National Information Security Policy and Guidelines | Ministry of Home Affairs factors such as conflict of privileges 13.4.19. 13.5. 13.5.1. User awareness & liability: The organization must ensure that all users are made aware of their responsibilities towards secure access to and usage of the organizations information and information systems. All users shall be accountable and responsible for all activities performed with their User-IDs C 41 Identity, access and privilege implementation guidelines Operational requirement mapping: The organization must develop a formal procedure to govern allocation of user identification and access mechanism. All privileges associated with a user-ID must also be governed as per standard procedure IG 23 a. Operational roles must be mapped to corresponding IT roles b. IT roles must be grouped for performing particular operations c. Credential requirements of the roles must be mapped carefully d. Operational rules for granting and revoking access must be studied and an inventory should be created of the same 13.5.2. Unique identity of each user: All employees including temporary and contract workers must be allotted a unique ID. The system for managing user IDs must function directly under the head of the department or his authorized representative IG 24 a. User identity schemes must be defined and enforced b. Identity provisioning workflow must be defined with proper checks and balances c. Identity provisioning process must be audited at periodic interval d. Any sharing of user ID’s should be restricted to special instances, which are duly approved by the information or information system owner e. The shared ID’s passwords must be changed promptly when the need no longer exists and should be changed frequently if sharing is required on a regular basis f. There must be clear ownership established for shared accounts g. There must be a log maintained as to whom the shared ID was assigned at any given point of time. Multiple parallel sessions of the same ID must be strictly prohibited 13.5.3. User access management: The organization must establish a process to manage user access across the lifecycle of the user from the initial registration of new users, password delivery, password reset to the final de-registration of users who no longer require access to information systems and services in the organization IG 25 a. Details of users authorized by the head of the department to access NISPG - Version 5.0 Restricted Page 50

Select target paragraph3