AM 40. *Users do not access Agency internal systems from public computers e.g. Cyber Cafes etc. or print material to any public computer. AM 41. Vendor remote access is limited to situations where there are no other alternatives. In this case, initiation of the connection SHALL be controlled and monitored by the Agency. Vendor remote access SHALL only be for a defined period of time, dictated by the duration of the task being undertaken. 10. Cryptographic Security [CY] 10.1. Policy Objective This policy establishes the baseline for the use of encryption technologies for keeping information assets confidential and/or integral. As a custodian of public and confidential information, Agencies must further protect private and sensitive data/information from all cyber threats and vulnerabilities whether external or internal to the Agency. 10.2. Policy & Baseline Controls In order to comply with this policy Agencies MUST ensure that: CY 1. The cryptographic algorithms, encryption hardware/software, key management systems and digital signatures, meet the requirements specified in Appendix B of this manual for Approved Encryption/ Cryptographic Algorithms and Systems. CY 2. The lifetime of the key SHALL be determined by the primarily by the application and the information infrastructure it is used in. Keys SHALL be immediately revoked and replaced if it has been or suspected of being compromised. CY 3. *Information assets classified as C3 [IAP-NAT-DCLS] are encrypted and protected against unauthorized disclosure when stored and/or in transit regardless of the storing format or media. Agencies MAY apply these cryptographic controls to assets with lower confidentiality requirements, if determined necessary by their risk assessment. CY 4. Information assets classified as I3 [IAP-NAT-DCLS] have assured integrity by the use of cryptographic hashing. Agencies MAY apply these cryptographic controls to assets with lower integrity requirements, if determined necessary by their risk assessment. Appendix B to this section specifies approved hashing algorithms. CY 5. *The following protocols or better, with approved algorithms outlined in Appendix B, are used for securing data classified as C3 when in transit: a. For securing web traffic: TLS (128+ bits) [RFC4346] b. For securing file transfers: SFTP [SFTP] c. For secure remote access: SSH v2 [RFC4253] or IPSEC [RFC 4301] d. Only S/MIME v3 [RFC3851] or better are used for securing emails. See CY11 for associated requirement. CY 6. *Passwords must always be encrypted/hashed and protected against unauthorized disclosure when they are stored and/or in transit regardless of the storing format or media. Privileged passwords SHALL be encrypted and stored off-site with backup files each time the password is changed to ensure complete recovery. CY 7. *Where Hardware Security Modules (HSMs) are used, they are certified to at least FIPS 140-2 Level 2 [FIPS-140-2] or Common Criteria [CC3.1] EAL4. CY 8. Cryptographic keys are only physically moved in HSMs meeting CY5 CY 9. Suitable key management processes are defined, as per [ISO11770-1] and used to manage the lifecycle of cryptographic keys, covering the following functions: •  Key Custodians Roles and Responsibilities •  Key Generation NATIONAL INFORMATION ASSURANCE MANUAL 44

Select target paragraph3