6.4. Policy & Baseline Controls – Web Applications
37
6.5. Policy & Baseline Controls – Databases
38
7. System Usage Security [SU]
38
7.1. Policy Objective
38
7.2. Policy & Baseline Controls
38
8. Media Security [MS]
39
8.1. Policy Objectives
39
8.2. Policy & Baseline Controls - Media Classification and Labelling
39
8.3. Policy & Baseline Controls - Media Sanitization
39
8.4. Policy & Baseline Controls - Media Repairing and Maintenance
40
8.5. Policy & Baseline Controls - Media Destruction & Disposal
40
9. Access Control Security [AM]
40
9.1. Policy Objective
40
9.2. Policy & Baseline Controls - General
40
9.3. Policy & Baseline Controls – Identification & Authentication
41
9.4. Policy & Baseline Controls – System Access
43
9.5. Policy & Baseline Controls – Privileged Access
43
9.6. Policy & Baseline Controls – Remote Access
43
10. Cryptographic Security [CY]
44
10.1. Policy Objective
44
10.2. Policy & Baseline Controls
44
11. Portable Devices & Working Off-Site Security [OS]
45
11.1. Policy Objective
45
11.2. Policy & Baseline Controls - General
45
12. Physical Security [PH]
46
12.1. Policy Objective
46
12.2. Policy & Baseline Controls
46
13. Virtualization [VL]
47
12.1. Policy Objective
47
12.2. Policy & Baseline Controls
47
APPENDIX A (NORMATIVE) – PHYSICAL CONTROLS
48
APPENDIX B (NORMATIVE) –
APPROVED CRYPTOGRAPHIC ALGORITHMS AND PROTOCOLS
54
APPENDIX C (NORMATIVE) –
INCIDENT MANAGEMENT CRITICALITY CLASSIFICATION
56
APPENDIX D (INFORMATIVE) –
SAMPLE NON-DISCLOSURE AGREEMENT (NDA)
13
NATIONAL INFORMATION ASSURANCE MANUAL
58