National Information Security Policy and Guidelines | Ministry of Home Affairs
security zones for isolating sensitive traffic and secure critical IT systems.
This is typically done by using means such as establishing Demilitarized
Zone (DMZ) and configuring virtual LANs
b. Organization should limit and segment user rights for access by
implementing proper Access Control Lists in the network. Access control
lists should be configured on devices such as routers and/or switches
12.5.8.
Security zones: Virtual LAN should be used by an organization to logically
separate zones which deal with confidential information from the rest of the
network
IG 8
a. VLANs should not be used between classified networks and any other
sensitive networks
b. VLANs between classified networks and any other network of a lower
classification must not be used
c. VLANs between a sensitive or classified network and public network
infrastructure must not be used
d. VLAN trunking must not be used on network devices managing VLANs of
differing security classifications
e. Administrative access for network devices using VLANs must only be
permitted from the most trusted network
12.5.9.
Network traffic segregation: Organization should enforce rule set to minimize
methods and level of access to classified information in order to limit access to
authorized personnel
IG 9
a. Implementation of traffic flow filters, VLANs, network and host based
firewalls,
b. Implementation of application level filtering, proxies, content-based
filtering etc.
c. Wherever possible physical segregation must be preferred over logical
segregation
12.5.10.
LAN security: The organization must implement the following to ensure LAN
security:
IG 10
a. Securing LAN devices: Ensure that all default passwords of routers and
switches are changed prior to deployment
b.
Strong device passwords: Use strong passwords such using a minimum of
12 characters or more (combination of alphanumeric and special
characters)
c. Using secure protocols: Disable all non-IP-based access protocols such as
TELNET, and use secure protocols such as SSH, SSL, or IP Security (IPSec)
NISPG - Version 5.0
Restricted
Page 41