National Information Security Policy and Guidelines | Ministry of Home Affairs B. Table of Contents 1. Overview ........................................................................................................................... 13 2. Purpose.............................................................................................................................. 19 3. Document distribution, applicability and review ................................................................. 20 4. Scope ................................................................................................................................. 20 5. Supplementary documents and references ......................................................................... 21 6. Approach ........................................................................................................................... 22 7. Information classification guidelines ................................................................................... 26 8. Information security organization overview ........................................................................ 27 9. Framework......................................................................................................................... 28 10. Domains impacting information security ............................................................................. 30 11. Guidelines structure and components ................................................................................. 33 12. Network and infrastructure security ................................................................................... 34 13. Identity, access and privilege management ......................................................................... 46 14. Physical and environmental security ................................................................................... 55 15. Application security ............................................................................................................ 64 16. Data security ...................................................................................................................... 71 17. Personnel security .............................................................................................................. 79 18. Threat and vulnerability management ................................................................................ 85 19. Security monitoring and incident management ................................................................... 91 Guidelines for technology specific ICT deployment ................................................................... 100 20. Cloud computing .............................................................................................................. 100 21. Mobility & BYOD .............................................................................................................. 104 22. Virtualization ................................................................................................................... 108 23. Social media ..................................................................................................................... 112 Guidelines for essential security practices................................................................................. 114 24. Security testing ................................................................................................................ 114 25. Security auditing .............................................................................................................. 116 26. Business continuity........................................................................................................... 119 27. Open source technology ................................................................................................... 121 Information handling matrix .................................................................................................... 123 28. Adoption matrix based on information classification ......................................................... 123 29. Annexures ........................................................................................................................ 167 NISPG - Version 5.0 Restricted Page 12

Select target paragraph3