ML20045B705

From kanterella
Jump to navigation Jump to search
Security Policy for Processing and Handling of Sensitive Unclassified Information in the Autos/Local Area Network Environment.A Local Area Network Security Guide
ML20045B705
Person / Time
Issue date: 06/18/1993
From:
NRC OFFICE OF INFORMATION RESOURCES MANAGEMENT (IRM)
To:
References
NUREG-BR-0168, NUREG-BR-168, NUDOCS 9306180321
Download: ML20045B705 (2)


Text

.

i 4

)

NUREG'BR-0168 A LOCAL AREA NETWORK SECURITY GUIDE Security Policy For Processing and Handling Of Sensitive Unclassiffied Information in the AUTOS / Local Area Network Environment U.S. Nuclear Regulatory Commrsson O'fce of Informaton Resources Management Division of Information Suppon Servas

\\

,+$9:

3:-

g e

+

L s'@

de{

~

BR-0168 R PDR' aw

__ m _ _

WN W !WH WNW% WN MN N ikMhWfk W h WI; MM iW-M IWY.W.-.~- M' WM MJ W a

s

-- w -

Securit, Polig IJor Pro (essing and liandling computer resiarts and automatically (3egins the netwuik file contammg the document and then return to the Of Sensitne Untlanified Informatinn in 't he AtHt)S/

logon process this can be corrected by IRM so that you mam Mail Screen Neser read the document while Imal Area Network Ensironment can hieldnectly to DOS Alternatively,IllM can supply connected to the I AN. Using the Save feature (see

.t his is to bring to your attention the need for administratne a switch to temporarily disomnect tbc computer from Wordperfect Ofhce Iteference, Mail. Inikix/Outikts controN and the use of techmcal measures to provide for the the I AN when necessary.

Options - SAVE), sase the hic to your kical hard drive or if the file contams SGI,save the file to remov-confidentiahty, mtegnty. and avadahoity of sensitive unclassi-When ;micessing.SGI, save the SGI file of ten and only to able n.aha(diskette or llernoulli bm) Enter the full fied mformation when processed in the Agency Upgrade of remosable media (diskette or llernoulh box) never to a pathname for the file where you want the item saved Technology for Othee Systems / local Area Netwu L(AIJIOS/

fixed disk. Change the kication of the Word!'erfect (WP)

(e g, InSGt MSG). Once the document has been LAN)cnuronment Sensitne informanon is defmed by Public backup file with the Iveation of liles feature < Shift-saved. deconnect from the IAN and retneve the 12w it4 235 as any information, the loss, nususe, or unauthor-I'l,6 > from the ftxed disk to the directory of the remob document using WP to insure that the passwurd pro-ired aarss to whnh would or could adverwly aficct the agency able media that you are usmg to proecss and store the tecoon is still intact. If you are prompted to enter a (NitC)m usion or operation but w hich does not meet dassihca-SGI data.

passwurd to access the document, then the passwurd tion entena protection is in plaec. If you are not prompted for a

.." I'# "# "' "

" # ",, "8 U

passwurd to access the document, the document can At the NitC we have groups processing various types of sensi-

  • CD P DB C" C

tive data as dermed in NRC Manual Chapter 2161 Part l(new be pauwurd protected using the WP passwerd pro-Management Directive Volume 12 Secunty, Glossary) There

) h'n n

t he mad hem as smn as ym 1

- are groups proecssing undassified safeguards mformation (SGI) where confidennahty is the primary concern, groups Utihre WP header / footer feature to mark all printed a

procesung msestigative, enforcement, predcasional or legal pages automatically with such markmgs as "Of fical Use Avoid wntmg passwurds anywhere.I.ry to commit actions u here integrity of data is the pnmary concern, with con-Only" or ' Safeguards Information "

them to memory. When you apply a WP passwurd to fidentulhy a ckwe second, and other staff processing perform.

a document, it cannot be retrieved without the pass-ance appraisals, personnel, fmancial or contractual data where Do not leave a docu ment containing 501 or other sensi.

wmd. If you forget the password, there is no way the

  • confulentuhty,integnty, and availabshty are allimportant tive unclassified information unattended at a printer.

document can be retneved The following paredures arc directly apphcahic to the han-If a document is passwurd protected. only retneve it onto Employees have a resfunsibihty to assess the sensitivity dhng and processing of all categones of sensitive unclassified a clear screen in order to preserve the WP kicking fea-of their data and to ensure its security. Ultimately,com-mformanon (i e, Official Use Only, Piopnetary, and SGI) In ture. Never append the password protected document to puter security is the user's responsibility. You, the uscr.

addition, ask your I AN admimstrator about designated private anotherdocument, this negates the WP passwurd for the must be alert to possible breaches m secunty, and adhere duectones NOVEll. NetWare " User Groups," or other file document to the secunty regulations that have been established protect on features that can be used for the processing and stor-within the NitC.

age of senutne data e

When transmittmg a document that contams sensitive data or SGI, that is, to send a document to another user As IAN technology advances, there may be other secu+

e llecause access to a ne tworked personalcomputer is pos-en your IAN via WP Office Mail feature, send only nty features designed for operatmg systems and applica-sible even w hen the user is not currently logged on to the those documents that are password protected. Choose tion software that will be easier to use. Staff will be evalu-network, it is neceuary to disconnect the computer encryption and security (label), priority deliscry, and ating new products and wWl adnse employees when new whenever senutive unclassiDed information is proc-auto-delete options You may commumcate the doeu-features are available.

essed I his can be accomplnhed by restartingihe system ment passwurd to the recipient by phone since the file

< Utrl/ Alt / Del > and dioosmg any opoun other than will be in the mail bm for a short ume-The NRC has a designated computer security staff to pro-

"lucal Area Netwurk" from the main menu. If your vide advice and guidance. If you have a quest on about the Upon receipt of a Mail Message containing sensitne e

contents of this publication or any other computer secu-data, read the message to determine the name of the nty issue, please contact the Office of Information lle-sources Management, Dwision of Information Support ~ '

Semees (DISS)

Unauthorized reprodtictitm of copyrighted software is against flie LAW

-t-e g4-e Aw+'e' t* * ' -

w te +vw-1--

'en Lt.-v--+-

hew w

D-~'-T9 W""-'

W*--V'

+ + - ' -

w + -, + ---- --

s v

- - - ---M e--

-r

+ - + -.

'+-s-w t-w e

=>

sm-s

-e

+

--++1-1y&-1-a N-4't--

r we-e--s" s