[CWA14167-1] Security Requirements for Trustworthy Systems Managing Certificates for Electronic Signatures Part 1: System Security Requirements, CEN Workshop Agreement, CWA 14167-1, June 2003 [FIP186-2] NIST FIPS PUB 186-2 “Digital Signature Standard (DSS),” with Change Notice 1, October 2001. [FIPS-140-2] National Institute of Standards and Technology, FIPS 140-2, Security Requirements for Cryptographic Modules, January 24, 2007 [Mitre] Mitre, 2009 CWE/SANS Top 25 Most Dangerous Programming Errors, http://cwe.mitre.org/ top25/, January 2009. [RFC 4301] Kent & Seo, Security Architecture for IP, RFC 4301, December 2005 [RFC3851] Ramsdell, S/MIME 3.1 Message Specification, RFC 3851, July 2004 [RFC4346] Dierks & Rescorla, The TLS Protocol, RFC4301, April 2006 [RSA] RSA Laboratories, “PKCS#1 v2.1: RSA Cryptography Standard,” June 2002. [SFTP] Galbraith & Saarenmaa, SSH File Transfer Protocol, draft-ietf-secsh-filexfer, June 2005 [SHA] NIST FIPS PUB 180-2, “Secure Hash Standard,” National Institute of Standards and Technology, U.S. Department of Commerce., August 2001. [SP800-67] NIST SP 800-67 “Recommendation for the Triple Data Encryption Algorithm (TDEA) Block Cipher,” May 2004. [ISO11770-1] Information technology – Security Techniques, Key Management, ISO/IEC 11770-1:2006(E) Part 1: Key Management-Framework, International Organisation for Standardisation & International Electrotechnical Commission, 2006 [RFC4408] M. Wong, W. Schlitt, on Sender Policy Framework (SPF) for Authorizing Use of Domains in E-Mail, Version 1, Internet Engineering Task Force (IETF), RFC 4408, April 2006 Defined terms are specified in the Information Assurance Framework, [IAP-NAT-IAFW]. The following defined terms are used in this document: Agency, State Agency, Personal Information, Hot/Warm/Cold Sites, Q-CERT, MOTC, National Classification Markings. 17 NATIONAL INFORMATION ASSURANCE MANUAL

Select target paragraph3