d. key management, the enrolment and removal of system users and issuing of personal identification e. staff member clearances, security awareness training and regular briefings f. inspection of the generated audit trails and logs g. end of day checks and lockup h. reporting of ICT security incidents and breaches. 13. Virtualization [VL] 13.1. Policy Objective The objective of this policy is to provide controls to secure the virualized IT infrastructureat the agency. Agencies need to ensure that such virtualized environments are adequately secured. For virtual environment hosted outside by 3rd parties , agencies should also refer to Cloud Security Policy (proposed). 13.2. Policy & Baseline Controls In order to comply with this policy, Agencies MUST ensure: VL 1. *Evaluate the risks associated with the virtual technologies. a. Evaluate the risks in context of relevant legal, regulatory policies and legislations. b. Evaluate how the introduction of virtual technology will change your existing IT infrastructure and the related risk posture. VL2 *Harden the hypervisor, administrative layer, the virtual machine and related components as per the industry accepted best practices and security guidelines and the vendor recommendations. VL3 Enforce least privilege and separation of duties [Refer to section C-9 Access Management] for managing the virtual environment. a. Define specific roles and granular privileges for each administrator in the central virtualization management software. b. Limit direct administrative access to the hypervisor to the extent possible c. Depending on the risk and the classification of the information processed, Agencies should consider the use of multi factor authentication or dual or split control of administrative passwords between multiple administrators. VL4 *Ensure adequate physical security to prevent unauthorized access to the virtual technology environment. VL5 Virtualized technology environment should be augmented by third party security technology to provide layered security controls (defence in depth approach) to complement the controls provided by the vendor and technology itself. VL6 Segregate the Virtual Machines based on the classification of data they process and / or store. VL7 *A change management [Refer to Section B-6 Change Management] process encompasses the virtual technology environment. a. Ensure that virtual machine profile is updated and the integrity of the Virtual Machine image is maintained at all times. b. Care should be taken to maintain and update VM’s which are not in active state (dormant or no longer used). VL8 47 *Logs from the virtual technology environment SHALL be logged and monitored along with other IT infrastructure. [Refer to Section B-10 Logging and Security Monitoring]. NATIONAL INFORMATION ASSURANCE MANUAL

Select target paragraph3