National Information Security Policy and Guidelines | Ministry of Home Affairs 14.3.5. Interior security: The organization must ensure that all information systems and assets are accessed by only authorized staff and protected by adequate interior security measures G 23 14.3.6. Security zones: The organization must ensure that appropriate zones are created to separate areas accessed by visitors from areas housing classified information assets and systems G 24 a. Basis information classification: Appropriate security zones must be created inside the premises/ building based on the location of information assets and systems, commensurate with the classification of information b. Marking of zones: Zones must be clearly marked to indicate type of personnel allowed access to the said zone within the premise c. Security and monitoring of zones: Strict security measures in addition to round the clock monitoring of such areas must be done 14.3.7. Access to restricted area: Access of people and equipment movement and disposal from the restricted area should be regulated and governed. A special care must be taken for wearable devices. Such clearances should be done by the concerned head of the department. The organization must establish a methodology to ensure coordination between internal functions and staff for the same G 25 14.3.8. Physical activity monitoring and review: All physical access to information assets and systems should be monitored and tracked. User should not be allowed to carry external devices such as laptops; USB drives etc. without prior approval and authorization, into areas which house critical information infrastructure such as data centers etc. G 26 14.4. Physical and environmental security controls 14.4.1. Map and characteristics of physical facilities: The organization must obtain visibility over physical facilities and information systems housed within C 42 a. A list of persons who are authorized to gain access to information assets and systems housed in data centers or other areas supporting critical activities, where computer equipment and data are located or stored, shall be kept up-to-date and should be reviewed periodically 14.4.2. Hazard assessment: The facility housing information assets and systems must be protected from natural hazard and man-made hazard. All facilities located in geographically vulnerable areas must undergo annual assessment to check structural strength C 43 14.4.3. Hazard protection: All facilities must be equipped with adequate equipment to counter man-made disasters or accidents such as fire. The facility should have a combination of hazard detection and control measures such as smoke sensors, sprinklers, fire extinguishers etc. Other sensors and alarms should also be installed for early warning C 44 14.4.4. Securing gateways: All entry and exit points to facilities housing information assets and systems must be secured by deploying manpower and appropriate technological solutions C 45 NISPG - Version 5.0 Restricted Page 56

Select target paragraph3