report an incident, contact the Information Security Operations team at security@omm.com or via the IT Service Desk.