DC 5. *Review and update documentation periodically to ensure that they are up to date and current. 13. Audit & Certification [AC] 13.1. Policy Objective The objective of this policy is to ensure that a adequate governance and security improvement programme is established and managed by the Agency, which is in compliance with the National Information Classification Policy [IAP-NAT-DCLS] and this NIA Manual. 13.2. Policy & Baseline Controls In order to comply with this policy Agencies SHALL: AC 1. *Ensure the establishment of a governance and security improvement programme in compliance with the National Information Classification Policy [IAP-NAT-DCLS] and this NIA Manual. AC 2. *Comply with relevant provisions of State Laws and regulations that exist at the time and those, which may be amended and / or added at a later date in time. AC 3. *Be audited by the Certification Body or an independent body designated by MOTC. AC 4. *Ensure that an audit of its Information System (infrastructure, people and processes) is carried out at least once every year or whenever it undergoes a change that may impact the security of the Agency. AC 5. *Ensure that the identified scope of the audit process includes all information assets, people and processes. AC 6. *Ensure that recertification is carried out where any change or new finding invalidates or calls into question the current accreditation. Full certification is required for major changes affecting the basic security design of a system and a partial process is needed where the change is moderate or affects two or more security requirements. AC 7. *Ensure that all non-conformance is fixed in a defined timeline. AC 8. *Ensure that any exemptions are approved by the Certification Body. C. SECURITY CONTROLS This section of the NIA Manual covers mainly technical control areas that a Agency needs to implement as baseline security to be compliant to this NIA Manual. The areas covered are Communications Security, Information Exchange, Gateway Security, Product Security, Software Security, System Usage, Media Security, Access Control, Cryptographic Security and finally policy covering portable devices, working off-site and Virualization. 1. Communications Security [CS] 1.1. Policy Objective The objective of the policy is to ensure Agencies take the necessary measures to ensure potential emanation security and physical security weaknesses associated with cabling is minimised. 1.2. Policy & Baseline Controls - Cabling In order to comply with this policy, Agencies MUST ensure: CS 1. Conduits (tubes, ducts or pipes) are used to protect cables from tampering, sabotage or accidental damage, when they are carrying data classified at C4 and above. This control is RECOMMENDED for data classified at C2 and above. CS 2. *Separate cabling distribution is used for systems dealing with information classified at C4 and above NATIONAL INFORMATION ASSURANCE MANUAL 26

Select target paragraph3