Information Classification Policy [IAP-NAT-DCLS], covering system users’:
a. identification
b. authentication
c. authorisation
AM 13.
They educate their system users of the Agency’s policies and procedures.
AM 14.
All system users are:
a. uniquely identifiable
b. authenticated on each occasion that access is granted to a system.
AM 15.
*Individuals who are not employees, contractors, or consultants are not granted a
user account or be given privileges to use the Agency’s information resources or
communications systems unless explicitly approved by the Security Manager who SHALL
check that appropriate agreements, clearance and access forms have been completed.
AM 16.
*That alternate methods of determining the identification of the system user are in place
when shared/non-specific accounts are used.
AM 17.
*Unprotected authentication information that grants system access, or decrypts an
encrypted device is located on, or with the system or device, to which the authentication
information grants access to.
AM 18.
*System authentication data whilst in use is not susceptible to attacks including, but not
limited to, replay, man-in-the-middle and session hijacking
AM 19.
*A password policy enforcing either a minimum password length of 12 characters with no
complexity requirement or a minimum password length of seven characters, consisting of
at least three of the following character sets:
a. lowercase characters (a-z)
b. uppercase characters (A-Z)
c. digits (0-9)
d. punctuation and special characters
AM 20.
*Passwords are changed at least every 90 days
AM 21.
*System users cannot change their password more than once a day and the system
forces the user to change an expired password on initial logon or if reset.
AM 22.
*Chosen passwords are checked to prevent:
a. predictable reset passwords
b. reuse of passwords when resetting multiple accounts
c. passwords to be reused within eight password changes
d. users to use sequential passwords
AM 23.
*Screen and/or session locks configured to:
a. activate after a maximum of 15 minutes of system user inactivity
b. activate manually by the system user, if desired
c. lock to completely conceal all information on the screen
d. ensure the screen does not appear to be turned off while in the locked state
e. have the system user re-authenticate to unlock the system
f. deny system users the ability to disable the locking mechanism.
AM 24.
Access to a system is suspended after a specified number of failed logon attempts or as soon
as possible after the staff member no longer needs access, due to changing roles or leaving the
NATIONAL INFORMATION ASSURANCE MANUAL
42