National Information Security Policy and Guidelines | Ministry of Home Affairs 12.5.15. a. Organization owned information assets should be configured to connect to organization owned/ operated networks only b. Organization must disable Internet connection sharing, Ad hoc networks, Routing between virtual private network interfaces and other network interfaces on all organization owned devices Network access control: The organization must implement network access control mechanism across the network IG 15 a. Verify identity of device upon request to connect to the network b. Perform health scan of device post access to network resources c. Authorize access to information sources post validation of policy implementation and update in device d. There must be documented standards/procedures for managing external network access to the organization’s information systems and networks, which specify: List of external connections must be maintained, access control must be implemented, allow only authorized remote device, external connection must be removed when no longer required e. Information systems and networks accessible by external connections must restrict external network traffic to only specified parts of information systems and networks as per the business requirements, provide access to defined entry points, verify the source of external connections, log all security-related activity, record details relating to external connections established f. Access to the network must be restricted to devices that meet minimum security configuration requirements, which includes verifying that devices which are authorized, are running up-to-date malware protection, have the latest systems and software patches installed, are connecting over an encrypted network g. There should be policy for use of firewalls, remote access, VOIP and Telephony and Conferencing 12.5.16. Firmware upgrade: Organization must regularly check for updated firmware for network appliances. All upgrades must be installed post appropriate validation and testing IG 16 12.5.17. Network change management: Organization must test/simulate the changes required for the network in the network simulator tools before implementing in live environment IG 17 a. Ensure that appropriate test and simulation facility/ lab is available b. Select and download appropriate patches/ upgrades and prepare them for test and simulation in facility/ lab c. Examine test results to ensure there are no conflicts with existing patches/ NISPG - Version 5.0 Restricted Page 44

Select target paragraph3