10.10.2014 Views

Policy 7230A - Department of Administration

Policy 7230A - Department of Administration

Policy 7230A - Department of Administration

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

4.3.2.2 Restrict Intra and Inter-System Communication by Content<br />

To ensure that information is not shared inappropriately, intra and<br />

inter-system communications must be restricted to agreed upon<br />

content only:<br />

• Define the specific communication paths and communications<br />

that will occur both intra- and inter-system.<br />

• Define the appropriate content for each communication as<br />

specifically as possible.<br />

• Monitor communications to ensure content meets established<br />

restrictions.<br />

4.3.2.3 Restrict Intra-System Communication by Authentication<br />

Before establishing communications, system components must<br />

positively identify one another to ensure that information is only<br />

being shared by intended devices:<br />

• Systems will use hierarchical device authentication based on<br />

the risk impact assignment <strong>of</strong> the system as a whole.<br />

4.4. Maintain Records<br />

Agencies should capture documentation appropriate to all access control processes:<br />

• Document and retain copies <strong>of</strong> system inter connection authorizations.<br />

11

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!