UNCLASSIFIED
5.4
Secure Information Sharing
Secure information sharing is about ascertaining that exchange partners have in
place security controls that achieve the minimum-security outcomes below.
IS3 – All organisations, particularly those within and/or connecting to
Government, must require internal and external entities to show compliance
with mandated NISF requirements and approved security policies before
sharing or allowing connections to protected computer assets. As a minimum
requirement, organisations must: (a) identify and record risks involving external
parties; (b) create information exchange policies and procedures; (c) use
formal exchange agreements such as codes of connection and memoranda of
understanding; (d) assess compliance of exchange partners at least annually
or when required; and, (e) disconnect/end sharing with non-compliant entities.
To achieve the security outcomes mandated above, organisations must:
Ensure that users are fully conversant and comply with approved information
exchange policies, procedures, controls and relevant national legislation;
Use cryptographic solutions to provide users and applications the underlying
“trust” to operate authentication, integrity, confidentiality and non-repudiation
security services to protect collaborative tools and information exchanges;
Establish exchange agreements that require parties seeking access to GoU
and other critical infrastructure to have in place security measures that match
the security classification and handling requirements for the asset;
Ascertain that exchange agreements with external parties are enforceable;
Confirm that receiving parties grasp and are complying with their obligations
to protect information assets appropriately;
Adopt policies to handle information assets received from foreign countries
and international bodies in line with applicable treaties and arrangements;
Abide by their own obligations under exchange agreements such as codes of
connection (CoCos) and memoranda of understanding (MoUs); and
Obtain authorisation before granting third parties access to information and
ICT systems owned by another organisation.
25