National Information Security Policy and Guidelines | Ministry of Home Affairs
B.
Table of Contents
1.
Overview ........................................................................................................................... 13
2.
Purpose.............................................................................................................................. 19
3.
Document distribution, applicability and review ................................................................. 20
4.
Scope ................................................................................................................................. 20
5.
Supplementary documents and references ......................................................................... 21
6.
Approach ........................................................................................................................... 22
7.
Information classification guidelines ................................................................................... 26
8.
Information security organization overview ........................................................................ 27
9.
Framework......................................................................................................................... 28
10. Domains impacting information security ............................................................................. 30
11. Guidelines structure and components ................................................................................. 33
12. Network and infrastructure security ................................................................................... 34
13. Identity, access and privilege management ......................................................................... 46
14. Physical and environmental security ................................................................................... 55
15. Application security ............................................................................................................ 64
16. Data security ...................................................................................................................... 71
17. Personnel security .............................................................................................................. 79
18. Threat and vulnerability management ................................................................................ 85
19. Security monitoring and incident management ................................................................... 91
Guidelines for technology specific ICT deployment ................................................................... 100
20. Cloud computing .............................................................................................................. 100
21. Mobility & BYOD .............................................................................................................. 104
22. Virtualization ................................................................................................................... 108
23. Social media ..................................................................................................................... 112
Guidelines for essential security practices................................................................................. 114
24. Security testing ................................................................................................................ 114
25. Security auditing .............................................................................................................. 116
26. Business continuity........................................................................................................... 119
27. Open source technology ................................................................................................... 121
Information handling matrix .................................................................................................... 123
28. Adoption matrix based on information classification ......................................................... 123
29. Annexures ........................................................................................................................ 167
NISPG - Version 5.0
Restricted
Page 12