CS 3. Conduits installed in public or visitor areas are not labelled in a manner that attract undue attention by people who may not have the appropriate security clearances or a need-to-know of the existence of such cabling CS 4. *They maintain a register of cables. The register SHOULD record at least the following: a. cable identification number, b. classification, c. source, d. destination, and e. floor plan diagram. CS 5. *Inspect cables for inconsistencies with the cable register on a regular basis CS 6. Agency’s MAY provision for redundant communication pathways to ensure continued connectivity. 1.3. Policy & Baseline Controls - Telephones & Faxes In order to comply with this policy, Agencies MUST: CS 7. Advise users of the maximum permitted classification level for conversations of both internal and external telephone connections, as determined by the examination of the internal telephone system and the level of the encryption, if any, on external connections CS 8. *Ensure that the speakerphone feature is disabled during telephonic/video conversations where information classified at C3 or above is likely to be discussed and where it may be overheard. CS 9. *Ensure that remote initiation of conferencing equipment is not enabled where it is installed in a sensitive location. CS 10. *Ensure that rooms designated for communication of sensitive material or information or meetings have appropriate controls for preventing the leakage of sound. CS 11. *Ensure that fax machines on both ends are secured using encryption devices, while sending information classified as C2 and above. CS 12. Ensure that all of the standards for the use of fax machines are met at both ends for the level of classification to be sent, and the sender makes arrangements for the receiver to: a. collect the information from the fax machine as soon as possible after it is received, and b. notify the sender if the fax does not arrive within an agreed amount of time, e.g. 10 minutes. 2. Network Security [NS] 2.1. Policy Objective This policy establishes the baseline for the general use and connection of IT networks. Networks have opened the doors to unlimited processing by sharing and inter connection of devices and given birth to concepts like distributed applications, GRID systems etc. However the introduction of networks has posed a slew of concerns, the security of multiple systems as well as the security of the interconnecting network is equally important, especially if public access wide area networks are used. The risks of connecting to outside networks must be weighed against the benefits. It may be desirable to limit connection to outside networks to those hosts that do not store sensitive material and keep vital machines isolated. 2.2. Policy & Baseline Controls - Network Management In order to comply with this policy Agencies MUST ensure that: 27 NS 1. *Details of internal network and system configuration, employee or device related directory services and other sensitive technology are not publicly disclosed or enumerable by unauthorized personnel. NS 2. They remove or disable all the default accounts e.g. root, administrator, etc. or change the password NATIONAL INFORMATION ASSURANCE MANUAL

Select target paragraph3