<section title="12.3. Product Classifying and Labelling"><subsection title="Objective"><paragraph
    title="12.3.1."


><![CDATA[<p>IT equipment is classified and appropriately labelled.</p>]]></paragraph>
 </subsection>
<subsection title="Context"> <block title="Scope"><paragraph
    title="12.3.2."


><![CDATA[<p>This section covers information relating to the classification and labelling of both evaluated and non-evaluated IT equipment.</p>]]></paragraph>
</block>
<block title="Non-essential labels"><paragraph
    title="12.3.3."


><![CDATA[<p>Non-essential labels are labels other than classification and asset labels.</p>]]></paragraph>
</block>
</subsection>
<subsection title="Rationale &amp; Controls"> <block title="Classifying IT equipment"><paragraph
    title="12.3.4.R.01."

    tags="IT Equipment,Technical,Product Security"


><![CDATA[<p>Much of today’s technology incorporates an internal data storage capability. When media is used in IT equipment there is no guarantee that the equipment has not automatically accessed classified information from the media and stored it locally to the device, without the knowledge of the system user. As such, the IT equipment needs to be afforded the same degree of protection as that of the associated media.</p>]]></paragraph>
<paragraph
    title="12.3.4.C.01."

    tags="IT Equipment,Technical,Product Security"


    classification="All Classifications"
    compliance="Must"
    cid="3423"
><![CDATA[<p>Agencies MUST classify IT equipment based on the highest classification of information the equipment and any associated media within the equipment, are approved for processing, storing or communicating.</p>]]></paragraph>
</block>
<block title="Labelling IT equipment"><paragraph
    title="12.3.5.R.01."

    tags="IT Equipment,Technical,Product Security"


><![CDATA[<p>The purpose of applying protective markings to all assets in a secure area is to reduce the likelihood that a system user will accidentally input classified information into another system residing in the same area that is of a lower classification than the information itself.</p>]]></paragraph>
<paragraph
    title="12.3.5.R.02."

    tags="IT Equipment,Technical,Product Security"


><![CDATA[<p>Applying protective markings to assets also assists in determining the appropriate usage, sanitisation, disposal or destruction requirements of the asset based on its classification. This is of particular importance in data centres and computer rooms.</p>]]></paragraph>
<paragraph
    title="12.3.5.C.01."

    tags="IT Equipment,Technical,Product Security"


    classification="Confidential, Top Secret, Secret"
    compliance="Must"
    cid="3427"
><![CDATA[<p>Agencies MUST clearly label all IT equipment capable of storing or processing classified information, with the exception of HACE, with the appropriate protective marking.</p>]]></paragraph>
<paragraph
    title="12.3.5.C.02."

    tags="IT Equipment,Technical,Product Security"


    classification="All Classifications"
    compliance="Must"
    cid="3428"
><![CDATA[<p>Agencies MUST clearly label all IT equipment in data centres or computer rooms with an asset identification and the level of classification to which that equipment has been accredited.</p>]]></paragraph>
</block>
<block title="Labelling high assurance products"><paragraph
    title="12.3.6.R.01."

    tags="Technical,High Assurance Products,Product Security"


><![CDATA[<p>High assurance products often have tamper-evident seals placed on their external surfaces. To assist system users in noticing changes to the seals, and to prevent functionality being degraded, agencies MUST limit the use of non-essential labels.</p>]]></paragraph>
<paragraph
    title="12.3.6.C.01."

    tags="Technical,High Assurance Products,Product Security"


    classification="All Classifications"
    compliance="Must Not"
    cid="3431"
><![CDATA[<p>Agencies MUST NOT have any non-essential labels applied to external surfaces of high assurance products.</p>]]></paragraph>
</block>
<block title="Labelling HACE"><paragraph
    title="12.3.7.R.01."

    tags="Technical,High Assurance Products,Product Security"


><![CDATA[<p>HACE often have tamper-evident seals placed on their external surfaces. To assist system users in noticing changes to the seals, and to prevent functionality being degraded, agencies MUST only place seals on equipment with GCSB approval.</p>]]></paragraph>
<paragraph
    title="12.3.7.C.01."

    tags="Technical,High Assurance Products,Product Security"


    classification="All Classifications"
    compliance="Should"
    cid="3434"
><![CDATA[<p>Agencies SHOULD seek GCSB authorisation before applying labels to external surfaces of HACE.</p>]]></paragraph>
</block>
</subsection>
</section>
