36 MAC Pt. 1, R. 16.1
System and Communications Protection
Cite as 36 Miss. Admin. Code Pt. 1, R. 16.1
System and Communications Protection
A. Each agency must monitor, control, and protect communications (i.e., information
transmitted or received by agency systems) at the external boundaries and key
internal boundaries of agency systems.
1. Use secure network management and communication protocols (e.g., 802.1X,
Wi-Fi Protected Access 2 (WPA2) Enterprise or greater).
i.
ITS recommends not using WPA2 Personal (standard wireless network
keys) as opposed to WPA2 Enterprise (username and password
wireless authentication).
2. Perform traffic filtering between network segments, where appropriate.
3. Collect and store all network traffic flow logs and/or network traffic in a
centralized server. All traffic logs must be retained for a predetermined period
defined by the agency. Logs shall be reviewed at consistent intervals, or in
response to a perceived or realized security event.
B. Each agency which develops in-house software must employ architectural designs,
software development techniques, and systems engineering principles that promote
effective information security within organizational systems.
1. Establish and maintain a secure network architecture. A secure network
architecture must address the following, at a minimum:
i.
Network segmentation: Development and production environments
should be separated logically from one another. Further, network
segmentation should exist between areas of differing data sensitivity
levels.
ii.
Least privilege: Software and systems shall be designed in a way users
are only afforded permissions to necessary functionality and
information.
iii.
Availability: Software shall be designed in a manner that does not
negatively impact the availability of other agency resources.
2. Establish and maintain a secure application development process. In the
process, address such items as: secure application design standards, secure
coding practices, developer training, vulnerability management, security of
third-party code, and application security testing procedures. Review and
update documentation annually, or when significant enterprise changes occur
that could impact this Safeguard.
C. Each agency must separate user functionality from system management functionality.
1. Agencies can implement separation of system management functionality from
user functionality by using:
i.
Different computers, different instances of operating systems, or
different network addresses, virtualization techniques, or combinations
of these or other methods, as appropriate.
ii.
This type of separation includes, for example, web administrative
interfaces that use separate authentication methods for users of any
other system resources.
iii.
Separation of system and user functionality may include isolating
administrative interfaces on different domains and with additional
access controls.
2. Establish and maintain dedicated computing resources, either physically or
logically separated, for all administrative tasks or tasks requiring
administrative access. The computing resources should be segmented from the
agency's primary network and not be allowed internet access.
D. Each agency must prevent unauthorized and unintended information transfer via
shared system resources. It is recommended that only Common Criteria (CC)
approved systems (such as Windows, Apple, Linux) are used. The CC evaluated
systems have been certified to protect against misuse of shared resources.
E. Each agency must implement DMZ subnetworks for publicly accessible system
components that are physically or logically separated from internal networks.
F. Each agency must deny network inbound communications traffic by default and
allow network communications traffic by exception (i.e., deny all, permit by
exception).
1. Use technical controls, such as application allowlisting, to ensure that only
authorized software can execute or be accessed. The agency should reassess
this bi-annually, or more frequently.
2. ITS recommends deploying port-level access control. Port-level access control
utilizes 802.1x, or similar network access control protocols, such as
certificates, and may incorporate user and/or device authentication.
G. Each agency must prevent remote devices from simultaneously establishing non-
remote connections with organizational systems and communicating via some other
connection to resources in external networks (i.e., split tunneling).
H. Each agency must implement cryptographic mechanisms to prevent unauthorized
disclosure of sensitive information during transmission unless otherwise protected by
alternative physical safeguards.
1. Encrypt sensitive data in transit. Example implementations can include
Transport Layer Security (TLS) and Open Secure Shell (OpenSSH).
I. Each agency must terminate network connections associated with communications
sessions at the end of the sessions or after a defined period of inactivity. For example,
this includes inactivity timeouts on management sessions to network devices and
servers in addition to inactivity timeouts on user network sessions such as
VPN connections and other network sessions.
J. Each agency must establish and manage cryptographic keys for cryptography
employed in organizational systems. For example, agencies should determine what
cryptographic keys (TLS certificates, VPN keys, etc.) are in use. Document how these
keys are managed and protected.
K. Each agency must employ federal information processing standards (FIPS)-validated
cryptography when used to protect the confidentiality of sensitive information.
L. Each agency must prohibit remote activation of collaborative computing devices such
as microphones, webcams, and screensharing applications. Users must be prompted
with an indication that these devices are โin useโ after activation.
M. Each agency must control and monitor the use of mobile code.
1. Mobile code includes software programs or part of a program obtained from
remote systems, transmitted across a network, and executed on a local system
without explicit installation or execution by the recipient. Mobile code
technologies include, but are not limited to Java, JavaScript, ActiveX,
Postscript, PDF, VBScript.
N. Each agency must control and monitor the use of Voice over Internet Protocol (VoIP)
technologies. This includes delegation of access to administrative and end users,
monitoring traffic flows, and review of any logging and alerts.
O. Each agency must protect the authenticity of communications sessions. This requires
authentication and encryption of traffic using FIPS-approved algorithms.
P. Each agency must protect the confidentiality of sensitive data at rest.
1. Encrypt sensitive data at rest on servers, applications, and databases
containing sensitive data. Storage-layer encryption, also known as server-side
encryption, meets the minimum requirement of this Safeguard. Additional
encryption methods may include application-layer encryption, also known as
client-side encryption, where access to the data storage device(s) does not
permit access to the plain-text data.