c) d) e) f) g) h) i) j) k) restriction of software installation; requirements for mobile device software versions and for applying patches; restriction of connection to information services; access controls; cryptographic techniques; malware protection; remote disabling, erasure or lockout; backups; usage of web services and web apps. Mobile devices should also be physically protected against theft especially when left, for example, in cars and other forms of transport, hotel rooms, conference centers and meeting places. Devices carrying important, sensitive or critical business information should not be left unattended and, where possible, should be physically locked away, or special locks should be used to secure the devices. Where the mobile device policy allows the use of privately owned mobile devices , the policy and related security measures should also consider: a) separation of private and business use of the devices, including using software to support such separation and protect business data on a private device; b) providing access to business information only after users have signed an end user agreement acknowledging their duties (physical protection, software updating, etc.), waiving ownership of business data, allowing remote wiping of data by the organization in case of theft or loss of the device or when no longer authorized to use the service. This policy needs to take account of privacy legislation. (NL ISO/IEC, 2015) 6. Information Transfer Policies and Procedures Formal transfer policies, procedures and controls should be in place to protect the transfer of information through the use of all types of communication facilities. The procedures and controls to be followed when using communication facilities for information transfer should consider the following items: a) procedures designed to protect transferred information from interception, copying, modification, miss-routing and destruction; b) procedures for the detection of and protection against malware that may be transmitted through the use of electronic communications; c) procedures for protecting communicated sensitive electronic information that is in the form of an attachment; d) policy or guidelines outlining acceptable use of communication facilities; e) use of cryptographic techniques e.g. to protect the confidentiality, integrity and authenticity of information; Lebanese National Security Policy Guidelines v1.7 Page 29 |

Select target paragraph3