f) controls and restrictions associated with using communication facilities, e.g.
automatic forwarding of electronic mail to external mail addresses;
g) advising personnel to take appropriate precautions not to reveal confidential
information.
In addition, personnel should be reminded that they should not have confidential conversations
in public places or over insecure communication channels, open offices and meeting places.
Information transfer services should comply with any relevant legal requirements. Information
transfer may occur through the use of a number of different types of communication facilities,
including electronic mail, voice, facsimile and video.
Software transfer may occur through a number of different mediums, including downloading
from the Internet and acquisition from vendors selling off-the-shelf products.
The business, legal and security implications associated with electronic data interchange,
electronic commerce and electronic communications and the requirements for controls should
be considered. (NL ISO/IEC, 2015)
6.1. Agreements on Information Transfer
Agreements should address the secure transfer of business information between
the organization and external parties.
Information transfer agreements should incorporate the following:
a) management responsibilities for controlling and notifying transmission, dispatch and
receipt;
b) procedures to ensure traceability and non-repudiation;
c) minimum technical standards for packaging and transmission;
d) courier identification standards;
e) responsibilities and liabilities in the event of information security incidents, such as
loss of data;
f) use of an agreed labelling system for sensitive or critical information, ensuring that
the meaning of the labels is immediately understood and that the information is
appropriately protected;
g) technical standards for recording and reading information and software;
h) any special controls that are required to protect sensitive items, such as
cryptography;
i) maintaining a chain of custody for information while in transit;
j) acceptable levels of access control.
Lebanese National Security Policy Guidelines v1.7
Page
30 |