NS 58.
*Soft-phones, if permitted are through a secure connection. e.g. secure VPN.
NS 59.
Backup power is provided to POE VoIP phone devices in case of failure of power.
NS 60.
Strong authentication and access controls are implemented to protect the voice gateway system.
NS 61.
IPSEC or Secure Shell (SSH) is used for all remote management and auditing access.
NS 62.
Contingency plans for making voice calls are developed if VoIP systems become unavailable.
NS 63.
*Port security features are enabled on the network LAN switches that connect VoIP
devices.
2.12. Policy & Baseline Controls – Internet Protocol Version 6
In order to comply with this policy Agencies MUST ensure that:
NS 64.
*A proper risk assessment is conducted by the Agency to assess the security merits and
demerits of IPv4 and IPv6 technology. Agencies SHOULD start considering IPv6 deployment.
NS 65.
A proper risk assessment is conducted if the Agency decided to implement a dual-stack environment.
NS 66.
Recertification is requested where Agencies deploy IPv6 in their network.
3. Information Exchange [IE]
3.1. Policy Objective
The purpose of this policy is to provide baseline security requirements when a Agency is exchanging confidential
information with other government agencies or with other third parties.
3.2. Policy & Baseline Controls
To meet the requirements of this policy Agencies SHALL:
IE1.
Prior to establishing cross-domain connectivity, the Agency evaluates, understands and accepts
the structure, security and risks of other domains. This risk review SHALL be documented for
compliance requirements.
IE2.
*When intending to connect an agency network to another secured network, they:
a. obtain a list of networks to which the other network is connected from the other network’s
Accreditation, Authority and System Manager,
b. examine the information from both sources to determine if any unintended cascaded connections
exist, and
c. consider the risks associated with any identified cascaded connections prior to connecting the
agency network to the other network, particularly where a connection to an un-trusted network
such as the internet may exist.
IE3.
Ensure that necessary agreements (specifically confidentiality agreements) between the entities
exchanging information have been established prior to information exchange. Agreements SHALL
provide information on responsibilities, information exchange notification procedure, technical
standards for transmission, identification of couriers, liabilities, ownership and controls. For
vendors and 3rd parties a formal Non-Disclosure Agreement (NDA) SHALL be used. Appendix D
provides a NDA template.
IE4.
Ensure media which is used to exchange information is protected against unauthorized access,
manipulation or misuse within or outside the Agency environment.
IE5.
Maintain the classification and protection of information that has been obtained from another
Agency.
IE6.
Maintain appropriate levels of physical protection for media in transit and store in packaging that
protects it against any hazard that would render the content unreadable.
IE7.
*Ensure only reliable and trusted courier service or transport organization SHALL be used
based on a list of known and authorized couriers.
NATIONAL INFORMATION ASSURANCE MANUAL
32