UNCLASSIFIED 5.4 Secure Information Sharing Secure information sharing is about ascertaining that exchange partners have in place security controls that achieve the minimum-security outcomes below. IS3 – All organisations, particularly those within and/or connecting to Government, must require internal and external entities to show compliance with mandated NISF requirements and approved security policies before sharing or allowing connections to protected computer assets. As a minimum requirement, organisations must: (a) identify and record risks involving external parties; (b) create information exchange policies and procedures; (c) use formal exchange agreements such as codes of connection and memoranda of understanding; (d) assess compliance of exchange partners at least annually or when required; and, (e) disconnect/end sharing with non-compliant entities. To achieve the security outcomes mandated above, organisations must:  Ensure that users are fully conversant and comply with approved information exchange policies, procedures, controls and relevant national legislation;  Use cryptographic solutions to provide users and applications the underlying “trust” to operate authentication, integrity, confidentiality and non-repudiation security services to protect collaborative tools and information exchanges;  Establish exchange agreements that require parties seeking access to GoU and other critical infrastructure to have in place security measures that match the security classification and handling requirements for the asset;  Ascertain that exchange agreements with external parties are enforceable;  Confirm that receiving parties grasp and are complying with their obligations to protect information assets appropriately;  Adopt policies to handle information assets received from foreign countries and international bodies in line with applicable treaties and arrangements;  Abide by their own obligations under exchange agreements such as codes of connection (CoCos) and memoranda of understanding (MoUs); and  Obtain authorisation before granting third parties access to information and ICT systems owned by another organisation. 25

Select target paragraph3