•  Dual Control and Split Knowledge •  Secure Key Storage •  Key Usage •  Secure Key Distribution and in Transit •  Key Backup and Recovery •  Periodic Key Status Checking •  Key Compromise •  Key Revocation and Destruction •  Audit Trails and Documentation CY 10. Agency’s SHALL ensure the digital certificates are compliant to standards in use by the CSP-PMA, MOTC. Agencies SHALL use online revocation systems to minimize the risk of fraudulent use of digital certificates. CY 11. Security token/smartcard provisioning systems of CSPs meet the requirements for Subject Device Provision Services as specified in [CWA14167-1]. CY 12. *Any digital certificates used in a production system SHALL be issued by a CSP licensed in Qatar. 11. Portable Devices & Working Off-Site Security [OS] 11.1. Policy Objective The main purpose of this policy is to specify the minimum requirements for mobile equipment (Mobile Devices (MDs) and laptops) when they are used within the vicinity of an Agency or when used in other uncontrolled environments. 11.2. Policy & Baseline Controls - General In order to comply with this policy, Agencies MUST ensure: 45 OS 1. *They develop policies governing if, and how, Mobile Devices (MDs) and laptops can be used in their organisation. OS 2. They do not conduct classified conversations using MDs and laptops capable of conducting phone conversations while using Bluetooth-enabled peripherals. OS 3. MDs and laptops with Bluetooth serial port connections do not have the port enabled if the device is to hold classified information. OS 4. MDs with recording facilities are not allowed into high risk areas without prior approval from the Security Manager. OS 5. *All laptops and MDs SHALL encrypt the information they carry and be password protected. OS 6. *MDs and laptops SHALL be kept under continual direct supervision when in use or kept secured when not in use. OS 7. *MDs and laptops not directly owned or controlled by the Agency are not used with the Agency’s systems. MDs and laptops not owned or controlled by the Agency SHALL be managed, accounted for and accredited in the same manner as agency owned devices. Agency MD’s and laptops MAY be temporary connected to a non- Agency network provided a suitable firewall is used to protect the device from any potential threats originating from the non- Agency controlled network. OS 8. Unaccredited MDs and laptops do not connect to the Agency’s systems or store Agency information. However, temporary connected MDs and laptops are permitted provided they are segregated from the main networks by a firewall. OS 9. *In case of loss or theft of the MDs or laptops, the incident should be immediately reported NATIONAL INFORMATION ASSURANCE MANUAL

Select target paragraph3