AM 40.
*Users do not access Agency internal systems from public computers e.g. Cyber Cafes
etc. or print material to any public computer.
AM 41.
Vendor remote access is limited to situations where there are no other alternatives. In this case,
initiation of the connection SHALL be controlled and monitored by the Agency. Vendor remote
access SHALL only be for a defined period of time, dictated by the duration of the task being
undertaken.
10. Cryptographic Security [CY]
10.1. Policy Objective
This policy establishes the baseline for the use of encryption technologies for keeping information assets confidential
and/or integral. As a custodian of public and confidential information, Agencies must further protect private and
sensitive data/information from all cyber threats and vulnerabilities whether external or internal to the Agency.
10.2. Policy & Baseline Controls
In order to comply with this policy Agencies MUST ensure that:
CY 1.
The cryptographic algorithms, encryption hardware/software, key management systems and digital
signatures, meet the requirements specified in Appendix B of this manual for Approved Encryption/
Cryptographic Algorithms and Systems.
CY 2.
The lifetime of the key SHALL be determined by the primarily by the application and the information
infrastructure it is used in. Keys SHALL be immediately revoked and replaced if it has been or
suspected of being compromised.
CY 3.
*Information assets classified as C3 [IAP-NAT-DCLS] are encrypted and protected against
unauthorized disclosure when stored and/or in transit regardless of the storing format
or media. Agencies MAY apply these cryptographic controls to assets with lower confidentiality
requirements, if determined necessary by their risk assessment.
CY 4.
Information assets classified as I3 [IAP-NAT-DCLS] have assured integrity by the use of
cryptographic hashing. Agencies MAY apply these cryptographic controls to assets with lower
integrity requirements, if determined necessary by their risk assessment. Appendix B to this section
specifies approved hashing algorithms.
CY 5.
*The following protocols or better, with approved algorithms outlined in Appendix B, are
used for securing data classified as C3 when in transit:
a. For securing web traffic: TLS (128+ bits) [RFC4346]
b. For securing file transfers: SFTP [SFTP]
c. For secure remote access: SSH v2 [RFC4253] or IPSEC [RFC 4301]
d. Only S/MIME v3 [RFC3851] or better are used for securing emails. See CY11 for associated
requirement.
CY 6.
*Passwords must always be encrypted/hashed and protected against unauthorized
disclosure when they are stored and/or in transit regardless of the storing format or
media. Privileged passwords SHALL be encrypted and stored off-site with backup files each time
the password is changed to ensure complete recovery.
CY 7.
*Where Hardware Security Modules (HSMs) are used, they are certified to at least FIPS
140-2 Level 2 [FIPS-140-2] or Common Criteria [CC3.1] EAL4.
CY 8.
Cryptographic keys are only physically moved in HSMs meeting CY5
CY 9.
Suitable key management processes are defined, as per [ISO11770-1] and used to manage the
lifecycle of cryptographic keys, covering the following functions:
• Key Custodians Roles and Responsibilities
• Key Generation
NATIONAL INFORMATION ASSURANCE MANUAL
44