National Information Assurance and Cyber Security Strategy (NIACSS)
2012
degrade gracefully. Resistance and tolerance are relatively ensured by
having software manufactures a) adhere to software security development
lifecycle and b) constant vulnerability assessment, analysis of perceived
vulnerabilities, and rapid counter-measures or other configuration changes.
A certification and accreditation program should be established for all
critical software that will be used in government entities and business
entities that operate critical national infrastructure. Moreover, Government
organizations and private sector will follow national guidelines, standards,
rules and best practices needed to guarantee software acquisition,
procurement, outsourcing, in-house developed software, and Commercially
available Off-The-Shelf (COTS) components will deliver software that
commit to the national security rules and do not yield security breaches.
4.8.5. Procedural Security
Government
organizations
and
private
sector
must
ensure
information security related procedures are in place, wellunderstood, and successfully implemented. These procedures should
meet the set of regulations, rules, best practices, national information
security policies and standards that direct how an entity manages,
protects its communications and distributes sensitive information.
4.8.6. Electro-Magnetic Emissions (Radiations) Security
Government organizations and private sector must ensure that
sensitive information is not leaked through system electro-magnetic
emissions
(radiations).
Organizations
should
take
necessary
measures to protect systems having sensitive information and
prevent adversaries from exploiting this vulnerability utilizing
Tempest Devices, shielding, Faraday caging and or any other
necessary measures.
Page 16 of 20