Sample Information Handling Standard:

From HORSE - Holistic Operational Readiness Security Evaluation.
Jump to navigation Jump to search

Sample Information Handling Standard

This Information Handling Standard builds on the objectives established in the Asset Protection Standard, and provides specific instructions and requirements for handling information assets. These instructions address handling requirements for printed, electronically stored, and electronically transmitted information.

Objectives

A. Printed Information


1. All printed information shall be handled based on its confidentiality classification. A description of handling requirements for each confidentiality classification category is provided in the following table:


RestrictedConfidentialInternal Use OnlyPublic
Labeling
Intra-Company or Office Mail
Duplication
Mailing of Documents
Disposal
Storage


B. Electronically Stored Information


1. All electronically stored information shall be handled based on its confidentiality classification. A description of handling requirements for each confidentiality classification category is provided in the following table:


RestrictedConfidentialInternal Use OnlyPublic
Labeling (application or screen)
Labeling (electronic media)
Stored on fixed media with access controls
Stored on fixed media without access controls
Storage on removable media
Disposal of electronic media
Disposal of information


C. Electronically Transmitted Information


1. All electronically transmitted information shall be handled based on its confidentiality classification. A description of handling requirements for each confidentiality classification category is provided in the following table:


RestrictedConfidentialInternal Use OnlyPublic
Local Area Network
Wide Area Network
Non-Secure/Public Networks
Electronic Mail
Fax
Voice-Mail


Document Examples

Use these samples as a guide for your policy development. Fully customizable versions are available from The Policy Machine.