other than the originator. 4.4. Policy & Baseline Controls – Data Import In order to comply with this policy, Agencies MUST ensure that: GS 15. System users: a. are held accountable for the data they import b. are instructed to perform a protective marking check, a visual inspection and a metadata check if relevant. GS 16. *Data imports are either: a. performed in accordance with processes and/or procedures approved by the Agency; or b. individually approved by the information security manager. GS 17. *Data imported to a Agency system is scanned for malicious and active content. 5. Product Security [PR] 5.1. Policy Objective This policy establishes the minimum security for selecting and acquiring information products through a proper selection and acquisition process. Agencies MUST ensure that selected products are chosen after an independent evaluation process that meets the security requirements listed in this policy. 5.2. Policy & Baseline Controls In order to comply with this policy, Agencies MUST ensure that: PR 1. The process for product selection is carried out with due diligence and ensures product and vendor independence. PR 2. Products are classified and labeled as per National Information Classification policy [IAP-NATDCLS]. PR 3. *The selection process includes proper identification of vendor, screening of vendors and evaluation criteria definition which should include as a minimum: a. Vendor status and identification, including location and ownership b. Financial situation c. References from previous successful engagements d. The ability of the vendor to build and/or maintain appropriate controls as determined by a risk assessment 35 PR 4. Proper testing and effective matching between vendor’s claim and functionality is carried out, to avoid loss of confidentiality, integrity and/or availability. PR 5. *Security evaluation of the product is done on a dedicated evaluation configuration including functionality tests, security tests and patching to protect against potential threats and vulnerabilities. PR 6. Delivery of products is consistent with the Agency’s security practice for secure delivery. PR 7. Secure delivery procedures SHALL include measures to detect tampering or masquerading. PR 8. *Products have been purchased from developers that have made a commitment to the ongoing maintenance of the assurance of their product. PR 9. Product patching and updating processes are in place. Updates to of products SHALL follow the change management policies specified in section B- 5, Change Management [CM]. NATIONAL INFORMATION ASSURANCE MANUAL

Select target paragraph3