NS 41. *A firewall or router is in place between the access point and the Agency’s network to filter connections. Restricted firewall rules MUST be applied to allow only needed ports to pass from the wireless segment. NS 42. WIPS/WIDS installation is recommended for networks with C3+ to monitor threats from wireless installations like rouge Aps, DOS attacks, etc. NS 43. Use multiple SSIDs with different configurations for different VLANs, client authentication methods, etc. For example, contract staff or guest may use a different WIFI connections. Guest WIFI may have lower security and may only allow for connecting to the internet. 2.9. Policy & Baseline Controls – Clock Synchronization In order to comply with this policy Agencies MUST ensure that: NS 44. NTP servers MUST be secured as per best practices. NS 45. *Where a computer or communications device has the capability to operate a real-time clock, it shall be set to an agreed standard, e.g., Universal Coordinated Time (UTC) or local standard time. As some clocks are known to drift with time, there shall be a procedure that checks for and corrects any significant variation. NS 46. State Agency’s MAY use the authorized Qatari Government time server (a part of the Government Network) as the primary NTP server. NS 47. All servers and network devices are synchronized with the local Agency NTP server which is synchronized as specified in NS45 and NS46. 2.10. Policy & Baseline Controls – Virtual Private Networks (VPNs) In order to comply with this policy Agencies MUST ensure that: NS 48. VPNs carrying classified data at C3 or above, SHALL authenticate using two-factor authentication : • first one a one-time password authentication such as a token device or a public/private key system with a strong passphrase • Second username and password using external authenication server (LDAP,Radius , TACACS .etc.) NS 49. VPNs disconnect automatically from Agency’s network after a pre-defined period of inactivity. The user SHALL be required to logon again to reconnect to the network. NS 50. *Dual (split) tunneling is not permitted unless suitable controls are in place. Agencies SHOULD only permit one network connection at a time. NS 51. All computers connected to a Agency’s networks via VPN are equipped with personal security software, latest security patches, anti-virus software and malicious code detection and repair software. This security software SHALL be activated at all time and with the latest virus signatures and malicious code definitions. NS 52. Gateway-level firewalls are installed to control network traffic from VPN clients to authorized information systems or servers. 2.11. Policy & Baseline Controls – Voice over IP Security (VoIP) In order to comply with this policy Agencies MUST ensure that: 31 NS 53. Voice and data are separate networks. The separation SHOULD be physical, but use of Virtual LANS is permitted. The voice gateway, which interfaces with the PSTN segregates H.323, SIP, or other VoIP protocols from the data network. NS 54. VoIP capable gateways and other appropriate security mechanisms are employed. NS 55. *They evaluate and use security enabled protocols such as Secure Real Time Protocol (SRTP) and disable unnecessary voice protocols. NS 56. *Proper physical counter measures are in place to protect the VoIP infrastructure. NS 57. *Adequate call log monitoring is implemented. NATIONAL INFORMATION ASSURANCE MANUAL

Select target paragraph3