National Information Security Policy and Guidelines | Ministry of Home Affairs 12.2.6. The new components and architectural elements incorporated as a part of the plan for infrastructure transition may introduce serious security issues. Adoption of trends such as mobility and usage of personally owned devices exposes the network to a new set of threats 12.3. Network and infrastructure security management guidelines 12.3.1. Inventory of assets and infrastructure: The organization should ensure that a network diagram illustrating all network devices and other significant devices is available. Since this contains classified information, such documentation should be appropriately protected and its distribution should be limited. The organization must maintain and update a map/inventory of authorized devices such as: G1 a. Infrastructure components spread across the organization and connected to the network endpoints, server systems, applications, databases and data files, and messaging systems b. Connectivity and access to users, endpoints, devices, server systems, applications, databases and messaging systems should be recorded and maintained c. The spread of the organizational assets across the operational functions and geographies and their access requirements should also be recorded 12.3.2. Security testing of network & infrastructure devices: All infrastructure and network hardware may be procured, from manufacturers or resellers who are authorized by manufacturers, with reasonable demonstration of compliance with global security best practices G2 12.3.3. Network perimeter security: The government organization must secure the network perimeter by deploying competent security solutions G3 12.3.4. Network zones: The organization must divide their networks into multiple functional zones according to the sensitivity or criticality of information or services in that zone. Wherever possible, physical isolation must be performed G4 a. Access from external environment: Sensitive IT assets must not be directly accessible from the external environment b. Network segmentation technologies: The organization must ensure that appropriate network segmentation technologies are enforced to logically and physically isolate the network and protect classified information and critical services (such as user authentication and user directory information) c. Operating zones for users: Environment that allow internal users access to information assets and systems should be separated from the environment created for external users 12.3.5. LAN security: The organization must develop, document and periodically update security policies and procedures related to Local Area Networks (LAN) G5 a. The organization must evaluate risks associated with transmission of NISPG - Version 5.0 Restricted Page 35

Select target paragraph3