IE8. *Protect information exchanged via electronic messaging from unauthorized access, change or interruption of service. IE9. Ensure secure messaging (information is digitally signed and/or encrypted) is used for all information classified at C3 or above. Agencies SHALL use Secure Multipurpose Internet Mail Extension (S/ MIME), equivalent or better protocol for secure messaging as specified in clause CY5, section C- 10, Cryptographic Security [CY]. IE10. *Attach the following email disclaimer, or similar, to all outgoing email: “The information in this email, including attachments, may contain information that is confidential, protected by intellectual property rights, or may be legally privileged. It is intended solely for the addressee(s). Access to this email by anyone else is unauthorized. Any use, disclosure, copying, or distribution of this email by persons other than the designated addressee is prohibited. If you are not the intended recipient, you should delete this message immediately from your system. If you believe that you have received this email in error, please contact the sender or < Agency’s name & contact information>. Any views expressed in this email or its attachments are those of the individual sender except where the sender, expressly and with authority, states them to be the views of < Agency>.” IE11. Exercise due diligence to ensure that any information sent/received is free of viruses, trojans and other malicious code IE12. Ensure information exchanged between systems is secured against misuse, unauthorized access or data corruption. For transmitting information classified at C2, I2 or above, authenticated and encrypted channels SHALL be used as specified in CY5, section C- 10, Cryptographic Security [CY]. IE13. *Limit the information provided to the general public (via media outlets), to sanitized and approved information, through a designated and trained media relation spokesperson. 4. Gateway Security [GS] 4.1. Policy Objective The main purpose of this policy is to provide minimum security requirement for securing gateways used for interagencies communications as well as for external link communications. The deployment of a controlled gateway can be used to ensure that only allowable information is transferred between the gateway and the connected networks. This can be used to preserve need-to-know requirements and to prevent malicious activities propagating from one network connected to another. Gateways include routers, firewalls, content filtering solutions and proxies. 4.2. Policy & Baseline Controls - General In order to comply with this policy, Agencies MUST ensure that: GS 1. Networks are protected from other networks by gateways and data flows are properly controlled GS 2. Gateways connecting Agency networks to other Agency networks, or to uncontrolled public networks, are implemented: a. with an appropriate network device to control data flow b. with all data flows appropriately controlled c. with gateway components physically located within an appropriately secured server room. 33 GS 3. Only authorized and trained staff manage and maintain gateways GS 4. *Administrative or management access to gateways processing or transmitting information classified at C3 or above is only provided based on dual control and the four eyes principles. GS 5. Information exchanged through gateways is labelled as per the National Information Classification policy [IAP-NAT-DCLS] and protected as specified in this document. Gateways SHALL be classified inline with the information they are transmitting. NATIONAL INFORMATION ASSURANCE MANUAL

Select target paragraph3