National Information Security Policy and Guidelines | Ministry of Home Affairs 12.4. Network and infrastructure security controls 12.4.1. Identification & classification: The organization must ensure that all infrastructure devices are grouped and classified in accordance to the criticality of the information that they contain/ process C1 12.4.2. Network diagram: The organization must ensure that the network diagram is updated as changes are made to the network. The date of last modification should be clearly stated C2 12.4.3. Network configuration: The organization should regularly review their network configuration to ensure that it conforms to the documented network configuration C3 12.4.4. Testing and certification of network & infrastructure device: Network and Infrastructure devices should be tested basis globally accepted security standards, in appropriate test labs prior to their purchase. A secure and stable configuration of the device and product may only be procured for deployment C4 12.4.5. Network security measures: The organization must ensure the competent security countermeasures for network security are established, such as: C5 a. Perimeter defense b. Traffic inspection and detection of anomalies and threats c. Detection and prevention of intrusion d. Filter, block and prevent the malicious traffic e. Restrict insecure ports, protocols and services f. Protection against the denial of service and distributed denial of service attacks g. Restriction on connections to the external world and the internet h. Malicious code detection and filtering i. Restrict, change and segment users access 12.4.6. Security of IPv6 device: The organization must ensure that all dual-stack network devices, equipment and operating systems that support IPv6 must disable the functionality unless it is being used and appropriate security measure have been deployed for their protection. All future networks should be IPv6 compatible C6 12.4.7. Segmentation: The organization must create appropriate network segmentation and maintain updated network access control lists C7 12.4.8. Security zones: The organization must create separate zones for and apply additional security protections to network zones that contain classified information from the environment where their users access the Internet and external email. C8 NISPG - Version 5.0 Restricted Page 37

Select target paragraph3