12.3. Using the Internet Objective: Mandatory Control 1: Mandatory Control 2: Mandatory Control 3: Recommended Control 1: Recommended Control 2: Recommended Control 3: Personnel use Internet services in a responsible and security conscious manner, consistent with agency policies Agencies must make their system users aware of the agency’s Web usage policies and personnel must formally acknowledge and accept agency Web usage policies Agencies must ensure personnel are instructed to take special care when posting information on the Web Agencies must ensure personnel posting information on the Web maintain separate professional accounts from any personal accounts they have for websites Accessing personal accounts from agency systems should be discouraged Agencies should notallow personnel to use peer‐to‐peer applications over the Internet Agencies should notallow personnel to receive files via peer‐to‐ peer, IM or IRC applications This section covers information relating to personnel using Internet services such as the Web, Web‐ based email, news feeds, subscriptions and other services. Users mustbe familiar with and formally acknowledge agency Web usage policies for system users in order to follow the policy and guidance. Personnel need to take special care not to accidentally post information on the Web, especially in forums and blogs. Even unclassified information that appears to be benign in isolation could, in aggregate, have a considerable security impact on the agency, government sector or wider government. To ensure that personal opinions of agency personnel are not interpreted as official policy or associated with an agency, personnel will need to maintain separate professional and personal accounts when using websites, especially when using online social networks. Accessing personal accounts from an agency’s systems is discouraged. Personnel using peer‐to‐peer file sharing applications are often unaware of the extent of files that are being shared from their workstation. In most cases peer‐to‐peer file sharing applications will scan workstations for common file types and share them automatically for sharing or public consumption. Examples of peer‐to‐peer file sharing applications include Shareaza, KaZaA, Ares, Limewire, eMule and uTorrent. When personnel receive files via peer‐to‐peer file sharing, IM or IRC applications they are often bypassing security mechanisms put in place by the agency to detect and 54

Select target paragraph3