Protection Level Baseline (All Mandatory) Medium & High Controls • All Minimal Controls • All Baseline Controls • Only authorised and certified personnel should carry out repairs and service equipment • Maintenance should preferably be carried within the premises of Agency or in a security controlled environment. • Information should be cleared from equipment when sent for 3rd party repair/maintenance • Only authorised and certified personnel, whose identification papers have been verified by the Agency, shall carry out repairs and service equipment • All Minimal Controls • All Baseline Controls • Home working controls should be determined (e.g. use of lockable cabinets, secure communications etc.) • Portable computers with sensitive data should not be taken out of the zone • Portable computers with sensitive data should employ media encryption • Devices containing sensitive information (including media, firmware passwords, etc.) should be physically destroyed or the information should be destroyed, deleted or overwritten using techniques to make the original information non-retrievable • All Baseline Controls • All Minimal Controls • All Baseline Controls • Employees, contractors and third party users who have authority to permit off-site removal of assets should be clearly identified; • Time limits for equipment removal should be set and returns checked for compliance • 24 x 7 guard at entrance • Perimeter video monitoring • Guard patrolling zone, in addition to guard at entrance • Video monitoring entrance to security zone • Security control centre • 30 day recording retention • Intrusion detection (ex: motion detection & alarm) within zone 53 NATIONAL INFORMATION ASSURANCE MANUAL • Damaged devices containing sensitive information should be physically destroyed • Media containing sensitive information should be physically destroyed. • Removal of “C3” classified information, shall require the authorization of “Information Security Manager”

Select target paragraph3