Cyber Security Byelaw, 2077 (ii) Detect threats/malware/botnets based on IP addresses of customers and inform them for cleaning their devices. 14. Licensee shall use commercial licensed Operating System (OS), applications, antivirus/antimalware used in Servers, Desktop, Laptop and Mobile devices etc. 15. Licensee shall follow the common best security practices defined by SANS, CIS etc. while using open source such as GNU General Public License, BSD license for operating system, applications, antivirus/antimalware etc. 16. Licensee shall perform regular update of Antivirus, Database, Application Libraries, Operating System, Kernel etc. 17. Licensee shall restrict default login for any applications, systems or software. 18. Licensee shall make provision for closing all hardware ports (including USB, CD/DVD and External Devices) of the devices (servers) for discouraging copying files directly and use alternative methods of sharing files like file server. 19. Licensee shall make provision for using Centralized Authentication System like Active Directory (AD), Light Weight Directory Access Protocol (LDAP) for AAA of its employees. 20. Licensee shall be encouraged to use PGP/Digital signature in email communications, documents, letters and other applications. 21. Licensee shall bind manufacturers/vendors/suppliers of hardware, software and related infrastructure to patch the vulnerabilities ensuring minimum level of security. 22. Licensee shall make use of national and international cyber risk information sharing platform to receive and share information regarding security issues, vulnerabilities, and cyber threat intelligence. 23. Licensee shall have its board approved disaster recovery and Business Continuity Policy/Procedure/Plan (BCP) to counteract interruptions to business activities and to protect critical business processes from the effects of major failure or disaster: (i) Redundancy and fault tolerance shall be built into the systems to minimize the impact of attacks and data corruption. (ii) The BCP shall contain identification of attacks and security breaches, incident response plan, communication plan and escalation matrix. (iii) The BCP shall contain offsite location for backups and disaster recovery. 24. Licensee shall establish security perimeters to protect physical and IT assets. Licensee shall establish protected entry controls, such as the followings, to ensure that only authorized personnel are allowed access: (i) Badges, Page 5 of 12

Select target paragraph3