National Information Security Policy and Guidelines | Ministry of Home Affairs
a. The organization must clearly state that it provides computer devices,
networks, and other electronic information systems to meet its missions,
goals, and initiatives and users must manage them responsibly to maintain
the confidentiality, integrity, and availability of the organizations
information
b. This needs to be elaborate across areas such as email, internet, desktops,
information, clear desk policy, password policy etc.
c. The organization must obtain user sign-off on acceptable usage policy
13.5.11.
Password policy: The organization must define its password policy, with
specific focus on password issuance and activation methods along with
standard process for governance and communicate the same to user upon
creation of user account
IG 33
a. All active sessions of a user must be terminated post 15 minutes of
inactivity and must be activated only post re-authentication by specified
mechanism such as re-entering password etc.
b. Passwords must be encrypted when transmitting over an un-trusted
communication network
c. Issue guidelines to end user to help in selection of strong alphanumeric
password comprising of a minimum of 12 characters
d. Prevent users from using passwords shorter than a pre-defined length, or
re-using previously used passwords
e. Passwords must be automatically reset if user accounts are revoked or
disabled upon inactivity beyond 30 days of inactivity
f.
Password communication must on verified alternate channel such as SMS,
email, etc.
13.5.12.
Default device credentials: The organization must ensure that default login
credentials of devices such as routers, firewall, storage equipment etc, are
changed prior to the deployment of such devices in the operational
environment
IG 34
13.5.13.
Monitoring and retention of logs: The organization must retain information
pertaining to requests for user ID creation, user rights allocation, user rights
modification, user password reset request and other instances of change or
modification to user profile, as per audit and governance requirements
IG 35
13.5.14.
Unsuccessful login attempts: The organization must monitor unsuccessful login attempts from each of the authentication mechanisms, to track for
consecutive unsuccessful log-in attempts
IG 36
a. The user account must be disabled for a pre-defined limit post five
unsuccessful log-in attempts
b. A random alpha numeric text CAPTCHA should be introduced post second
unsuccessful log-in attempt
NISPG - Version 5.0
Restricted
Page 53