GS 6. Demilitarized zones (DMZs) are used to separate externally accessible systems from uncontrolled public networks and internal networks via usage of firewalls and other network security capable equipment GS 7. Gateways: a. are the only communications paths into and out of internal networks b. by default, deny all connections into and out of the network c. allow only explicitly authorised connections d. are managed via a secure path isolated from all connected networks e. provide sufficient audit capability to detect gateway security breaches and attempted network intrusions f. provide real-time alarms. GS 8. *Gateways are hardened prior to any implementation on production site and are protected against: a. Malicious code and vulnerabilities b. Wrong or poor configurations c. Account compromise and privilege escalation d. Rogue network monitoring e. Denial of service (DoS) attacks f. Information/data leakage GS 9. *Monitoring and supervision of gateways is in place and include threat prevention mechanisms, logging, alerts and surveillance of equipments. Section B- 10, Logging & Security Monitoring [SM]. GS 10. Gateways block or drop any data identified by a content filter as suspicious, including at least the following: a. *Offensive language or attachments b. Malware infected content c. DoS attacks d. *Categories of website/content defined as inappropriate in the proposed Cyber Crime Law including sites hosting obscene material, gambling sites, etc. 4.3. Policy & Baseline Controls – Data Export In order to comply with this policy, Agencies MUST ensure that: GS 11. System users: a. are held accountable for the data they export b. are instructed to perform a protective marking check, a visual inspection and a metadata check if relevant on whether the information can be exported GS 12. Data exports are either: a. performed in accordance with processes and/or procedures approved by the Agency; or b. individually approved by the information security manager. GS 13. *Export of data to a less classified system is restricted by filtering data using at least checks on classification labels. GS 14. *Data exports are checked, ensuring: a. keyword searches are performed on all textual data b. any unidentified data is quarantined until reviewed and approved for release by a trusted source NATIONAL INFORMATION ASSURANCE MANUAL 34

Select target paragraph3