National Information Security Policy and Guidelines | Ministry of Home Affairs security zones for isolating sensitive traffic and secure critical IT systems. This is typically done by using means such as establishing Demilitarized Zone (DMZ) and configuring virtual LANs b. Organization should limit and segment user rights for access by implementing proper Access Control Lists in the network. Access control lists should be configured on devices such as routers and/or switches 12.5.8. Security zones: Virtual LAN should be used by an organization to logically separate zones which deal with confidential information from the rest of the network IG 8 a. VLANs should not be used between classified networks and any other sensitive networks b. VLANs between classified networks and any other network of a lower classification must not be used c. VLANs between a sensitive or classified network and public network infrastructure must not be used d. VLAN trunking must not be used on network devices managing VLANs of differing security classifications e. Administrative access for network devices using VLANs must only be permitted from the most trusted network 12.5.9. Network traffic segregation: Organization should enforce rule set to minimize methods and level of access to classified information in order to limit access to authorized personnel IG 9 a. Implementation of traffic flow filters, VLANs, network and host based firewalls, b. Implementation of application level filtering, proxies, content-based filtering etc. c. Wherever possible physical segregation must be preferred over logical segregation 12.5.10. LAN security: The organization must implement the following to ensure LAN security: IG 10 a. Securing LAN devices: Ensure that all default passwords of routers and switches are changed prior to deployment b. Strong device passwords: Use strong passwords such using a minimum of 12 characters or more (combination of alphanumeric and special characters) c. Using secure protocols: Disable all non-IP-based access protocols such as TELNET, and use secure protocols such as SSH, SSL, or IP Security (IPSec) NISPG - Version 5.0 Restricted Page 41

Select target paragraph3