1. Introduction & Scope This manual applies to all Agencies1 and their corresponding information assets. Where the Agency has outsourced or subcontracted any processes or activities they should ensure they comply with this manual and associated controls. In summary, the information security programme must cover such elements as: •  Assignment of roles and responsibilities •  Assignment of ownership of information assets •  Classification of information assets •  Periodic assessments of threats and vulnerabilities •  Adequate, effective and tested controls •  Integration of security in all organizational processes •  Processes to monitor security elements •  Effective identity and access management processes for users and suppliers of information • Education on information security requirements for all users, managers, and board members • Training, as appropriate, in the operation of security processes • •  Development and testing of plans for continuing the business in case of interruption or disaster Perpetual maintenance of the information security programme and change management processes 2. Usage of this Manual This NIA Manual is designed to be used in conjunction with the National Information Classification Policy [IAP-NATDCLS] and applicable laws and regulations within State of Qatar. The manual provides, baseline controls which an organization should implement at minimum to protect their information system. The controls are grouped in the following security domains: • Access Control Security [AM] • Audit & Certification [AC] • Business Continuity Management [BC] • Change Management [CM] • Communications Security [CS] • Cryptographic Security [CY] • Data Labeling [DL] • Data Retention & Archival [DR] • Documentation [DC] • Gateway Security [GS] • Governance Structure [IG] • Incident Management [IM] • Information Exchange [IE] • Logging, Auditing & Security Monitoring [SM] • Media Security [MS] 1The term ‘Agency’ will refer to all entities in Qatar (inclusive of Government, Semi-Government and Private entities). The term ‘State Agency’ will refer exclusively to Government entities. 15 NATIONAL INFORMATION ASSURANCE MANUAL

Select target paragraph3