security posture, including any incidents. TM5. The services, reports and records provided by the third party should be continuously monitored and reviewed, and audits should be conducted on defined periodic intervals. 4. Data Labelling [DL] 4.1. Policy Objective This policy provides a high-level data labelling methodology for all Agencies for the purpose of understanding and managing data and information assets with regard to their level of classification. The policy explains the methodology and the processes for effective data labelling. The rationale for labelling information assets per their classification levels is to ensure the Agency and the designated users of the information assets will be able to correctly identify and adequately allocate resources for the protection of the information assets. 4.2. Policy & Baseline Controls Although this document provides an overall policy to achieve consistent data labelling, the Agency MAY be expected to extend these concepts to fit the needs of National Classification Markings. To meet the requirements of this policy Agencies MUST: DL1. *Serve as a labelling authority for the data and information that it collects or maintains. DL2. *Rate all information assets in accordance with [IAP-NAT-DCLS]. All assets rated with a Confidentiality rating of C1, C2 or C3 SHALL be suitably marked the data label of Internal, Limited Access or Restricted respectively. DL3. *By default, classify information assets as ‘Internal’ unless they are specifically for public release or consumption. DL4. Establish the data labelling system to support the “Need-To-Know” requirement, so that information will be protected from unauthorized disclosure and use. DL5. Establish data labelling education and awareness for its staff, employees and contractors. 5. Change Management [CM] 5.1. Policy Objective The purpose of the Change Management Policy is ensure no unauthorized changes are made to information systems to which may otherwise expose, disclose or threaten CIA of information. It is necessary to document, review, approve and implement changes in a formal process oriented mechanism to minimize security or business risks and to derive maximum value from information resources. 5.2. Policy & Baseline Controls To comply with this policy Agencies MUST: CM 1. *Define and adhere to a documented change management process which may include the following or similar change categories: a. Planned Major Change. Examples of planned major changes are: •  Change that results in business interruption during regular business hours •  Change that results in business or operational practice change •  Changes in any system that affects disaster recovery or business continuity •  Introduction or discontinuance of an information technology service b. Maintenance and Minor Changes. Examples of this type of change are: • Application level security changes/patches • Operating system patches (critical, hotfixes, and service packs) NATIONAL INFORMATION ASSURANCE MANUAL 20

Select target paragraph3