The asset owner shall have policies and procedures around restricting the capability of userto-user messages transferred on IACS networks from containing payloads, such as attachments, network links or scripts, that can be used to support attacks against the IACS.