as specified in section C-6, Software Security [SS].
NS 3.
Network configuration is kept under the control of the network manager or similar and all changes
to the configurations are:
a. approved through a formal change control process as defined in section B- 5, Change Management
[CM]
b. documented, and comply with the network security policy and security plan as defined in section
B- 12, Documentation [DC].
c. regularly reviewed. Old configurations as mandated by the Agency’s procedures are maintained
as part of change revision. The frequency of reviewing configuration shall depend on the Agency
risk and processes.
NS 4.
*For each managed network the Agency has:
a. a high level diagram showing all connections into the network, and
b. a logical network diagram showing all network devices.
c. processes to update NS4 (a) & (b), as network changes occur
d. include a “Current at <date>” label on each page.
NS 5.
*Networks are designed and configured to limit opportunities of unauthorized access
to information transiting the network infrastructure. Agencies SHOULD use the following
technologies to meet this requirement:
a. switches instead of hubs,
b. port security on switches to limit access and disable all unused ports
c. routers and firewalls segregating parts of the network on a need-to-know basis,
d. IPSEC/IP Version 6
e. application-level encryption
f. an automated tool that compares the running configuration of network devices against the
documented configuration
g. network edge authentication
h. Restrict and manage end-user devices communicating to Agency network through techniques
such as MAC address filtering.
i. IPS/IDS to detect/prevent malicious activity within the network
j. Time and day restriction.
NS 6.
*Management networks adopt the following protection measures:
a. dedicated network are used for management devices, i.e. implement a separate management
VLAN, or physically separate infrastructure,
b. secure channels e.g. by using VPNs, SSH, etc.
2.3. Policy & Baseline Controls – Virtual LANs (VLANs)
In order to comply with this policy Agencies MUST ensure that:
NS 7.
VLANs are used to separate IP telephone traffic, in business critical networks.
NS 8.
*Administrative access is only permitted from the most highly classified VLAN to one at
the same level of classification or of lower classification.
NS 9.
*They implement all security measures recommended by the agency’s risk assessment
and the hardening guidelines by the vendor of the switch.
NS 10.
*Trunking/port mirroring SHALL not be used on switches managing VLANs of differing
classifications.
2.4. Policy & Baseline Controls – Multifunction Devices (MFDs)
NATIONAL INFORMATION ASSURANCE MANUAL
28