21.1. Network Management ...................................................................................................... 99 21.2. Wireless Local Area Networks ......................................................................................... 101 21.3. Video and Telephony Conferencing and Internet Protocol Telephony .......................... 105 21.4. Intrusion Detection and Prevention ................................................................................ 107 21.5. Gateways ......................................................................................................................... 109 21.6. Firewalls ........................................................................................................................... 111 21.7. Diodes .............................................................................................................................. 112 21.8. Session Border Controller ................................................................................................ 112 22. Working Off‐Site ..................................................................................................................... 116 22.1. Agency Owned Mobile Devices ....................................................................................... 116 22.2. Working outside the Office ............................................................................................. 117 22.3. Non‐Agency Owned Devices and Bring Your Own Device (BYOD) .................................. 117 23. Enterprise System Security ..................................................................................................... 123 23.1. Cloud Computing ............................................................................................................. 123 23.2. Virtualization ................................................................................................................... 125 24. Annexure ................................................................................................................................. 128 24.1. Annex 1‐ Impact Classification System ............................................................................ 128 24.2. Annex 2 ‐Threat Vector Analysis ..................................................................................... 129 24.3. Annex 3 ‐ Cause Analysis ................................................................................................. 130 24.4. Annex 4 ‐ Incident response plan, policy & Procedure Creation .................................... 131 24.5. Annex 6 – Access Control Event Logging ......................................................................... 131 25. References .............................................................................................................................. 133 5

Select target paragraph3