General classified information security measures
Creating a registration system
Your agency must have a system for controlling and handling government and protectively-marked information.
For each document or file, your registration system needs to detail:
- when it was created
- where it is stored
- when it will be destroyed.
To register media, follow the requirements in the New Zealand Information Security Manual (NZISM) – 13.2.14 Registering Media(external link).
Maintaining a Classified Document Register
You must maintain a Classified Document Register (CDR) for all TOP SECRET and ACCOUNTABLE MATERIAL produced or received within your agency.
The CDR should include details of the documents received and all retained copies.
It’s good practice to maintain a register for SECRET information. You can also use CDRs for documents with lower classifications when necessary for risk mitigation.
With due care, your CDR should rarely need to be protectively marked. When it is necessary, mark your CDR on its own merits — not according to the protective markings of the documents it records (unless the title of a document in your CDR is protectively marked, which should be rare).
If the volume of correspondence justifies it, use separate registers for each security classification and inwards and outwards correspondence.
Auditing hardcopies
Your agency must develop a system for auditing hardcopy information that has protective markings. Audit requirements for ICT systems and equipment are defined in the NZISM.
Using a receipt process to increase security
Consider having a receipt process for when protectively-marked information or equipment is delivered to your agency. The benefits include being able to:
- provide confirmation that information has been delivered
- trace the movement of protected information
- ensure the recipient takes responsibility for protecting the information.
Any type of receipt mechanism is suitable, as long as it identifies the document either by reference number or title.
A reference number is often easier than a title, as the title of a document may describe the content of a protectively-marked document or, in limited cases, contain a word such as ‘secret’ or ‘confidential’.
Specify a period on the receipt (for example, 7 days) in which the recipient must sign and returned the receipt.
Confirm you’ve received all expected receipt returns within a month of their due date.
Spot-checking information marked ‘Top secret’ and ‘accountable material’
At irregular intervals, conduct or arrange a spot check of a small sample of TOP SECRET and ACCOUNTABLE MATERIAL to ensure it’s accounted for, and being handled and stored correctly. The manager responsible for the information should take charge of conducting or arranging spot checks.
Your agency should also conduct spot checks on 5 percent of TOP SECRET and ACCOUNTABLE MATERIAL per month.
All (100 percent) of your TOP SECRET and ACCOUNTABLE MATERIAL files must be checked within every two-year period.
Recording spot checks
- Maintain a record of your spot checks. It is good practice to conduct a similar spot check of other protectively-marked files at irregular intervals.
Reporting discrepancies
- The manager should report any discrepancies to the Chief Security Officer (CSO), Chief Information Security Officer (CISO), or other appropriate authority for investigation. Examples of other authorities that might be appropriate are the Privacy Commissioner, Ombudsman, National Cyber Security Centre (NCSC), or Cert NZ.
Go to the Management protocol for information security for more about managing information security incidents.