IE8.
*Protect information exchanged via electronic messaging from unauthorized access,
change or interruption of service.
IE9.
Ensure secure messaging (information is digitally signed and/or encrypted) is used for all information
classified at C3 or above. Agencies SHALL use Secure Multipurpose Internet Mail Extension (S/
MIME), equivalent or better protocol for secure messaging as specified in clause CY5, section C- 10,
Cryptographic Security [CY].
IE10.
*Attach the following email disclaimer, or similar, to all outgoing email:
“The information in this email, including attachments, may contain information that is confidential,
protected by intellectual property rights, or may be legally privileged. It is intended solely for the
addressee(s). Access to this email by anyone else is unauthorized. Any use, disclosure, copying,
or distribution of this email by persons other than the designated addressee is prohibited. If you
are not the intended recipient, you should delete this message immediately from your system. If
you believe that you have received this email in error, please contact the sender or < Agency’s
name & contact information>. Any views expressed in this email or its attachments are those of
the individual sender except where the sender, expressly and with authority, states them to be the
views of < Agency>.”
IE11.
Exercise due diligence to ensure that any information sent/received is free of viruses, trojans and
other malicious code
IE12.
Ensure information exchanged between systems is secured against misuse, unauthorized access
or data corruption. For transmitting information classified at C2, I2 or above, authenticated and
encrypted channels SHALL be used as specified in CY5, section C- 10, Cryptographic Security [CY].
IE13.
*Limit the information provided to the general public (via media outlets), to sanitized and
approved information, through a designated and trained media relation spokesperson.
4. Gateway Security [GS]
4.1. Policy Objective
The main purpose of this policy is to provide minimum security requirement for securing gateways used for interagencies communications as well as for external link communications.
The deployment of a controlled gateway can be used to ensure that only allowable information is transferred between
the gateway and the connected networks. This can be used to preserve need-to-know requirements and to prevent
malicious activities propagating from one network connected to another. Gateways include routers, firewalls, content
filtering solutions and proxies.
4.2. Policy & Baseline Controls - General
In order to comply with this policy, Agencies MUST ensure that:
GS 1.
Networks are protected from other networks by gateways and data flows are properly controlled
GS 2.
Gateways connecting Agency networks to other Agency networks, or to uncontrolled public
networks, are implemented:
a. with an appropriate network device to control data flow
b. with all data flows appropriately controlled
c. with gateway components physically located within an appropriately secured server room.
33
GS 3.
Only authorized and trained staff manage and maintain gateways
GS 4.
*Administrative or management access to gateways processing or transmitting
information classified at C3 or above is only provided based on dual control and the four
eyes principles.
GS 5.
Information exchanged through gateways is labelled as per the National Information Classification
policy [IAP-NAT-DCLS] and protected as specified in this document. Gateways SHALL be classified
inline with the information they are transmitting.
NATIONAL INFORMATION ASSURANCE MANUAL