National Information Security Policy and Guidelines | Ministry of Home Affairs denial of service; impersonation (rogue AP, DHCP, or other spoofing) attacks, and more h. Logging and monitoring: Organization must have a logging mechanism in place to record and maintain unauthorized attempts and authorized user activity i. Prevent simultaneous connections: Organization must implement appropriate technical security controls to separate Wi-Fi network and wired network, if any. Devices used for connecting the Wi-Fi network should not be allowed to connect simultaneously to the wired network such as by explicitly disabling or enabling wireless adapters j. Physical isolation: Organization should ensure that there is proper physical isolation of sensitive and wireless networks. All the terminals or computers dealing with sensitive/classified information should not have any wireless equipment including Internet and Bluetooth k. Disable SSID broadcasting to prevent the access points from broadcasting the SSID to enable only authorized users with preconfigured configured SSID to access the network l. Disable DHCP and assign static IP addresses to all wireless users 12.5.12. Disabling unused ports: The organization must identify ports, protocols and services required to carry out daily operations and block all others, including all non-IP based and unencrypted protocols, by establishing policies in routers and wireless access points IG 12 12.5.13. Personal devices usage policy: Use of personal devices must be authorized by concerned personnel of the organization, with documented forms maintained to reflect approvals and rejections. This documentation should include fields such as employee name, employee ID, device approved/rejected status, date and time, device identity and type etc. (refer section 20.2) IG 13 a. The organization must perform security check of the personal device prior to authorization for use in official premises. A comprehensive security evaluation of the device must be performed to ensure no security loophole is induced in the network due to introduction of such devices. These checks should include at a minimum checking for malwares, open ports, installed firewall, antivirus, latest system patches installed amongst others b. The organization must create a secure data container on the personal device c. Classified information marked secret and top secret must be prohibited from storage, transaction or processing on personal devices 12.5.14. Restricting access to public network: The organization must disable unused network adapters in systems and restrict internet connection sharing and adhoc network creation. NISPG - Version 5.0 Restricted IG 14 Page 43

Select target paragraph3