National Information Assurance and Cyber Security Strategy (NIACSS) 2012 4.8.2. Physical Security Government organizations and private sector must employ all necessary measures to deter, delay, and detect attackers or potential insider threats from accessing a facility, resource, or information stored on physical media. When the physical environment is threatened, appropriate response options must be in place. Organizations should plan for this event, as well as natural disasters, manmade catastrophes, accidental damage and other various events which could damage the information infrastructure. These plans should be tested and exercised regularly to ensure response times and effectiveness. 4.8.3. Network and Communication Security Government organizations and private sector must defend the communications networks, critical infrastructures, networks boundaries, and computing systems that they own through using proper COMSEC and TRANSEC technologies, protection paths and secure alternatives. National networks and communication infrastructures must be secure, reliable and available, they must maintain the trust of government, private sector and individuals, and should be resilient to malicious or arbitrary disruption and or deception. 4.8.4. Software Security Government organizations and private sector must ensure software consistently exhibits required desirable properties even when the software comes under attack. It should minimize the numerous flaws and errors in software that are often located and exploited by attackers to compromise the software’s security and other required properties. Software should be able to resist most attacks and tolerate the majority of those attacks it cannot resist. If neither resistance nor tolerance is possible and the software is compromised, it should be able to isolate itself from the attack source and Page 15 of 20

Select target paragraph3