to the Information Security Manager / Office and the concerned Law enforcement agencies. The loss / theft SHALL be handled as per the B-8 Incident Management[IM] OS 10. *Emergency destruction/locking plan /remote wipe/auto destruct is in place for any MDs and laptops. 12. Physical Security [PH] 12.1. Policy Objective The objective of the policy is to ensure prevention of unauthorized physical access, damage, and interference to an Agency’s premises and information. Agencies need to ensure that appropriate physical security measures and controls are adopted to meet the baseline requirements of this policy. 12.2. Policy & Baseline Controls In order to comply with this policy, Agencies MUST ensure: PH 1. Appropriate protection for physical space is determined based on an assessment of risk. This assessment SHALL occur during the design phase of a new construction or, for existing workplaces, as part of an on-going risk management process. PH 2. Physical spaces are zoned depending upon their security requirement. Each zone is designated a physical security level. The table below specifies the levels: Minimal Protection This provides a level of security designed to control assets with no classification (e.g. C0I0A0). It is generally unsuitable for (non-public) government operations. Baseline Protection This provides a level of security designed to control assets of moderate value or classified as ‘Low‘. It is generally used as the baseline for government operations. Medium Protection This provides a level of security designed to control assets of medium value or classified as ‘Medium‘. High Protection This provides a level of security designed to control assets of high value or classified as ‘High‘. PH 3. Each zone has the appropriate physical security controls implemented. Appendix A provides details of these minimal and baseline protection controls, together with recommendations for additional controls. Medium protection requires one additional class of control, whereas High protection requires two additional class of control. An Agency MAY incorporate additional controls in addition to those mandated by this policy. PH 4. Implementation of a “clean desk” and “clean screen” policy. PH 5. Server/Data rooms meet at least the medium protection requirement PH 6. *Cabling carrying information at levels C1-C3 is physically separate (including for fibre optic cabling) and is in separate ducting to that carrying Nationally Classified information PH 7. A site security plan and where necessary standard operating procedures (SOPs) for each secure areas are developed and implemented. Information to be covered includes, but is not limited to: a. a summary of the protective security risk assessment b. roles and responsibilities of facility or ICT security officer and staff members; c. the administration, operation and maintenance of the electronic access control system and/or security alarm system NATIONAL INFORMATION ASSURANCE MANUAL 46

Select target paragraph3