10.10.2014 Views

Policy 7230A - Department of Administration

Policy 7230A - Department of Administration

Policy 7230A - Department of Administration

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

5.2.1.b Mandatory Infrastructure Component Configurations<br />

• Firewalls shall be configured to block by default and allow by<br />

exception in regards to both inbound and outbound traffic.<br />

• Enterprise anti-malware will be automatically updated on a<br />

daily basis or as frequently as is possible based on the<br />

distribution <strong>of</strong> patch and definition files from the antimalware<br />

provider.<br />

• Endpoint anti-malware will be automatically updated on a<br />

daily basis, or as frequently as is possible based on the<br />

distribution <strong>of</strong> patch and definition files from the antimalware<br />

provider.<br />

• IDS or IDP systems will be configured to monitor all inbound<br />

and outbound traffic, scanning for anomalous traffic<br />

signatures and anomalous traffic patterns. These systems will<br />

be configured to issue alerts must inappropriate traffic be<br />

detecteds.<br />

5.3. Data/Media Protection<br />

The following are the Mandatory Baselines that support the Data/Media Protection<br />

section <strong>of</strong> the Default Security Requirements:<br />

5.3.1. Securely Handle Data and Media<br />

Protect data while it is in system, both in storage and use, as well as out <strong>of</strong><br />

system in media, in both storage and transit:<br />

5.3.1.a Transmission Configuration<br />

• Where possible, encrypted tunnels must be used for all<br />

electronic PII data transmissions.<br />

• Where encrypted tunnels cannot be used for electronic PII<br />

data transmissions, PII data must be directly encrypted prior<br />

to transmission.<br />

5.3.1.b Data Disposal Methods<br />

• Use s<strong>of</strong>tware or hardware delete functions to remove data<br />

from digital media that has stored non-confidential or non-PII.<br />

• Use dedicated media wiping solutions to permanently remove<br />

data from digital media that has stored confidential or PII.<br />

Mandatory Baselines<br />

Page 10 <strong>of</strong> 25

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!