6.5. Policy & Baseline Controls – Databases In order to comply with this policy, Agencies MUST ensure: SS 27. All information stored within a database is associated with an appropriate classification if the information: a. could be exported to a different system, or b. contains differing classifications and/or different handling requirements. SS 28. Agencies should ensure that classifications are applied with a level of granularity sufficient to clearly define the handling requirements for any information retrieved or exported from a database. SS 29. *Database files are protected from access that bypasses the database’s normal access controls. SS 30. Databases provide functionality to allow for auditing of system users’ actions. SS 31. *System users who do not have sufficient privilege to view database contents cannot see associated metadata in a list of results from a search engine query. If results from database queries cannot be appropriately filtered, agencies MUST ensure that all query results are appropriately sanitized to meet the minimum-security privilege of system users. SS 32. Sensitive data in database shall be masked using data masking technology for C3 & above. 7. System Usage Security [SU] 7.1. Policy Objective This policy establishes the need for Agencies to clearly define what behaviours and actions are permitted on their systems, and what is unacceptable. Agencies MUST ensure that system users have awareness training to ensure they understand their obligations. 7.2. Policy & Baseline Controls In order to comply with this policy, Agencies MUST ensure that: SU 1. System users SHALL be responsible for the information assets (systems / infrastructure) provided to them to carry out their official responsibilities. They SHALL handle the information assets with due care and operate them in line with the vendor / Agency’s Acceptable usage policy. SU 2. System users will conduct due diligence when accessing the web and browsing the web SHALL strictly follow Agency principles and guidelines on accessing the internet. Agencies SHOULD consider whether usage of forums, social networks, etc is permitted or not. SU 3. ICT assets are protected against web-based threats by implementing measures that will prevent downloading software programs, active content and non- business related websites. SU 4. Web access is provided through secure proxies and filtering gateways as defined in section C 4, Gateway Security [GS]. SU 5. *Staff is aware of the types of content permitted and restricted within the Agency, as specified in section B- 4, Gateway Security [GS]. Agencies SHOULD consider an effective solution for monitoring content of encrypted channels. SU 6. Staff use e-mail with due diligence and include necessary classification labeling depending upon the content/attachments according to National Information Classification Policy [IAP-NAT-DCLS]. SU 7. Appropriate measures are taken that e-mail is protected against potential threats as viruses, trojans, spam mails, forgery and social engineering SU 8. *Staff is aware that web based public e-mail services are not allowed to be used to send and receive e-mails from Agency systems. SU 9. Staff is aware that e-mails used to exchange confidential information SHOULD only be sent to named recipients and not to a group or distribution list. SU 10. Staff is aware that the use of automatic forwarding of e-mails is dependent upon the sensitivity NATIONAL INFORMATION ASSURANCE MANUAL 38

Select target paragraph3