<section title="8.5. Tamper Evident Seals"><subsection title="Objective"><paragraph
    title="8.5.1."


><![CDATA[<p>Tamper evident seals and associated auditing processes identify attempts to bypass the physical security of systems and their infrastructure.</p>]]></paragraph>
 </subsection>
<subsection title="Context"> <block title="Scope"><paragraph
    title="8.5.2."


><![CDATA[<p>This section covers information on tamper evident seals that can be applied to assets.</p>]]></paragraph>
</block>
</subsection>
<subsection title="Rationale &amp; Controls"> <block title="Recording seal usage"><paragraph
    title="8.5.3.R.01."

    tags="Governance,Physical Security"


><![CDATA[<p>Recording information about seals in a register and on which asset they are used assists in reducing the security risk that seals could be substituted without security personnel being aware of the change.</p>]]></paragraph>
<paragraph
    title="8.5.3.C.01."

    tags="Governance,Physical Security"


    classification="Top Secret"
    compliance="Must"
    cid="1425"
><![CDATA[<p>Agencies MUST record the usage of seals in a register that is appropriately secured.</p>]]></paragraph>
<paragraph
    title="8.5.3.C.02."

    tags="Governance,Physical Security"


    classification="Top Secret"
    compliance="Must"
    cid="1426"
><![CDATA[<p>Agencies MUST record in a register, information on:</p><ul>
<li>issue and usage details of seals and associated tools;</li>
<li>serial numbers of all seals purchased; and</li>
<li>the location or asset on which each seal is used.</li>
</ul>]]></paragraph>
<paragraph
    title="8.5.3.C.03."

    tags="Governance,Physical Security"


    classification="All Classifications"
    compliance="Should"
    cid="1427"
><![CDATA[<p>Agencies SHOULD record the usage of seals in a register that is appropriately secured.</p>]]></paragraph>
<paragraph
    title="8.5.3.C.04."

    tags="Governance,Physical Security"


    classification="All Classifications"
    compliance="Should"
    cid="1428"
><![CDATA[<p>Agencies SHOULD record in a register information on:</p><ul>
<li>issue and usage details of seals and associated tools;</li>
<li>serial numbers of all seals purchased; and</li>
<li>the location or asset on which each seal is used.</li>
</ul>]]></paragraph>
</block>
<block title="Purchasing seals"><paragraph
    title="8.5.4.R.01."

    tags="Governance,Physical Security"


><![CDATA[<p>Using uniquely numbered seals ensures that a seal can be uniquely mapped to an asset. This assists security personnel in reducing the security risk that seals could be replaced without anyone being aware of the change.</p>]]></paragraph>
<paragraph
    title="8.5.4.C.01."

    tags="Governance,Physical Security"


    classification="All Classifications"
    compliance="Should"
    cid="1431"
><![CDATA[<p>Agencies SHOULD consult with the seal manufacturer to ensure that, if available, any purchased seals and sealing tools display a unique identifier or image appropriate to the agency.</p>]]></paragraph>
<paragraph
    title="8.5.4.C.02."

    tags="Governance,Physical Security"


    classification="All Classifications"
    compliance="Should"
    cid="1432"
><![CDATA[<p>Seals and any seal application tools SHOULD be secured when not in use.</p>]]></paragraph>
<paragraph
    title="8.5.4.C.03."

    tags="Governance,Physical Security"


    classification="All Classifications"
    compliance="Should Not"
    cid="1433"
><![CDATA[<p>Agencies SHOULD NOT allow contractors to independently purchase seals and associated tools on behalf of the government.</p>]]></paragraph>
</block>
<block title="Reviewing seal usage"><paragraph
    title="8.5.5.R.01."

    tags="Governance,Physical Security"


><![CDATA[<p>Users of assets with seals should be encouraged to randomly check the integrity of the seals and to report any concerns to security personnel. In addition, conducting at least annual reviews will allow for detection of any tampering to an asset and ensure that the correct seal is located on the correct asset.</p>]]></paragraph>
<paragraph
    title="8.5.5.C.01."

    tags="Governance,Physical Security"


    classification="All Classifications"
    compliance="Should"
    cid="1436"
><![CDATA[<p>Agencies SHOULD review seals for differences with a register at least annually. At the same time seals SHOULD be examined for any evidence of tampering.</p>]]></paragraph>
</block>
</subsection>
</section>
