Cyber Security Byelaw, 2077
(ii) Limited access to buildings,
(iii) Guards on entrance doors,
(iv) Properly secured and tamper proof wiring,
(v) Alarm doors.
Chapter-3
Provisions Relating to Infrastructure/Network Security
25.
Licensee shall use DDoS Detection and Mitigation system to avoid possible DDoS
attack on the network infrastructure.
26.
Licensee shall have Flow Analyzer which shall be continuously monitored for threat
intelligence (threat detection and alarming).
27.
Licensee shall strictly use secure Virtual Private Network (with IPSec or SSL) when
accessing the system remotely.
28.
Licensee shall map and analyze organizational communication and data flows for
possible security threats.
29.
Licensee shall deploy Mutually Agreed Norms for Routing Security (MANRS).
30.
Licensee shall have provision to securely authenticate users (2 Factor Authentication/
OTP) and provide encrypted access (IPSec/SSL) to Value Added Service
Provider/Third Party into the core system to avoid any security risk.
31.
Licensee shall:
(i) Perform Penetration testing of Critical infrastructure regularly.
(ii) Identify status of equipment performing vulnerability assessment.
(iii) Implement standard security configuration policy on Switches & Routers.
(iv) Isolate and segregate (VLAN) the networks based on needs.
32.
Licensee shall routinely assess their suppliers/third-party partners using audits, test
results, or other forms of evaluations to confirm they are meeting their contractual
security obligations.
33.
Licensee shall implement Wireless Local Area Network (WLAN) security standards
like WPA-2/3.
34.
Licensee shall have Network Firewall and following shall be implemented:
(i) Firewall shall protect their internal network and devices against unauthorized
access.
(ii) Each rule set on the firewall must be approved by an authorized individual and
documented including an explanation of the business need of this rule.
(iii) Unapproved or vulnerable services should be blocked at the gateway firewall.
Page 6 of 12