Agency. AM 25. Lost, stolen, compromised passwords are immediately: a. reported, to the Security Manager who SHALL ensure the corresponding account is suspended b. changed upon user identity verification AM 26. *Accounts that are inactive for more than three (3) months are suspended. AM 27. *Accounts on systems processing information rated C2, I2, A2 or above are audited for currency on a six (6) monthly basis. 9.4. Policy & Baseline Controls – System Access In order to comply with this policy, Agencies MUST ensure: AM 28. Security policies document any access requirements, security clearances and briefings necessary for system access. AM 29. *System users have been vetted as specified in section B- 6, Personnel Security [PS], before being granted access to a system. AM 30. *System users have received any necessary briefings before being granted access to a system. 9.5. Policy & Baseline Controls – Privileged Access In order to comply with this policy, Agencies MUST ensure: AM 31. The use of privileged accounts is documented, controlled and accountable and kept to a minimum. Privileged accounts SHALL only be used for administrative work AM 32. System administrators are assigned an individual account for undertaking their administration tasks AM 33. *Only Qatari nationals have privileged access to systems processing information classified at C4 and above unless explicit authorisation for exemption to this policy is given. AM 34. *System management log is updated to record the following information: a. sanitisation activities b. system startup and shutdown c. component or system failures d. maintenance activities e. backup and archival activities f. system recovery activities g. special or out of hours activities. 9.6. Policy & Baseline Controls – Remote Access In order to comply with this policy, Agencies MUST ensure: 43 AM 35. Remote access SHALL NOT be provided unless authorized explicitly by the department head and only if it is warranted by business requirements and only after due diligence has been performed to analyze associated risks and suitable controls are implemented to mitigate the identified risks. AM 36. *Two factor authentication, using a hardware token, biometric control or similar is used when accessing systems processing data classified at C3 or above. AM 37. *Remote access sessions are secured by using suitable end-to-end encryption as specified in section C- 10, Cryptographic Security [CY]. AM 38. Remote access computers are equipped with at a minimum, a personal firewall and anti-malware software. These security controls SHALL be activated at all times. AM 39. Software, including security software on these computers SHALL be patched and kept up to date. NATIONAL INFORMATION ASSURANCE MANUAL

Select target paragraph3