a. Disable any active content options, e.g. Java, JavaScript and ActiveX, in the email application/
browser, except when communicating with a trusted source
b. Use up-to-date browser versions and apply latest security patches
c. Disable password auto-complete/password remembering features
d. Enable pop-up blocking features, except when communicating with trusted sites
e. Regularly remove cache files or temporary files of the browsers to protect data privacy
f. Disable automatic installation of plug-ins, add-ons or software
NS 27.
*They have the capability needed to monitor the traffic, deduce traffic patterns, usage etc.
See section B- 10, Logging & Security Monitoring [SM] for more information.
2.7. Policy & Baseline Controls – E-Mail Security
In order to comply with this policy Agencies MUST ensure that:
NS 28.
E-mail servers are hardened as per best practices and configured as a bastion server. If technically
and operationally feasible, information revealing the specific details of internal systems or
configurations MUST be avoided in email headers to avoid the disclosure of system information to
external parties.
NS 29.
TLS protection is used with the SMTP Mail server in line with section C-10, Cryptographic Security
[CY].
NS 30.
*They implement the email Sender Policy Framework (SPF) [RFC4408]. Agencies SHOULD
only send undeliverable or bounce emails to senders that can be verified via SPF.
NS 31.
*Internal email distribution lists are secured to prevent access from external parties to
reduce the risk of unsolicited email.
NS 32.
Email gateways are employed to scan all incoming and outgoing emails to ensure it complies with
the Agency’s security policy and that it is free of any malicious code.
2.8. Policy & Baseline Controls – Wireless Security
In order to comply with this policy Agencies MUST ensure that:
NS 33.
*Where wireless LANs (WLANs) are used, they are used with sufficient authentication
and transmission encryption measures in place, complemented by proper security
management processes and practices.
NS 34.
*Strong wireless security protocols such as WPA2 and EAP-TLS are used. However, such
wireless security protocol should not be solely relied upon to protect data confidentiality and
integrity. Agency SHALL deploy dynamic key exchange mechanisms, secure Virtual Private Network
(VPN) on top of wireless network if classified data, C3 and above, is to be communicated over
wireless networks. WEP SHALL NOT be implemented within any network.
NS 35.
*A good inventory of all devices with wireless interface cards is maintained. Once a
device is reported missing, consider modifying the encryption keys and SSID.
NS 36.
*Network administrators regularly scan for “rouge” or “unauthorized” wireless access
points.
NS 37.
Access points are located to minimize network tapping from publicly accessible area.
NS 38.
The client side settings for 802.1x MUST be secured. Some of the techniques are: server certificate
validation by selecting the CA certificate, specify the server address and disable it from prompting
users to trust new certificates or servers.
NS 39.
*The network default name, encryption keys and Simple Network Management Protocol
(SNMP) community strings (and any insecure configuration) is changed at installation.
SSID SHALL NOT reflect the name of any Agency’s departments, system name or product name.
NS 40.
For non-public wireless access points, encryption keys are regularly changed and SSID broadcasting
is disabled. Where applicable MAC address filtering SHOULD also be considered.
NATIONAL INFORMATION ASSURANCE MANUAL
30