to the Information Security Manager / Office and the concerned Law enforcement
agencies. The loss / theft SHALL be handled as per the B-8 Incident Management[IM]
OS 10.
*Emergency destruction/locking plan /remote wipe/auto destruct is in place for any MDs
and laptops.
12. Physical Security [PH]
12.1. Policy Objective
The objective of the policy is to ensure prevention of unauthorized physical access, damage, and interference to an
Agency’s premises and information. Agencies need to ensure that appropriate physical security measures and
controls are adopted to meet the baseline requirements of this policy.
12.2. Policy & Baseline Controls
In order to comply with this policy, Agencies MUST ensure:
PH 1.
Appropriate protection for physical space is determined based on an assessment of risk. This
assessment SHALL occur during the design phase of a new construction or, for existing workplaces,
as part of an on-going risk management process.
PH 2.
Physical spaces are zoned depending upon their security requirement. Each zone is designated a
physical security level. The table below specifies the levels:
Minimal Protection
This provides a level of security designed to control assets
with no classification (e.g. C0I0A0). It is generally unsuitable
for (non-public) government operations.
Baseline Protection
This provides a level of security designed to control assets of
moderate value or classified as ‘Low‘. It is generally used as
the baseline for government operations.
Medium Protection
This provides a level of security designed to control assets of
medium value or classified as ‘Medium‘.
High Protection
This provides a level of security designed to control assets of
high value or classified as ‘High‘.
PH 3.
Each zone has the appropriate physical security controls implemented. Appendix A provides details
of these minimal and baseline protection controls, together with recommendations for additional
controls. Medium protection requires one additional class of control, whereas High protection
requires two additional class of control. An Agency MAY incorporate additional controls in
addition to those mandated by this policy.
PH 4.
Implementation of a “clean desk” and “clean screen” policy.
PH 5.
Server/Data rooms meet at least the medium protection requirement
PH 6.
*Cabling carrying information at levels C1-C3 is physically separate (including for fibre
optic cabling) and is in separate ducting to that carrying Nationally Classified information
PH 7.
A site security plan and where necessary standard operating procedures (SOPs) for each secure
areas are developed and implemented. Information to be covered includes, but is not limited to:
a. a summary of the protective security risk assessment
b. roles and responsibilities of facility or ICT security officer and staff members;
c. the administration, operation and maintenance of the electronic access control system and/or
security alarm system
NATIONAL INFORMATION ASSURANCE MANUAL
46