accordance with the Proposed Information Privacy & Protection Legislation.. SM 7. *These logs are retained for a minimum of ninety (90) days and a maximum depending on criticality assessments and sector specific laws and regulations. SM 8. Agency’s MUST enable audit logging or log capture, to record date, time, authentication activity with unique user and system identifiers, including all failure or change actions, further including commands issued and output generated to provide enough information to permit reconstruction of incidents and move system to its original state. SM 9. Exceptions are identified and reported in accordance with the Incident Handling policy, as defined in section B- 8, Incident Management [IM]. 11. Data Retention & Archival [DR] 11.1. Policy Objective The objective of the policy is to provide direction on setting up the retention period for information and the necessary security controls to protect information in its lifetime. 11.2. Policy & Baseline Controls To meet the requirements of this policy, Agencies SHALL ensure that: DR 1. *They determine and document the retention periods of suitable information assets including but not limited to the critical information assets that they hold. Data retention periods SHALL, at a minimum, be governed by: a. Agency policies & needs b. Regulatory requirements c. Legal requirements DR 2. *Data, which needs to be retained, is stored ensuring confidentiality, integrity and availability and that it can be accessed for defined future purposes. DR 3. Personal and sensitive Information is not retained for longer than it is necessary as per the Proposed Information Privacy & Protection Legislation. DR 4. Processes for backup, archival and recovery of data have corresponding procedures which ensure that the integrity and confidentiality of the data is retained. DR 5. *Archived data retains it classification markings and is secured accordingly. DR 6. The archiving technology deployed is regularly reviewed to ensure that it does not suffer from obsolescence and archived data is maintained in a state that allows successful recovery. 12. Documentation [DC] 12.1. Policy Objective The objective of this policy is to define the minimum set of security documentations that a Agency needs to produce, as well as how these documents should be protected and maintained. 12.2. Policy & Baseline Controls In order to comply with this policy Agencies SHALL: 25 DC 1. *Produce a Agency security policy, incorporating the requirements of this NIA Manual. DC 2. Ensure that every system that is determined to be critical to the Agency is covered by a system security plan/standard. Agencies SHOULD ensure that, where necessary, security operating procedures are created and documented. DC 3. Ensure system security standards and procedures are aligned and consistent with the Agency’s security policies and objectives. DC 4. *By default, classify ICT security documentation as a minimum of C3/RESTRICTED NATIONAL INFORMATION ASSURANCE MANUAL

Select target paragraph3