d. key management, the enrolment and removal of system users and issuing of personal
identification
e. staff member clearances, security awareness training and regular briefings
f. inspection of the generated audit trails and logs
g. end of day checks and lockup
h. reporting of ICT security incidents and breaches.
13. Virtualization [VL]
13.1. Policy Objective
The objective of this policy is to provide controls to secure the virualized IT infrastructureat the agency. Agencies need
to ensure that such virtualized environments are adequately secured.
For virtual environment hosted outside by 3rd parties , agencies should also refer to Cloud Security Policy (proposed).
13.2. Policy & Baseline Controls
In order to comply with this policy, Agencies MUST ensure:
VL 1.
*Evaluate the risks associated with the virtual technologies.
a. Evaluate the risks in context of relevant legal, regulatory policies and legislations.
b. Evaluate how the introduction of virtual technology will change your existing IT infrastructure and
the related risk posture.
VL2
*Harden the hypervisor, administrative layer, the virtual machine and related components
as per the industry accepted best practices and security guidelines and the vendor
recommendations.
VL3
Enforce least privilege and separation of duties [Refer to section C-9 Access Management] for
managing the virtual environment.
a. Define specific roles and granular privileges for each administrator in the central virtualization
management software.
b. Limit direct administrative access to the hypervisor to the extent possible
c. Depending on the risk and the classification of the information processed, Agencies should
consider the use of multi factor authentication or dual or split control of administrative passwords
between multiple administrators.
VL4
*Ensure adequate physical security to prevent unauthorized access to the virtual
technology environment.
VL5
Virtualized technology environment should be augmented by third party security technology to
provide layered security controls (defence in depth approach) to complement the controls provided
by the vendor and technology itself.
VL6
Segregate the Virtual Machines based on the classification of data they process and / or store.
VL7
*A change management [Refer to Section B-6 Change Management] process encompasses
the virtual technology environment.
a. Ensure that virtual machine profile is updated and the integrity of the Virtual Machine image is
maintained at all times.
b. Care should be taken to maintain and update VM’s which are not in active state (dormant or no
longer used).
VL8
47
*Logs from the virtual technology environment SHALL be logged and monitored along with
other IT infrastructure. [Refer to Section B-10 Logging and Security Monitoring].
NATIONAL INFORMATION ASSURANCE MANUAL