National Information Security Policy and Guidelines | Ministry of Home Affairs
classified information over LAN on a periodic basis
b. The organization must clearly define roles and responsibility of personnel
for supporting planning and implementing of LAN security, through
appropriate job functions
c. The organization must ensure that appropriate security measures, tools
and methodologies are implemented to protect transmission of classified
information over LAN. Traffic over LAN should be protected with use of
appropriate encryption methodologies
12.3.6.
Wireless architecture: The organization must ensure that Wireless LAN (WLAN)
planning and implementation incorporates security best practices
G6
a. Confidentiality and integrity: The organization must implement
appropriate encryption for transmission of classified information over
WLAN
b. Administration of access points: The access to WLAN key distribution
program should be controlled and limited to the administrators only
c. Logging of device activities and audit trails: Network traffic and access to
the WLAN should be logged by using suitable methodologies
12.3.7.
Network security management: Network security management processes
should be created and documented. These processes should define the
governing procedures for any security mechanism, changes or modification to
the network configuration, the approval matrix, backup mechanisms,
guidelines for testing and failover switching amongst others. The organization
should ensure that all network security management tasks are approved and
performed under the aegis of a single authority or team
G7
12.3.8.
Unauthorized device connection: Organizations should implement stringent
measures to minimize the risk of unauthorized devices from accessing the
network. The necessary countermeasures must be deployed to deter the
attempts of unauthorized access
G8
12.3.9.
Extending connectivity to third parties: The government organizations must
integrate the infrastructure security with other security solutions such as
identity & access management, security monitoring & incident management
for integrated defense and response against the threats
G9
NISPG - Version 5.0
Restricted
Page 36