Protection Level
Baseline (All Mandatory)
Medium & High Controls
• All Minimal Controls
• All Baseline Controls
• Only authorised and certified personnel should carry
out repairs and service equipment
• Maintenance should preferably be carried within
the premises of Agency or in a security controlled
environment.
• Information should be cleared from equipment when
sent for 3rd party repair/maintenance
• Only authorised and certified personnel, whose
identification papers have been verified by the
Agency, shall carry out repairs and service equipment
• All Minimal Controls
• All Baseline Controls
• Home working controls should be determined
(e.g. use of lockable cabinets, secure
communications etc.)
• Portable computers with sensitive data should not be
taken out of the zone
• Portable computers with sensitive data should
employ media encryption
• Devices containing sensitive information (including
media, firmware passwords, etc.) should be physically
destroyed or the information should be destroyed,
deleted or overwritten using techniques to make the
original information non-retrievable
• All Baseline Controls
• All Minimal Controls
• All Baseline Controls
• Employees, contractors and third party users who
have authority to permit off-site removal of assets
should be clearly identified;
• Time limits for equipment removal should be set and
returns checked for compliance
• 24 x 7 guard at entrance
• Perimeter video monitoring
• Guard patrolling zone, in addition to guard at
entrance
• Video monitoring entrance to security zone
• Security control centre
• 30 day recording retention
• Intrusion detection (ex: motion detection & alarm)
within zone
53
NATIONAL INFORMATION ASSURANCE MANUAL
• Damaged devices containing sensitive information
should be physically destroyed
• Media containing sensitive information should be
physically destroyed.
• Removal of “C3” classified information, shall require
the authorization of “Information Security Manager”