a. removal of unwanted software
b. disabling of unused or undesired functionality in installed software and operating systems
c. implementation of access controls on relevant objects to limit system users and programs to the
minimum access needed to perform their duties
d. installation of software-based firewalls limiting inbound and outbound network connections
e. configuration of either remote logging or the transfer of local event logs to a central server.
SS 14.
*Potential vulnerabilities in their SOEs and systems are reduced by:
a. removing unnecessary file shares
b. ensuring patching is up to date
c. disabling access to all unnecessary input/output functionality.
d. removing unused accounts
e. renaming default accounts
f. replacing default passwords.
SS 15.
High risk servers e.g. Web, email, file and Internet Protocol telephony servers, etc. having
connectivity to uncontrolled public networks:
a. maintain effective functional separation between servers allowing them to operate independently
b. minimise communications between servers at both the network and file system level, as
appropriate
c. limit system users and programs to the minimum access needed to perform their duties.
SS 16.
Check the integrity of all servers whose functions are critical to the Agency, and those identified as
being at a high risk of compromise. Wherever possible these checks SHOULD be performed from a
trusted environment rather than the system itself.
SS 17.
Store the integrity information securely off the server in a manner that maintains integrity
SS 18.
Update the integrity information after every legitimate change to a system
SS 19.
*As part of the Agency’s ongoing audit schedule, compare the stored integrity information
against current integrity information to determine whether a compromise, or a legitimate
but incorrectly completed system modification, has occurred
SS 20.
Resolve any detected changes in accordance with the Agency’s information and communications
technology (ICT) security incident management procedures.
SS 21.
*All software applications are reviewed to determine whether they attempt to establish
any external connections. If automated outbound connection functionality is included, Agencies
SHOULD make a business decision to determine whether to permit or deny these connections,
including an assessment of the risks involved in doing so.
6.4. Policy & Baseline Controls – Web Applications
In order to comply with this policy, Agencies MUST ensure:
37
SS 22.
*All active content on their Web servers is reviewed for security issues. Agencies
SHOULD follow the documentation provided in the Open Web Application Security Project
(OWASP) guide to building secure Web applications and Web services.
SS 23.
Connectivity and access between each Web application component is minimised.
SS 24.
That Personal Information and sensitive data is protected whilst in storage and in transmission
using appropriate cryptographic controls
SS 25.
Critical sector websites that need to be strongly authenticated, use SSL certificates provided from
a Certificate Service Provider (CSP) licensed in the State of Qatar.
SS 26.
Web application firewall (WAF) MUST be used for applications with MEDIUM or higher risk rating.
NATIONAL INFORMATION ASSURANCE MANUAL