Page 3.3 3.4 Human Factors 3 - 6 3.3.1 Personnel Security 3 - 7 3.3.1.1 Confidentiality Agreement 3 - 7 3.3.1.2 Personnel Screening 3 - 7 3.3.2 Awareness 3 - 7 3.3.3 Problem Employees 3 - 7 3.3.4 Former Employees 3 - 7 Electronic Facilities 3 - 8 3.4.1 Telecommuting 3 - 8 3.4.2 Voice, Telephone and Related Equipment 3 - 8 3.4.2.1 Access to Voice Mail system 3 - 9 3.4.2.2 Private Branch Exchange 3 - 9 3.4.2.3 Spoken Word 3 - 9 3.4.2.4 Intercept 3 - 10 3.4.2.5 Casual Viewing 3 - 10 3.4.2.6 Output Distribution Schemes 3 - 10 3.4.2.7 Destruction 3 - 10 3.4.2.8 Clock Synchronization 3 - 10 3.4.3 3.5 Facsimile 3 - 10 3.4.3.1 Modification 3 - 11 3.4.3.2 Transmission Acknowledgement 3 - 11 3.4.3.3 Misdirection of Messages 3 - 11 3.4.3.4 Disclosure 3 - 11 3.4.3.5 Unsolicited Messages 3 - 11 3.4.3.6 Retention of Documents 3 - 12 Electronic Mail 3 - 12 3.5.1 Authorised Users 3 - 12 3.5.2 Physical Protection 3 - 12 3.5.3 Logical Protection 3 - 12 3.5.4 Integrity of Content 3 - 13 3.5.5 Disclosure 3 - 13 3.5.6 Message Retention 3 - 13 3.5.7 Message Reception 3 - 13 3.5.8 Protection against Malicious Code 3 - 14 3.5.9 Security Labelling 3 - 14 vii

Select target paragraph3