Cyber Security Byelaw, 2077
(ii) Detect threats/malware/botnets based on IP addresses of customers and inform
them for cleaning their devices.
14.
Licensee shall use commercial licensed Operating System (OS), applications,
antivirus/antimalware used in Servers, Desktop, Laptop and Mobile devices etc.
15.
Licensee shall follow the common best security practices defined by SANS, CIS etc.
while using open source such as GNU General Public License, BSD license for
operating system, applications, antivirus/antimalware etc.
16.
Licensee shall perform regular update of Antivirus, Database, Application Libraries,
Operating System, Kernel etc.
17.
Licensee shall restrict default login for any applications, systems or software.
18.
Licensee shall make provision for closing all hardware ports (including USB,
CD/DVD and External Devices) of the devices (servers) for discouraging copying
files directly and use alternative methods of sharing files like file server.
19.
Licensee shall make provision for using Centralized Authentication System like
Active Directory (AD), Light Weight Directory Access Protocol (LDAP) for AAA of
its employees.
20.
Licensee shall be encouraged to use PGP/Digital signature in email communications,
documents, letters and other applications.
21.
Licensee shall bind manufacturers/vendors/suppliers of hardware, software and
related infrastructure to patch the vulnerabilities ensuring minimum level of security.
22.
Licensee shall make use of national and international cyber risk information sharing
platform to receive and share information regarding security issues, vulnerabilities,
and cyber threat intelligence.
23.
Licensee shall have its board approved disaster recovery and Business Continuity
Policy/Procedure/Plan (BCP) to counteract interruptions to business activities and to
protect critical business processes from the effects of major failure or disaster:
(i) Redundancy and fault tolerance shall be built into the systems to minimize the
impact of attacks and data corruption.
(ii) The BCP shall contain identification of attacks and security breaches, incident
response plan, communication plan and escalation matrix.
(iii) The BCP shall contain offsite location for backups and disaster recovery.
24.
Licensee shall establish security perimeters to protect physical and IT assets. Licensee
shall establish protected entry controls, such as the followings, to ensure that only
authorized personnel are allowed access:
(i) Badges,
Page 5 of 12