National Information Security Policy and Guidelines | Ministry of Home Affairs information systems and devices must be communicated as per standard user access request form containing details such as name of person, location, designation, department, access level authorization, access requirement for applications, databases, files, information repositories etc. b. Any changes or update to user access level must be made only post approval from head of department c. User access deactivation request must be submitted immediately upon termination of employment, instances of non-compliance, suspicious activity and incase required as part of disciplinary action etc. d. The organization must ensure that all user access requests are well documented with details including, but not restricted to, reason for access, user details, type or user – admin, super user, contractor, visitor etc., period of access, HOD approval, information asset/ system owner approval 13.5.4. Access control policies: The organization must enforce, govern and measure compliance with access control policy. IG 26 a. Enforcement of access control policies: Access control policies must be defined to be enforced on ICT infrastructure components such as network, endpoints, servers systems, applications, messaging, databases and security devices b. Governance of access control policies: Access to the systems, network resources and information must be governed as per organization’s policies c. Compliance with access control policies: Non-conformance to policy must be monitored and dealt with as per standard practice defined by organization d. Correlation of logical and physical access: The organization must implement a mechanism to correlate instances of physical access and logical access using IP enabled physical security devices, collection and correlation of logs and rules written to correlate physical and logical instances 13.5.5. Need – to – know access: Access privileges to users must be based on operational role and requirements IG 27 a. Access to higher category of classified information must not be granted unless authorized by information owner b. Access to systems containing higher category of classified information must be restricted by logical access control c. Access security matrix must be prepared which contains the access rights mapped to different roles. This must be done to achieve the objective of role based access control (RBAC) d. Access to system must be granted based on access security matrix NISPG - Version 5.0 Restricted Page 51

Select target paragraph3