• Network Security [NS] • Personnel Security [PS] • Physical Security [PH] • Portable Device & Working Off-Site Security [OS] • Product Security [PR] • Risk Management [RM] • Security Awareness [SA] • Software Security [SS] • System Usage Security [SU] • Third Party Security Management [TM] • Virtualization [VL] Within this manual, baseline controls (indicated by ‘*’) are mandatory and must be followed at minimum and implemented respectively. These form auditable items, against which conformance will be sought. Agencies may implement over and above the baseline. In case NIA controls intersect with other Laws and regulations, Agency must consider compliance to both or whichever is providing higher degree of security. The following steps are required to use this manual: a. Use the National Information Classification Policy [IAP-NAT-DCLS] to classify all your information assets. This is a mandatory step before attempting to apply the policy and controls outlined in this document. b. Assets allocated security attributes of I0, A0 and C0 require no baseline controls. Some minimal controls MAY apply. c. Assets allocated security attributes of I1, A1, C1 or above, require compliance to all policy statements that are baseline at minimum; these are indicated by (*). All sections of the manual have positive impact on integrity, availability and confidentiality of assets (to some degree), hence for each asset, the appropriate baseline controls should be implemented. d. Assets allocated security attributes of I2, A2, or C2 require additional controls (one or more) per applicable domain based on the results of a Risk Assessment (see section B- 2, Risk Management [RM] for more details). This assessment needs to be undertaken before these additional controls are chosen. e. Assets allocated security attributes of I3, A3, or C3 require multiple additional controls (two or more) per applicable domain based on the results of a Risk Assessment (see section B- 2, Risk Management [RM] for more details). This assessment needs to be undertaken before these additional controls are chosen. f. Implementation of the chosen controls needs to be undertaken for each asset. Implementation priority should be based on the aggregate security level (L,M,H), with High (H) assets being the highest priority for implementation. 3. Ownership & Maintenance The manual is owned by Ministry of Transport and Communications, MOTC, and shall update the document as when deemed necessary. 4. References [IAP-NAT-DCLS] National Information Classification Policy, 2014 [IAP-NAT-IAFW] Information Assurance Framework, 2008 [AES] NIST FIPS PUB 197 “Advanced Encryption Standard (AES),” November 2001. [CC3.1] Common Criteria for Information Technology Security Evaluation (CC), Version 2.0 (2006) NATIONAL INFORMATION ASSURANCE MANUAL 16

Select target paragraph3