accordance with the Proposed Information Privacy & Protection Legislation..
SM 7.
*These logs are retained for a minimum of ninety (90) days and a maximum depending on
criticality assessments and sector specific laws and regulations.
SM 8.
Agency’s MUST enable audit logging or log capture, to record date, time, authentication activity
with unique user and system identifiers, including all failure or change actions, further including
commands issued and output generated to provide enough information to permit reconstruction of
incidents and move system to its original state.
SM 9.
Exceptions are identified and reported in accordance with the Incident Handling policy, as defined
in section B- 8, Incident Management [IM].
11. Data Retention & Archival [DR]
11.1. Policy Objective
The objective of the policy is to provide direction on setting up the retention period for information and the necessary
security controls to protect information in its lifetime.
11.2. Policy & Baseline Controls
To meet the requirements of this policy, Agencies SHALL ensure that:
DR 1.
*They determine and document the retention periods of suitable information assets
including but not limited to the critical information assets that they hold. Data retention
periods SHALL, at a minimum, be governed by:
a. Agency policies & needs
b. Regulatory requirements
c. Legal requirements
DR 2.
*Data, which needs to be retained, is stored ensuring confidentiality, integrity and
availability and that it can be accessed for defined future purposes.
DR 3.
Personal and sensitive Information is not retained for longer than it is necessary as per the Proposed
Information Privacy & Protection Legislation.
DR 4.
Processes for backup, archival and recovery of data have corresponding procedures which ensure
that the integrity and confidentiality of the data is retained.
DR 5.
*Archived data retains it classification markings and is secured accordingly.
DR 6.
The archiving technology deployed is regularly reviewed to ensure that it does not suffer from
obsolescence and archived data is maintained in a state that allows successful recovery.
12. Documentation [DC]
12.1. Policy Objective
The objective of this policy is to define the minimum set of security documentations that a Agency needs to produce,
as well as how these documents should be protected and maintained.
12.2. Policy & Baseline Controls
In order to comply with this policy Agencies SHALL:
25
DC 1.
*Produce a Agency security policy, incorporating the requirements of this NIA Manual.
DC 2.
Ensure that every system that is determined to be critical to the Agency is covered by a system
security plan/standard. Agencies SHOULD ensure that, where necessary, security operating
procedures are created and documented.
DC 3.
Ensure system security standards and procedures are aligned and consistent with the Agency’s
security policies and objectives.
DC 4.
*By default, classify ICT security documentation as a minimum of C3/RESTRICTED
NATIONAL INFORMATION ASSURANCE MANUAL