National Information Security Policy and Guidelines | Ministry of Home Affairs d. The changes should be approved by a designated authority e. The changes should be recorded for any future analysis 13.3.2. Authentication & authorization for access: The organizations must establish processes for authenticating each user accessing information systems or assets. The access requests should be authorized based on predetermined rules that consider type of information, access types, access requirements, users roles and security requirements (Refer section 7.2) G 11 a. Instances that authenticate users and authorize their access to critical information must be recorded b. Inactive accounts must be disabled as per the organization's policy 13.3.3. Password management: The organizations must have standardized, reliable and secure way of managing passwords of users G 12 a. A standard for password must be defined length, type of characters permitted b. Password history, password change duration etc. should be determined depending on the sensitivity of information and transactions c. Password reset requests must be handled carefully and securely d. Password of privileged user accounts should be handled with additional care e. Shared passwords with vendors must be changed regularly 13.3.4. Credential monitoring: The organization must ensure that instances of user access provisioning, identification, authentication, access authorization, credential changes and deprovisioning are logged G 13 a. The access instances should be monitored and reviewed for identifying discrepancies b. Malicious attempts of authentication should be prevented, recorded and reviewed 13.3.5. Provisioning personal devices and remote access: The organizations must ensure that provisioning of access to employees of external service providers and vendors is managed in a standardized and secure manner G 14 13.3.6. Segregation of duties: The organization must ensure that user roles are appropriately segregated for performing operations. It should be ensured that user levels and their designated actions are segregated based on the criticality of information and transactions G 15 a. Each user action must be distinguished from other users. Any discrepancies must be identified, reviewed and corrected 13.3.7. Access record documentation: The organization must ensure that it maintains an updated record of all personnel granted access to a system, reason for NISPG - Version 5.0 Restricted G 16 Page 47

Select target paragraph3