1. Policy Objective This policy specifies a high-level information classification methodology for entities in the State of Qatar. The rationale for classifying information into classes is to allow appropriate values to be ascertained for information items, their risks to be determined, and the corresponding protection to be applied. The following threats are covered in this policy: •  Unauthorised Disclosure •  Unauthorised Modification •  Non-Availability Consistent use of information classification methodology will facilitate business activities, ensure compliance with accepted best practices, and help keep the costs of information security to a minimum. Without its use, Agencies would have varying levels of protection applied to assets, with no defined baseline in place. 2. Scope This policy applies to all Agencies and their corresponding Information Assets unless specifically exempted. The following definitions, outlined in [IAP-NAT-IAFW] are used in this policy: Agency, Information Asset, Unauthorised Disclosure, Unauthorised Modification, Availability The following normative references apply: [IAP-NAT-IAFW] Information Assurance Framework, 2008 [IAP-NAT-INFA] National Information Assurance Policy, 2014 [IAP-NAT-CIIP] Critical Information Infrastructure Protection Law, 2014 3. Policy 3.1 Agencies SHALL prioritise their compliance of this policy by determining the criticality of their processes according to the following: a. 1st Priority: Criticality to the State of Qatar. Processes SHALL be checked against Appendix A, [IAP-NAT-CIIP] to check whether they are critical at a national level. b. 2nd Priority: Criticality to the Agency. Processes SHALL be assessed based upon their criticality to the functioning of the Agency, using a Business Impact Analysis, Appendix A maybe used for this. 3.2 Agencies SHALL develop a compliance plan, which shows the compliance priority of processes (as specified in section 3.1), their dependent Information Assets and the schedule for assessment and control implementation. 3.3 For dependent Information Assets, Agencies SHALL: a. Classify them according to a classification scheme, Appendix B maybe used for this. b. Prioritise the implementation of controls based on the aggregate security level. c. Apply baseline controls as specified in [IAP-NAT-INFA] to all classified assets. Additional, stronger controls MAY be applied, if necessary. d. Consistently protect controlled Information Assets throughout their life, from their origination to their destruction, in a manner commensurate with their sensitivity, regardless of where they reside, what form they take, what technology was used to handle them, or what purpose(s) they serve. e. Ensure assets with confidentiality requirements of C1, C2 or C3 are appropriately labelled as specified in [IAP-NAT-INFA]. 4. Compliance 4.1 All Agencies SHALL be audited for compliance to this policy on an annual basis by a Certification body. NATIONAL INFORMATION ASSURANCE POLICIES 6

Select target paragraph3