1.12.20.18 NMAC

Section 18. Network Segregation

Last amended: 2010Year: 2010Length: 262 wordsOfficial source
When an agency desires to connect its network to any other third party network or its network becomes a segment on a larger network, controls shall be in place to prevent access by users from other connected networks to sensitive areas of the agencyโ€™s private network. Such connection must first be approved by the agency CIO. Firewalls or other agency approved technologies shall be implemented to control access to secured resources on the trusted agency network. If any such third party network connections are contemplated, the agency CIO must first approve and receive approval from the state CIO. [1.12.20.18 NMAC - N/E, 04/14/2010] 1.12.20.19 WIRELESS NETWORKS, BLUETOOTH, AND RADIO FREQUENCY IDENTIFICATION: A. No wireless network or wireless access point shall be installed prior to an agency performed risk assessment and the written approval of the agency CIO. B. Suitable controls, such as media access control (MAC), address restriction, authentication, and encryption, shall be implemented by the agency to ensure that a wireless network or access point cannot be exploited to disrupt agency information services or to gain unauthorized access to agency information. When selecting wireless technologies, such as 802.11x or its predecessors or its successor, wireless network security features on the equipment shall be available and implemented at the time of deployment. C. Access to systems that hold sensitive information or the transmission of protected or sensitive information via a wireless network is not permitted unless and until appropriate and adequate measures have been implemented and approved by the state CIO. Such measures shall include authentication, authorization, encryption, access controls, and logging.
1.12.20.18 NMAC: Section 18. Network Segregation | Justis AI