In order to comply with this policy Agencies MUST ensure that: NS 11. *Network-connected MFDs are not used to copy documents classified above the level of the connected network NS 12. Where network-connected MFDs have the ability to transmit information via a gateway to another network, agencies MUST ensure that: a. each MFD applies user identification, authentication and audit functions for all information transmitted by users from that MFD, b. these mechanisms are of similar strength to those required for workstations on that network, and c. *the gateway can identify and filter the information in accordance with the requirements for the export of data. NS 13. *There is no direct connection from an MFD to a telephone network of a lower classification unless the MFD has been evaluated, and the scope of the evaluation includes: a. information flow control functions to prevent unintended and unauthorized data flows, b. data export controls capable of blocking information based on information classification, c. authentication, and audit data generation and protection, NS 14. They deploy MFDs after developing a set of policies, plans and procedures governing the use of the equipment. NS 15. Information classified at C1 or above is not retained permanently in the MFD. Where the MFD has features to schedule jobs, sufficient manual/automatic controls or configurations SHALL exist to remove the information from its memory once the job is complete. NS 16. MFDs follow the procedures specified in section C, 8.3, Media Sanitization. 2.5. Policy & Baseline Controls – Domain Name Service (DNS) Servers In order to comply with this policy Agencies MUST ensure that: NS 17. A separate internal DNS server is set up and placed in the internal network for internal domain information that is not disclosed to the Internet. NS 18. DNS information that should be made public either has a locally hosted and secured (bastion server) server. State Agencies may also use the Government DNS which is part of the Government Network as the Primary DNS. NS 19. DNS servers are deployed to ensure there is no single points of failure in their service, they are security-hardened and security is proactively maintained. NS 20. *Zones files are digitally signed, and cryptographic mutual authentication and data integrity of zone transfers and dynamic updates is provided. NS 21. *Cryptographic origin authentication and integrity assurance of DNS data is provided. NS 22. DNS services including zone transfers are provided to authorized users only. NS 23. *Cryptographic functions related to NS 20 and NS 21 above, use a hardware security module for both key management and cryptographic processing as specified in section C- 10, Cryptographic Security [CY]. 2.6. Policy & Baseline Controls – Internet Security In order to comply with this policy Agencies MUST ensure that: 29 NS 24. All software and files downloaded from the Internet are screened and verified against malicious software, including mechanisms to scan HTTP traffic. NS 25. *The Internet gateway denies all Internet services unless specifically enabled. NS 26. Web browsers running on user’s workstation are properly configured and updated. Agencies SHOULD reference the following guidelines when configuring web browsers: NATIONAL INFORMATION ASSURANCE MANUAL

Select target paragraph3