12.3.
Using the Internet
Objective:
Mandatory Control 1:
Mandatory Control 2:
Mandatory Control 3:
Recommended Control 1:
Recommended Control 2:
Recommended Control 3:
Personnel use Internet services in a responsible and security
conscious manner, consistent with agency policies
Agencies must make their system users aware of the agency’s Web
usage policies and personnel must formally acknowledge and
accept agency Web usage policies
Agencies must ensure personnel are instructed to take special care
when posting information on the Web
Agencies must ensure personnel posting information on the Web
maintain separate professional accounts from any personal
accounts they have for websites
Accessing personal accounts from agency systems should be
discouraged
Agencies should notallow personnel to use peer‐to‐peer
applications over the Internet
Agencies should notallow personnel to receive files via peer‐to‐
peer, IM or IRC applications
This section covers information relating to personnel using Internet services such as the Web, Web‐
based email, news feeds, subscriptions and other services.
Users mustbe familiar with and formally acknowledge agency Web usage policies for system users
in order to follow the policy and guidance.
Personnel need to take special care not to accidentally post information on the Web, especially in
forums and blogs. Even unclassified information that appears to be benign in isolation could, in
aggregate, have a considerable security impact on the agency, government sector or wider
government.
To ensure that personal opinions of agency personnel are not interpreted as official policy or
associated with an agency, personnel will need to maintain separate professional and personal
accounts when using websites, especially when using online social networks. Accessing personal
accounts from an agency’s systems is discouraged.
Personnel using peer‐to‐peer file sharing applications are often unaware of the extent of files that
are being shared from their workstation. In most cases peer‐to‐peer file sharing applications will
scan workstations for common file types and share them automatically for sharing or public
consumption. Examples of peer‐to‐peer file sharing applications include Shareaza, KaZaA, Ares,
Limewire, eMule and uTorrent. When personnel receive files via peer‐to‐peer file sharing, IM or IRC
applications they are often bypassing security mechanisms put in place by the agency to detect and
54