a. Confidentiality and non-disclosure obligations.
PS 7.
Ensure that adequate controls are in place to prevent personnel (employees, vendors, contractors
and visitors) from making unauthorized disclosures, misusing or corrupting information as per
Agency security policies.
PS 8.
Ensure that users access rights are restrictive to the information they need to fulfill their job
requirements as per least privilege and need to have principles.
PS 9.
Implement a split of responsibilities over sensitive security processes and tasks, using the four
eyes principles to ensure knowledge sharing and to avoid a single individual having full control over
critical processes or tasks.
PS 10.
*Define, communicate and enforce a disciplinary process and ensure that employees are
made aware of the process. Disciplinary processes SHOULD be documented in the employee or
HR manual.
PS 11.
*Ensure that vendors, contractors, delegates or guests visiting Agency premises are:
a. Logged with unique identifiable information including date, time and purpose of admittance.
b. Provided with a visitor badge or identification tag.
c. Wearing a noticeable sign displaying their status as “visitor” at all times.
d. Made aware of their obligations in complying with the security policies of the Agency.
e. Escorted by Agency employees while accessing secure areas.
PS 12.
*Ensure that a change request from the HR department is generated when a change of
duties or termination of contract of an employee, contractor or third party occurs. This
ensures that employees, contractors and third parties return Agency assets and physical & logical
access are amended/removed as appropriate.
7. Security Awareness [SA]
7.1. Policy Objective
The purpose of this policy is to define criteria for a security training and awareness programme conducted by the
Agency for its employees, contractors, temporary personnel, and other entities who may use or administer the Agency’s
Information System assets.
7.2. Policy & Baseline Controls
To meet the requirements of this policy, Agencies MUST ensure:
SA 1.
*A security awareness programme is defined and adequate budgets are allocated for its
implementation.
SA 2.
*As a minimum, such training includes
a. Baseline requirements specified in this NIA Manual
b. Agency’s security requirements
c. Legal and regulatory responsibilities
d. Business specific processes and controls
e. Acceptable use of information processing facilities, (e.g. log-on procedures, use of software
packages, etc.)
f. Information on the enforcement and disciplinary process
g. Information on who to contact for further security advice and the proper channels for reporting
information security incidents
SA 3.
*All employees of the Agency and, where relevant, contractors and third party users
receive appropriate security awareness training regarding the Agency’s policies and
NATIONAL INFORMATION ASSURANCE MANUAL
22