NS 58. *Soft-phones, if permitted are through a secure connection. e.g. secure VPN. NS 59. Backup power is provided to POE VoIP phone devices in case of failure of power. NS 60. Strong authentication and access controls are implemented to protect the voice gateway system. NS 61. IPSEC or Secure Shell (SSH) is used for all remote management and auditing access. NS 62. Contingency plans for making voice calls are developed if VoIP systems become unavailable. NS 63. *Port security features are enabled on the network LAN switches that connect VoIP devices. 2.12. Policy & Baseline Controls – Internet Protocol Version 6 In order to comply with this policy Agencies MUST ensure that: NS 64. *A proper risk assessment is conducted by the Agency to assess the security merits and demerits of IPv4 and IPv6 technology. Agencies SHOULD start considering IPv6 deployment. NS 65. A proper risk assessment is conducted if the Agency decided to implement a dual-stack environment. NS 66. Recertification is requested where Agencies deploy IPv6 in their network. 3. Information Exchange [IE] 3.1. Policy Objective The purpose of this policy is to provide baseline security requirements when a Agency is exchanging confidential information with other government agencies or with other third parties. 3.2. Policy & Baseline Controls To meet the requirements of this policy Agencies SHALL: IE1. Prior to establishing cross-domain connectivity, the Agency evaluates, understands and accepts the structure, security and risks of other domains. This risk review SHALL be documented for compliance requirements. IE2. *When intending to connect an agency network to another secured network, they: a. obtain a list of networks to which the other network is connected from the other network’s Accreditation, Authority and System Manager, b. examine the information from both sources to determine if any unintended cascaded connections exist, and c. consider the risks associated with any identified cascaded connections prior to connecting the agency network to the other network, particularly where a connection to an un-trusted network such as the internet may exist. IE3. Ensure that necessary agreements (specifically confidentiality agreements) between the entities exchanging information have been established prior to information exchange. Agreements SHALL provide information on responsibilities, information exchange notification procedure, technical standards for transmission, identification of couriers, liabilities, ownership and controls. For vendors and 3rd parties a formal Non-Disclosure Agreement (NDA) SHALL be used. Appendix D provides a NDA template. IE4. Ensure media which is used to exchange information is protected against unauthorized access, manipulation or misuse within or outside the Agency environment. IE5. Maintain the classification and protection of information that has been obtained from another Agency. IE6. Maintain appropriate levels of physical protection for media in transit and store in packaging that protects it against any hazard that would render the content unreadable. IE7. *Ensure only reliable and trusted courier service or transport organization SHALL be used based on a list of known and authorized couriers. NATIONAL INFORMATION ASSURANCE MANUAL 32

Select target paragraph3