National Information Security Policy and Guidelines | Ministry of Home Affairs
encryption for all remote connections to the router/switch/server
d. Traffic monitoring: Deploy traffic management capabilities which
continuously monitors and controls IP network
e. Allocating IP address: Ensure that IP addresses allocated to each network
appliance/system/server is associated with their respective MAC address
and is not user modifiable
12.5.11.
Wireless LAN security: The organization must implement the following for
wireless LAN security:
IG 11
a. Limiting coverage of access points: Organization must evaluate physical
perimeter to define positioning of wireless device thereby limiting radio
transmission and coverage, inside the physical premises or intended
coverage area
b. Device configuration: Organization owned systems with ability to connect
wireless network should be preconfigured with relevant and appropriate
drivers by the relevant ICT personnel. Configuration of wireless access
including Wi-Fi/Bluetooth and similar technologies should not be user
configurable
c. Wireless encryption: Organization must ensure that communication
between user system and wireless AP are secured using highest graded
encryption (WPA-2 or higher) for data confidentiality and integrity. Under
no circumstances, should open APs be deployed in the network
d. Using secure protocols: Organization must ensure that all available
measures are applied on Access Points (APs) or WLAN switches to secure
them from unauthorized access, use of plaintext protocols such as SNMP,
Telnet or HTTP for access management services should not be done.
Restrict systems from which management access is permitted
e. Wireless security gateway: Organization should place firewalls or
application proxies between client and server subnets and before network
admission of any new devices proper security scanning should be done.
f.
Visitor access to WLAN: If the organization sets up external WLANs
primarily to provide Internet access to visitors; such WLANs should be
architected so that their traffic does not traverse the organization’s
internal trusted networks such as configuring a guest WLAN access with a
second SSID for limiting guest access to Internet only. Organization should
further ensure use of guest accounts and require login (guest
authentication)
g. Perform a WLAN security audit to identify vulnerabilities: Organization
with WLANs should conduct regular periodic security audit to see if
organization’s WLAN networks are vulnerable to attacks resulting from
configuration errors; if equipment or software used have critical flaws that
attackers can exploit to penetrate the network; if network is vulnerable to
NISPG - Version 5.0
Restricted
Page 42