National Information Assurance and Cyber Security Strategy (NIACSS)
4.8.
2012
Securing National Information Systems and Networks
Securing national systems should not only prevent security breaches, but
also detect and respond to possible attacks. Employing Defense-in-Depth
multiple layers of protection methods
is critical to securing government
systems and networks. Defense-inEmploy Defense-in-Depth to
Depth is not limited to technical
protect national information
security methods and procedures.
systems
Defense-in-Depth should also be
resilient to accommodate rapid
change in the cyber environment. It
also includes a close examination of
personnel security, network setup and configuration, and operational
procedures. Security vulnerabilities across personnel, technology, and
operations must be considered throughout the system's life cycle.
It is through the combination of people, technology and operations which
provides the greatest cyber security posture. Tactics, techniques, and
procedures must be developed in the following areas to ensure success:
4.8.1. Personnel Security
Government organizations and private sector must issue security clearances
to users, system administrators, and any other parties using or accessing
information systems. Security clearance validation and renewal requires
appropriate management, background checks, and commitment of resources.
Also, cleared personnel require a “need-to-know” and integration in physical
security systems to ensure control and monitoring of man and machine in the
government information systems. Private sector will manage personnel
security issues under its control. Private sector still needs to cooperate with
the authorized government organization(s) to fulfill personnel security
requirements outside its authority.
Page 14 of 20