c)
d)
e)
f)
g)
h)
i)
j)
k)
restriction of software installation;
requirements for mobile device software versions and for applying patches;
restriction of connection to information services;
access controls;
cryptographic techniques;
malware protection;
remote disabling, erasure or lockout;
backups;
usage of web services and web apps.
Mobile devices should also be physically protected against theft especially when left, for
example, in cars and other forms of transport, hotel rooms, conference centers and meeting
places. Devices carrying important, sensitive or critical business information should not be left
unattended and, where possible, should be physically locked away, or special locks should be
used to secure the devices.
Where the mobile device policy allows the use of privately owned mobile devices , the policy
and related security measures should also consider:
a) separation of private and business use of the devices, including using software to
support such separation and protect business data on a private device;
b) providing access to business information only after users have signed an end user
agreement acknowledging their duties (physical protection, software updating, etc.),
waiving ownership of business data, allowing remote wiping of data by the
organization in case of theft or loss of the device or when no longer authorized to
use the service. This policy needs to take account of privacy legislation.
(NL ISO/IEC, 2015)
6. Information Transfer Policies and Procedures
Formal transfer policies, procedures and controls should be in place to protect the transfer of
information through the use of all types of communication facilities.
The procedures and controls to be followed when using communication facilities for
information transfer should consider the following items:
a) procedures designed to protect transferred information from interception, copying,
modification, miss-routing and destruction;
b) procedures for the detection of and protection against malware that may be
transmitted through the use of electronic communications;
c) procedures for protecting communicated sensitive electronic information that is in
the form of an attachment;
d) policy or guidelines outlining acceptable use of communication facilities;
e) use of cryptographic techniques e.g. to protect the confidentiality, integrity and
authenticity of information;
Lebanese National Security Policy Guidelines v1.7
Page
29 |