National Information Security Policy and Guidelines | Ministry of Home Affairs 12.4.9. Network traffic segregation : The organization must implement network access controls to limit traffic within and between network segments to only those that are required for operations C9 12.4.10. LAN security: The organization must implement relevant controls to ensure security of information traversing the organizations Local Area Network (LAN) C 10 12.4.11. Wireless LAN security: The organization should implement appropriate controls to protect the confidentiality and integrity of information traversing over WLAN. C 11 12.4.12. Disabling unused ports: The organization must disable unused physical ports on network devices such as switches, routers and wireless access points C 12 12.4.13. Personal devices usage policy: The organization must ensure that incase personally owned devices are permitted to be connected to the organizations network, a prior security validation must be performed on such devices at each log-in instance to check for basic system health requirements. Devices which are non-compliant with health requirements should be quarantined C 13 12.4.14. Restricting access to public network: The organization must ensure that devices are prevented from simultaneously connecting to an organization controlled network and to a public data network. C 14 12.4.15. Network access control: The organization must implement network access controls on all networks C 15 12.4.16. Firmware upgrade: The organization must ensure that firmware for network devices is kept up to date C 16 12.4.17. Network change management: All changes to the network configuration, in the form of upgrades of software and firmware or in the form of addition or removal of hardware devices and systems should be undertaken post approval from competent authority. All changes to the network configuration should be documented and approved through a formal change control process C 17 12.4.18. Securing transmission media: All cables and encompassing cabinets must be secured from unauthorized access, physical damage and tampering C 18 12.4.19. Default device credentials: The organization must ensure that default usernames and passwords are changed before network devices are deployed C 19 12.4.20. Connecting devices: The organization must deploy appropriate monitoring and network scanning methodologies to detect systems connecting to the network and portable devices connected to workstations via USB ports C 20 12.4.21. Audit and review: The organization must conduct periodic audits of network devices which are being added or removed from networks and create an inventory of authorized network devices C 21 a. Network logs: The organization must set up logging of access and activity of network devices. Depending on the scale of the network components, NISPG - Version 5.0 Restricted Page 38

Select target paragraph3