1. Policy Objective
This policy specifies a high-level information classification methodology for entities in the State of Qatar. The rationale
for classifying information into classes is to allow appropriate values to be ascertained for information items, their risks
to be determined, and the corresponding protection to be applied.
The following threats are covered in this policy:
•
Unauthorised Disclosure
•
Unauthorised Modification
•
Non-Availability
Consistent use of information classification methodology will facilitate business activities, ensure compliance with
accepted best practices, and help keep the costs of information security to a minimum. Without its use, Agencies would
have varying levels of protection applied to assets, with no defined baseline in place.
2. Scope
This policy applies to all Agencies and their corresponding Information Assets unless specifically exempted.
The following definitions, outlined in [IAP-NAT-IAFW] are used in this policy: Agency, Information Asset,
Unauthorised Disclosure, Unauthorised Modification, Availability
The following normative references apply:
[IAP-NAT-IAFW]
Information Assurance Framework, 2008
[IAP-NAT-INFA]
National Information Assurance Policy, 2014
[IAP-NAT-CIIP]
Critical Information Infrastructure Protection Law, 2014
3. Policy
3.1
Agencies SHALL prioritise their compliance of this policy by determining the criticality of their processes
according to the following:
a. 1st Priority: Criticality to the State of Qatar. Processes SHALL be checked against Appendix A,
[IAP-NAT-CIIP] to check whether they are critical at a national level.
b. 2nd Priority: Criticality to the Agency. Processes SHALL be assessed based upon their criticality to
the functioning of the Agency, using a Business Impact Analysis, Appendix A maybe used for this.
3.2
Agencies SHALL develop a compliance plan, which shows the compliance priority of processes
(as specified in section 3.1), their dependent Information Assets and the schedule for assessment and control
implementation.
3.3
For dependent Information Assets, Agencies SHALL:
a. Classify them according to a classification scheme, Appendix B maybe used for this.
b. Prioritise the implementation of controls based on the aggregate security level.
c. Apply baseline controls as specified in [IAP-NAT-INFA] to all classified assets. Additional, stronger controls
MAY be applied, if necessary.
d. Consistently protect controlled Information Assets throughout their life, from their origination to their
destruction, in a manner commensurate with their sensitivity, regardless of where they reside, what form
they take, what technology was used to handle them, or what purpose(s) they serve.
e. Ensure assets with confidentiality requirements of C1, C2 or C3 are appropriately labelled as specified in
[IAP-NAT-INFA].
4. Compliance
4.1
All Agencies SHALL be audited for compliance to this policy on an annual basis by a Certification body.
NATIONAL INFORMATION ASSURANCE POLICIES
6