4. Legal Impact: Low impact (I4=1) 5. Economic Impact: No impact (I5=1) Impactvalue = 1.25 (3x3 + 3x1 + 2x3 + 4x1 +2x1) This would yield an impact value of: 30. Appendix B – Asset Classification Model To determine the classification of Information Assets and the corresponding level of security protection, the following steps should be undertaken: 1. Identify key1 processes and their owners in the organization. 2. Identity process dependencies: information, applications, systems, networks, etc. 3. Determine the security classification for each information asset using table 1 below; aggregate security levels are: H: High, M: Medium, L: Low 4. Record the full classification (e.g.. C0I2A2) and aggregate security level (e.g. M) foreach asset. A0 C0 I0 11 12 13 A1 A2 A3 L M H C1 L L M H C2 M M M H C3 H H H H C0 L L M H C1 L L M H C2 M M M H C3 H H H H C0 M M M H C1 M M M H C2 M M M H C3 H H H H C0 H H H H C1 H H H H C2 H H H H C3 H H H H Table 1 -­ Security Classification Table Availability The availability of data means timely and easy access to usable data during previously agreed necessary and required business hours (i.e. at the necessary and required moment and within the necessary and required period of time) for authorised persons or technical means. A0: Availability and productivity/reaction time not important A1: Availability 90% (downtime ~ 17h/week); allowed max response time – hours (1 to 10) A2: Availability 99% (downtime ~ 2h/week); allowed max response time – minutes (1 to 10) A3: Availability 99.9% (downtime ~ 10min/week); allowed max response time – sec (1 to 10) 1 These are processes that are absolutely critical to the effective functioning of the Agency. NATIONAL INFORMATION ASSURANCE POLICIES 8

Select target paragraph3