<section title="13.2. Media Handling"><subsection title="Objective"><paragraph
    title="13.2.1."


><![CDATA[<p>Media is properly classified, labelled and registered in order to clearly indicate the required handling instructions and degree of protection to be applied.</p>]]></paragraph>
 </subsection>
<subsection title="Context"> <block title="Scope"><paragraph
    title="13.2.2."


><![CDATA[<p>This section covers information relating to classifying, labelling and registering media. Information relating to classifying and labelling IT equipment can be found in <a title="Product classifying and labelling" href="http://nzism.gcsb.govt.nz/ism-document#Section-14507">Section 12.3 - Product Classifying and Labelling</a>.</p>]]></paragraph>
</block>
<block title="Exceptions for labelling and registering media"><paragraph
    title="13.2.3."


><![CDATA[<p>Labels are not needed for internally mounted fixed media if the IT equipment containing the media is labelled. Likewise fixed media does not need to be registered if the IT equipment containing the media is registered.</p>]]></paragraph>
</block>
</subsection>
<subsection title="References"><paragraph
    title="13.2.4."


><![CDATA[<p>Additional information relating to media handling is contained in:</p><table class="table-main">
<tbody>
<tr>
<td><strong>Reference</strong></td>
<td><strong>Title</strong></td>
<td><strong>Publisher</strong></td>
<td><strong>Source</strong></td>
</tr>
<tr>
<td>
<p><strong><strong>ISO/IEC 27001:2013</strong></strong></p>
</td>
<td>
<p><strong>&nbsp;10.7, Media Handling</strong></p>
</td>
<td>
<p style="text-align: center;">ISO</p>
</td>
<td>
<p><a title="Information technology — Security techniques — Information security management systems — Requirements - 10.7 Media Handling" rel="noopener noreferrer" href="https://www.iso.org/standard/54534.html" target="_blank">https://www.iso.org/standard/54534.html</a></p>
<p><a rel="noopener noreferrer" href="https://www.standards.govt.nz/" target="_blank">&nbsp;</a></p>
</td>
</tr>
</tbody>
</table>]]></paragraph>
 </subsection>
<subsection title="PSR references"><paragraph
    title="13.2.5."


><![CDATA[<p class="NormS6C1">Relevant PSR requirements can be found at:</p>
<table class="table-grey" style="width: 100%; height: 241.487px;">
<tbody>
<tr style="height: 61.4306px;">
<td style="width: 18.7326%; height: 61.4306px;"><strong>Reference</strong></td>
<td style="width: 17.0703%; height: 61.4306px;"><strong>Title</strong></td>
<td style="width: 62.5998%; height: 61.4306px;"><strong>Source</strong></td>
</tr>
<tr style="height: 180.056px;">
<td style="width: 18.7326%; height: 180.056px;">
<p><strong>PSR Mandatory Requirements</strong></p>
</td>
<td style="width: 17.0703%; height: 180.056px;">GOV3, INFOSEC1, INFOSEC2, INFOSEC3, INFOSEC4, PHYSEC1 and PHYSEC2</td>
<td style="width: 62.5998%; height: 180.056px;">
<p><a title="PSR Home" rel="noopener noreferrer" href="https://www.protectivesecurity.govt.nz" target="_blank">Home | Protective Security Requirements<br></a></p>
<p><a title="Security Governance" rel="noopener noreferrer" href="https://www.protectivesecurity.govt.nz/policy/security-governance" target="_blank">Security governance (GOV) | Protective Security Requirements</a></p>
<p><a title="Information Security" rel="noopener noreferrer" href="https://www.protectivesecurity.govt.nz/policy/information-security" target="_blank">Information security (INFOSEC) | Protective Security Requirements</a></p>
<a title="Physical Security" rel="noopener noreferrer" href="https://www.protectivesecurity.govt.nz/policy/physical-security" target="_blank">Physical security (PHYSEC) | Protective Security Requirements</a></td>
</tr>
</tbody>
</table>]]></paragraph>
 </subsection>
<subsection title="Rationale &amp; Controls"> <block title="Reclassification and declassification procedures"><paragraph
    title="13.2.6.R.01."

    tags="Governance,Classifying Media,Media Handling,Media Management"


><![CDATA[<p>When reclassifying or declassifying media the process is based on an assessment of risk, including:</p><ul>
<li>the classification of the media and associated handling instructions;</li>
<li>the effectiveness of any sanitisation or destruction procedure used; </li>
<li>the planned redeployment; and</li>
<li>the intended destination of the media.</li>
</ul>]]></paragraph>
<paragraph
    title="13.2.6.C.01."

    tags="Governance,Classifying Media,Media Handling,Media Management"


    classification="All Classifications"
    compliance="Must"
    cid="3896"
><![CDATA[<p>Agencies MUST document procedures for the reclassification and declassification of media.</p>]]></paragraph>
</block>
<block title="Classifying media storing information"><paragraph
    title="13.2.7.R.01."

    tags="Governance,Classifying Media,Media Handling,Media Management"


><![CDATA[<p>Media that is not classified or not correctly classified may be stored, identified and handled inappropriately.</p>]]></paragraph>
<paragraph
    title="13.2.7.R.02."

    tags="Governance,Classifying Media,Media Handling,Media Management"


><![CDATA[<p>Incorrect or no classification may result in access by a person or persons without the appropriate security clearance.</p>]]></paragraph>
<paragraph
    title="13.2.7.C.01."

    tags="Governance,Classifying Media,Media Handling,Media Management"


    classification="All Classifications"
    compliance="Must"
    cid="3904"
><![CDATA[<p>Agencies MUST classify media to the highest classification of data stored on the media.</p>]]></paragraph>
</block>
<block title="Classifying media connected to systems of higher classifications"><paragraph
    title="13.2.8.R.01."

    tags="Governance,Classifying Media,Media Handling,Media Management"


><![CDATA[<p>Unless connected through a data diode or similar infrastructure, there is no guarantee that classified information was not copied to the media while it was connected to a system of higher classification than the classification level of the media itself.</p>]]></paragraph>
<paragraph
    title="13.2.8.C.01."

    tags="Governance,Classifying Media,Media Handling,Media Management"


    classification="All Classifications"
    compliance="Must"
    cid="3910"
><![CDATA[<p>Agencies MUST classify any media connected to a system of a higher classification at the higher system classification until confirmed not to be the case.</p>]]></paragraph>
</block>
<block title="Classifying media below that of the system"><paragraph
    title="13.2.9.R.01."

    tags="Governance,Classifying Media,Media Handling,Media Management"


><![CDATA[<p>When sufficient assurance exists that information cannot be written to media that is used with a system, then the media can be treated in accordance with the handling instructions of the classification of the information it stores rather than the classification of the system it is connected to or used with.</p>]]></paragraph>
<paragraph
    title="13.2.9.C.01."

    tags="Governance,Classifying Media,Media Handling,Media Management"


    classification="All Classifications"
    compliance="Must"
    cid="3915"
><![CDATA[<p>Agencies intending to classify media below the classification of the system to which it is connected to MUST ensure that:</p><ul>
<li>the media is read-only;</li>
<li>the media is inserted into a read-only device; or</li>
<li>the system has a mechanism through which read-only access can be assured such as approved data diodes, write-blockers or similar infrastructure.</li>
</ul>]]></paragraph>
</block>
<block title="Reclassifying media to a lower classification"><paragraph
    title="13.2.10.R.01."

    tags="Governance,Classifying Media,Media Handling,Media Management"


><![CDATA[<p>Agencies must follow the reclassification process as illustrated in Section 13.6 – Media Disposal.</p>]]></paragraph>
<paragraph
    title="13.2.10.C.01."

    tags="Governance,Classifying Media,Media Handling,Media Management"


    classification="All Classifications"
    compliance="Must"
    cid="3922"
><![CDATA[<p>Agencies wishing to reclassify media to a lower classification MUST ensure that:</p><ul>
<li>a formal decision is made to reclassify, or redeploy the media; and</li>
<li>the reclassification of all information on the media has been approved by the originator, or the media has been appropriately sanitised or destroyed.</li>
</ul>]]></paragraph>
</block>
<block title="Reclassifying media to a higher classification"><paragraph
    title="13.2.11.R.01."

    tags="Governance,Classifying Media,Media Handling,Media Management"


><![CDATA[<p>The media will always need to be protected in accordance with the classification of the information it stores. As such, if the classification of the information on the media changes, then so will the classification of the media.</p>]]></paragraph>
<paragraph
    title="13.2.11.C.01."

    tags="Governance,Classifying Media,Media Handling,Media Management"


    classification="All Classifications"
    compliance="Must"
    cid="3979"
><![CDATA[<p>Agencies MUST reclassify media if:</p><ul>
<li>information copied onto the media is of a higher classification; or</li>
<li>information contained on the media is subjected to a classification upgrade.</li>
</ul>]]></paragraph>
</block>
<block title="Labelling media"><paragraph
    title="13.2.12.R.01."

    tags="Governance,Media Handling,Media Management"


><![CDATA[<p>Labelling helps all personnel to identify the classification of media and ensure that they afford the media the correct protection measures.</p>]]></paragraph>
<paragraph
    title="13.2.12.C.01."

    tags="Governance,Media Handling,Media Management"


    classification="Top Secret, Secret, Confidential"
    compliance="Must"
    cid="3982"
><![CDATA[<p>Agencies MUST label media with a marking that indicates the maximum classification and any endorsements applicable to the information stored.</p>]]></paragraph>
<paragraph
    title="13.2.12.C.02."

    tags="Governance,Media Handling,Media Management"


    classification="Secret, Top Secret, Confidential"
    compliance="Must"
    cid="3983"
><![CDATA[<p>Agencies MUST ensure that the classification of all media is easily visually identifiable.</p>]]></paragraph>
<paragraph
    title="13.2.12.C.03."

    tags="Governance,Media Handling,Media Management"


    classification="All Classifications"
    compliance="Must"
    cid="3984"
><![CDATA[<p>When using non-textual (colour, symbol) protective markings for operational security reasons, agencies MUST document the labelling scheme and train personnel appropriately.</p>]]></paragraph>
<paragraph
    title="13.2.12.C.04."

    tags="Governance,Media Handling,Media Management"


    classification="All Classifications"
    compliance="Should"
    cid="3985"
><![CDATA[<p>Agencies SHOULD label media with a marking that indicates the maximum classification and any endorsements applicable to the information stored.</p>]]></paragraph>
</block>
<block title="Labelling sanitised media"><paragraph
    title="13.2.13.R.01."

    tags="Governance,Media Handling,Media Management,Media Sanitisation"


><![CDATA[<p>It is not possible to effectively sanitise and subsequently reclassify SECRET or TOP SECRET non-volatile media to a classification lower than SECRET. Media of other classifications may be reclassified (See Section 13.6 – Media Disposal).</p>]]></paragraph>
<paragraph
    title="13.2.13.C.01."

    tags="Governance,Media Handling,Media Management,Media Sanitisation"


    classification="Secret, Top Secret"
    compliance="Must"
    cid="3988"
><![CDATA[<p>Agencies MUST label non-volatile media that has been sanitised and reclassified for redeployment with a notice similar to:</p><p>Warning: media has been sanitised and reclassified from [classification] to [classification]. Further lowering of classification only via destruction.</p>]]></paragraph>
</block>
<block title="Registering media"><paragraph
    title="13.2.14.R.01."

    tags="Governance,Media Handling,Media Management"


><![CDATA[<p>If agencies fail to register media with an appropriate identifier they will not be able to effectively keep track of their classified media and there will be a greater likelihood of unauthorised disclosure of classified information.</p>]]></paragraph>
<paragraph
    title="13.2.14.C.01."

    tags="Governance,Media Handling,Media Management"


    classification="Top Secret, Secret, Confidential"
    compliance="Must"
    cid="3991"
><![CDATA[<p>Agencies MUST register all media with a unique identifier in an appropriate register.</p>]]></paragraph>
<paragraph
    title="13.2.14.C.02."

    tags="Governance,Media Handling,Media Management"


    classification="All Classifications"
    compliance="Should"
    cid="3992"
><![CDATA[<p>Agencies SHOULD register all media with a unique identifier in an appropriate register.</p>]]></paragraph>
</block>
</subsection>
</section>
