36 MAC Pt. 1, R. 16.1

System and Communications Protection

Year: 2026Length: 969 wordsOfficial source

Cite as 36 Miss. Admin. Code Pt. 1, R. 16.1

System and Communications Protection A. Each agency must monitor, control, and protect communications (i.e., information transmitted or received by agency systems) at the external boundaries and key internal boundaries of agency systems. 1. Use secure network management and communication protocols (e.g., 802.1X, Wi-Fi Protected Access 2 (WPA2) Enterprise or greater). i. ITS recommends not using WPA2 Personal (standard wireless network keys) as opposed to WPA2 Enterprise (username and password wireless authentication). 2. Perform traffic filtering between network segments, where appropriate. 3. Collect and store all network traffic flow logs and/or network traffic in a centralized server. All traffic logs must be retained for a predetermined period defined by the agency. Logs shall be reviewed at consistent intervals, or in response to a perceived or realized security event. B. Each agency which develops in-house software must employ architectural designs, software development techniques, and systems engineering principles that promote effective information security within organizational systems. 1. Establish and maintain a secure network architecture. A secure network architecture must address the following, at a minimum: i. Network segmentation: Development and production environments should be separated logically from one another. Further, network segmentation should exist between areas of differing data sensitivity levels. ii. Least privilege: Software and systems shall be designed in a way users are only afforded permissions to necessary functionality and information. iii. Availability: Software shall be designed in a manner that does not negatively impact the availability of other agency resources. 2. Establish and maintain a secure application development process. In the process, address such items as: secure application design standards, secure coding practices, developer training, vulnerability management, security of third-party code, and application security testing procedures. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard. C. Each agency must separate user functionality from system management functionality. 1. Agencies can implement separation of system management functionality from user functionality by using: i. Different computers, different instances of operating systems, or different network addresses, virtualization techniques, or combinations of these or other methods, as appropriate. ii. This type of separation includes, for example, web administrative interfaces that use separate authentication methods for users of any other system resources. iii. Separation of system and user functionality may include isolating administrative interfaces on different domains and with additional access controls. 2. Establish and maintain dedicated computing resources, either physically or logically separated, for all administrative tasks or tasks requiring administrative access. The computing resources should be segmented from the agency's primary network and not be allowed internet access. D. Each agency must prevent unauthorized and unintended information transfer via shared system resources. It is recommended that only Common Criteria (CC) approved systems (such as Windows, Apple, Linux) are used. The CC evaluated systems have been certified to protect against misuse of shared resources. E. Each agency must implement DMZ subnetworks for publicly accessible system components that are physically or logically separated from internal networks. F. Each agency must deny network inbound communications traffic by default and allow network communications traffic by exception (i.e., deny all, permit by exception). 1. Use technical controls, such as application allowlisting, to ensure that only authorized software can execute or be accessed. The agency should reassess this bi-annually, or more frequently. 2. ITS recommends deploying port-level access control. Port-level access control utilizes 802.1x, or similar network access control protocols, such as certificates, and may incorporate user and/or device authentication. G. Each agency must prevent remote devices from simultaneously establishing non- remote connections with organizational systems and communicating via some other connection to resources in external networks (i.e., split tunneling). H. Each agency must implement cryptographic mechanisms to prevent unauthorized disclosure of sensitive information during transmission unless otherwise protected by alternative physical safeguards. 1. Encrypt sensitive data in transit. Example implementations can include Transport Layer Security (TLS) and Open Secure Shell (OpenSSH). I. Each agency must terminate network connections associated with communications sessions at the end of the sessions or after a defined period of inactivity. For example, this includes inactivity timeouts on management sessions to network devices and servers in addition to inactivity timeouts on user network sessions such as VPN connections and other network sessions. J. Each agency must establish and manage cryptographic keys for cryptography employed in organizational systems. For example, agencies should determine what cryptographic keys (TLS certificates, VPN keys, etc.) are in use. Document how these keys are managed and protected. K. Each agency must employ federal information processing standards (FIPS)-validated cryptography when used to protect the confidentiality of sensitive information. L. Each agency must prohibit remote activation of collaborative computing devices such as microphones, webcams, and screensharing applications. Users must be prompted with an indication that these devices are โ€œin useโ€ after activation. M. Each agency must control and monitor the use of mobile code. 1. Mobile code includes software programs or part of a program obtained from remote systems, transmitted across a network, and executed on a local system without explicit installation or execution by the recipient. Mobile code technologies include, but are not limited to Java, JavaScript, ActiveX, Postscript, PDF, VBScript. N. Each agency must control and monitor the use of Voice over Internet Protocol (VoIP) technologies. This includes delegation of access to administrative and end users, monitoring traffic flows, and review of any logging and alerts. O. Each agency must protect the authenticity of communications sessions. This requires authentication and encryption of traffic using FIPS-approved algorithms. P. Each agency must protect the confidentiality of sensitive data at rest. 1. Encrypt sensitive data at rest on servers, applications, and databases containing sensitive data. Storage-layer encryption, also known as server-side encryption, meets the minimum requirement of this Safeguard. Additional encryption methods may include application-layer encryption, also known as client-side encryption, where access to the data storage device(s) does not permit access to the plain-text data.
36 MAC Pt. 1, R. 16.1: System and Communications Protection | Justis AI