National Information Security Policy and Guidelines | Ministry of Home Affairs c. Network and infrastructure devices must be tested and certified in any globally recognised lab d. The organization must ensure comprehensive network and infrastructure device testing from established testing labs of STQC, DRDO or other designated government test labs 12.5.5. Network security measures: For perimeter defense, organization must use appropriate security capability, such as IG 5 a. For traffic inspection and detection of anomalies and threats organization should implement Security Information and Event Management (SIEM) capability b. Organization should deploy Intrusion Detection System (IDS) capabilities to monitor network or system activities for malicious activities or policy violations c. Organization should deploy Intrusion Prevention System (IPS) capabilities to identify malicious activities in the network, log information and attempts to block them d. For protection against the distributed denial of service (DDoS) and denial of service (DoS) attacks appropriate protection must be incorporated inhouse such as on premise traffic filtering equipment or from service providers for services such as traffic-routing service through Border Gateway Protocol, DNS change to traffic snubbing centers, cloud based mitigation etc. e. The organization should conduct or participate in mock drill exercises to test network security measure 12.5.6. Security of IPv6 device: The organization should have security measures specific to IPv6 security IG 6 a. Disable IPv6 functionality at the gateway level until and unless required for use by organization with additional DoS security measures. Block all IPv6 traffic on IPv4-only networks b. Use standard, non-obvious static addresses for critical systems c. Firewall, IDS/IPS must be able to scan IPv6 traffic and enforce policies on the same d. The event and transaction logging mechanism must be capable of capturing activity of IPv6 devices e. All future networks should be IPv6 compatible 12.5.7. Segmentation: To restrict, segment and modify user access, organization should deploy tools such as Active Directory to limit or grant permissions to a user IG 7 a. The organizations must ensure segmentation of the network to create NISPG - Version 5.0 Restricted Page 40

Select target paragraph3