a. Disable any active content options, e.g. Java, JavaScript and ActiveX, in the email application/ browser, except when communicating with a trusted source b. Use up-to-date browser versions and apply latest security patches c. Disable password auto-complete/password remembering features d. Enable pop-up blocking features, except when communicating with trusted sites e. Regularly remove cache files or temporary files of the browsers to protect data privacy f. Disable automatic installation of plug-ins, add-ons or software NS 27. *They have the capability needed to monitor the traffic, deduce traffic patterns, usage etc. See section B- 10, Logging & Security Monitoring [SM] for more information. 2.7. Policy & Baseline Controls – E-Mail Security In order to comply with this policy Agencies MUST ensure that: NS 28. E-mail servers are hardened as per best practices and configured as a bastion server. If technically and operationally feasible, information revealing the specific details of internal systems or configurations MUST be avoided in email headers to avoid the disclosure of system information to external parties. NS 29. TLS protection is used with the SMTP Mail server in line with section C-10, Cryptographic Security [CY]. NS 30. *They implement the email Sender Policy Framework (SPF) [RFC4408]. Agencies SHOULD only send undeliverable or bounce emails to senders that can be verified via SPF. NS 31. *Internal email distribution lists are secured to prevent access from external parties to reduce the risk of unsolicited email. NS 32. Email gateways are employed to scan all incoming and outgoing emails to ensure it complies with the Agency’s security policy and that it is free of any malicious code. 2.8. Policy & Baseline Controls – Wireless Security In order to comply with this policy Agencies MUST ensure that: NS 33. *Where wireless LANs (WLANs) are used, they are used with sufficient authentication and transmission encryption measures in place, complemented by proper security management processes and practices. NS 34. *Strong wireless security protocols such as WPA2 and EAP-TLS are used. However, such wireless security protocol should not be solely relied upon to protect data confidentiality and integrity. Agency SHALL deploy dynamic key exchange mechanisms, secure Virtual Private Network (VPN) on top of wireless network if classified data, C3 and above, is to be communicated over wireless networks. WEP SHALL NOT be implemented within any network. NS 35. *A good inventory of all devices with wireless interface cards is maintained. Once a device is reported missing, consider modifying the encryption keys and SSID. NS 36. *Network administrators regularly scan for “rouge” or “unauthorized” wireless access points. NS 37. Access points are located to minimize network tapping from publicly accessible area. NS 38. The client side settings for 802.1x MUST be secured. Some of the techniques are: server certificate validation by selecting the CA certificate, specify the server address and disable it from prompting users to trust new certificates or servers. NS 39. *The network default name, encryption keys and Simple Network Management Protocol (SNMP) community strings (and any insecure configuration) is changed at installation. SSID SHALL NOT reflect the name of any Agency’s departments, system name or product name. NS 40. For non-public wireless access points, encryption keys are regularly changed and SSID broadcasting is disabled. Where applicable MAC address filtering SHOULD also be considered. NATIONAL INFORMATION ASSURANCE MANUAL 30

Select target paragraph3