National Information Security Policy and Guidelines | Ministry of Home Affairs upgrades d. Appropriate permissions should be obtained from the concerned department e. Significant changes to network configuration must be approved by the ISSC 12.5.18. Securing transmission media: All cables and encompassing cabinets must be secured from unauthorized access, physical damage and tampering IG 18 a. Ensure proper mapping and labeling of transmission media b. Physical access to cables must be restricted c. All connectivity points must be secured inside a cabinet 12.5.19. Default device credentials: The organization must ensure that default credentials of network devices and information systems such as usernames, passwords, tokens are changed prior to their deployment or first use IG 19 12.5.20. Connecting devices: The organization must identify active hosts connected to its network using tools and techniques such as IP scanners, network security scanners etc. IG 20 a. Deploy client-side digital certificates for devices to authorize access to network or information resources 12.5.21. Audit & review: Refer section 21.2 IG 21 12.5.22. Extending connectivity to third parties: IG 22 a. The organization must restrict the use of ports, service, protocols etc. used for extending access of organizations network to third parties b. The organization must limit the access granted to third parties to the purpose of granting such access and to the time duration specified for completion of defined tasks c. The organization must ensure that network documentation provided to a third party, such as to a commercial provider, must only contain information necessary for them to undertake their contractual services and functions. Detailed network configuration information must not be published in documentation d. All traffic emanating from third partied must be monitored NISPG - Version 5.0 Restricted Page 45

Select target paragraph3