National Information Security Policy and Guidelines | Ministry of Home Affairs organisation may be also evolving to have automated alert systems wherever there is a deviation in the acceptable log parameters 12.4.22. Extending connectivity to third parties: The connectivity to third party must be securely managed C 22 12.5. Network and Infrastructure security implementation guidelines 12.5.1. Identification and classification: The organization must ensure that classified information is mapped with the infrastructure elements through which it will be transmitted, processed or stored. IG 1 a. All infrastructure devices should be categorized as per classification of information that they manage 12.5.2. Network diagram: The organization must develop an accurate mapping of the core components, connections and information of the network to build organization’s network diagram including network components such as routers, switches, firewall and computer systems, IP addresses, data flow routes, blacklisted or white listed systems/IP addresses, open/entry ports, subnet mask, administrative interface, zones, access control lists, network name amongst others IG 2 a. All amendments to network diagram should be documented with reason of change, nature of change, person responsible b. All previous configuration diagram must also be retained for reference 12.5.3. Network configuration: Organization must review network configuration periodically by using configuration audit and configuration comparison tools IG 3 a. The organization must establish a mechanism that compares the running configuration of network devices against the documented configuration b. There must be documented standards/procedures for configuring network devices (e.g. routers, hubs, bridges, concentrators, switches, firewalls, IPS, IDS etc.), which cover - security architecture, device configuration, access control to network devices, vulnerability and patch management, changes to routing tables and settings in network devices and regular review of network device configuration and set-up. c. Security controls applied to network devices must incorporate security architecture principles (e.g. ‘secure by design’, 'defense in depth', ‘secure by default’, ‘default deny’, ‘fail secure’, 'secure in deployment' and 'usability and manageability'). 12.5.4. Testing and certification of network & infrastructure device: Devices deployed must be tested and certified prior to their implementation in the organization’s environment IG 4 b. Network and infrastructure devices must be self-certified by the manufacturer NISPG - Version 5.0 Restricted Page 39

Select target paragraph3