National Information Assurance and Cyber Security Strategy (NIACSS) 4.8. 2012 Securing National Information Systems and Networks Securing national systems should not only prevent security breaches, but also detect and respond to possible attacks. Employing Defense-in-Depth multiple layers of protection methods is critical to securing government systems and networks. Defense-inEmploy Defense-in-Depth to Depth is not limited to technical protect national information security methods and procedures. systems Defense-in-Depth should also be resilient to accommodate rapid change in the cyber environment. It also includes a close examination of personnel security, network setup and configuration, and operational procedures. Security vulnerabilities across personnel, technology, and operations must be considered throughout the system's life cycle. It is through the combination of people, technology and operations which provides the greatest cyber security posture. Tactics, techniques, and procedures must be developed in the following areas to ensure success: 4.8.1. Personnel Security Government organizations and private sector must issue security clearances to users, system administrators, and any other parties using or accessing information systems. Security clearance validation and renewal requires appropriate management, background checks, and commitment of resources. Also, cleared personnel require a “need-to-know” and integration in physical security systems to ensure control and monitoring of man and machine in the government information systems. Private sector will manage personnel security issues under its control. Private sector still needs to cooperate with the authorized government organization(s) to fulfill personnel security requirements outside its authority. Page 14 of 20

Select target paragraph3