National Information Assurance and Cyber Security Strategy (NIACSS)
2012
4.8.2. Physical Security
Government organizations and private sector must employ all necessary
measures to deter, delay, and detect attackers or potential insider threats
from accessing a facility, resource, or information stored on physical media.
When the physical environment is threatened, appropriate response options
must be in place. Organizations should plan for this event, as well as natural
disasters, manmade catastrophes, accidental damage and other various
events which could damage the information infrastructure. These plans
should be tested and exercised regularly to ensure response times and
effectiveness.
4.8.3. Network and Communication Security
Government organizations and private sector must defend the
communications
networks,
critical
infrastructures,
networks
boundaries, and computing systems that they own through using
proper COMSEC and TRANSEC technologies, protection paths and
secure
alternatives.
National
networks
and
communication
infrastructures must be secure, reliable and available, they must
maintain the trust of government, private sector and individuals, and
should be resilient to malicious or arbitrary disruption and or
deception.
4.8.4. Software Security
Government organizations and private sector must ensure software
consistently exhibits required desirable properties even when the software
comes under attack. It should minimize the numerous flaws and errors in
software that are often located and exploited by attackers to compromise the
software’s security and other required properties. Software should be able to
resist most attacks and tolerate the majority of those attacks it cannot resist.
If neither resistance nor tolerance is possible and the software is
compromised, it should be able to isolate itself from the attack source and
Page 15 of 20