|
Requirements to work with confidential information |
|
Wednesday, 14 December 2005 |
|
At work with the information of 1-st class of confidentiality performance of following requirements is recommended:
* Notification of employees about closeness of the given information,
* General acquaintance of employees with the basic possible methods of attacks to the information
* Restriction of physical access
* Full set of the documentation by rules of performance of operations with the given information
At work with the information of 2-nd class of confidentiality to the requirements listed above the following are added:
* Calculation of risks of attacks to the information
* Maintenance of the list of the persons having access to the given information
* Whenever possible delivery of the similar information on the receipt (including electronic)
* Automatic check of system integrity and its safety
* Reliable plans of physical security
* Obligatory enciphering by transfer on communication lines
* The plan of a uninterrupted electricity supply to the computers
At work with the information of 3-rd class of confidentiality to all requirements listed above the following are added:
* The detailed plan of rescue or reliable destruction of the information in emergencies (a fire, flooding, explosion)
* Protection of the computer or data carriers against damage by water and a heat
* Cryptographic check of integrity of the information
|