other than the originator.
4.4. Policy & Baseline Controls – Data Import
In order to comply with this policy, Agencies MUST ensure that:
GS 15.
System users:
a. are held accountable for the data they import
b. are instructed to perform a protective marking check, a visual inspection and a metadata check
if relevant.
GS 16.
*Data imports are either:
a. performed in accordance with processes and/or procedures approved by the Agency; or
b. individually approved by the information security manager.
GS 17.
*Data imported to a Agency system is scanned for malicious and active content.
5. Product Security [PR]
5.1. Policy Objective
This policy establishes the minimum security for selecting and acquiring information products through a proper selection
and acquisition process. Agencies MUST ensure that selected products are chosen after an independent evaluation
process that meets the security requirements listed in this policy.
5.2. Policy & Baseline Controls
In order to comply with this policy, Agencies MUST ensure that:
PR 1.
The process for product selection is carried out with due diligence and ensures product and
vendor independence.
PR 2.
Products are classified and labeled as per National Information Classification policy [IAP-NATDCLS].
PR 3.
*The selection process includes proper identification of vendor, screening of vendors and
evaluation criteria definition which should include as a minimum:
a. Vendor status and identification, including location and ownership
b. Financial situation
c. References from previous successful engagements
d. The ability of the vendor to build and/or maintain appropriate controls as determined by a risk
assessment
35
PR 4.
Proper testing and effective matching between vendor’s claim and functionality is carried out, to
avoid loss of confidentiality, integrity and/or availability.
PR 5.
*Security evaluation of the product is done on a dedicated evaluation configuration
including functionality tests, security tests and patching to protect against potential
threats and vulnerabilities.
PR 6.
Delivery of products is consistent with the Agency’s security practice for secure delivery.
PR 7.
Secure delivery procedures SHALL include measures to detect tampering or masquerading.
PR 8.
*Products have been purchased from developers that have made a commitment to the
ongoing maintenance of the assurance of their product.
PR 9.
Product patching and updating processes are in place. Updates to of products SHALL follow the
change management policies specified in section B- 5, Change Management [CM].
NATIONAL INFORMATION ASSURANCE MANUAL