National Information Security Policy and Guidelines | Ministry of Home Affairs 12. Network and infrastructure security 12.1. Background 12.1.1. The increased adoption of information technologies has created immense opportunities to connect, expand and integrate different entities. This led to the expansion of the network capabilities and adoption of emerging connectivity techniques 12.1.2. The network infrastructure itself has evolved with various options of network topologies, types of routing and switching devices and different connectivity options. Networks are playing important role in providing access to information and information systems; providing new ways for executing transactions and helping organizations leverage fruits of globalization and hyper specialization. The diversity of these topologies, devices and connections contributes to creating immense possibilities, however; it also introduces several new security issues and concerns 12.1.3. The organizational ecosystem is undergoing transformation, extending its boundaries by increasingly providing access to third parties and vendors, integrating external interfaces, adopting innovations in endpoint, mobility and wireless technologies, while relaxing norms of standardization and ownership of connecting devices. Enterprise architectures are becoming more complex, multiple new system components are under deployment, and their capabilities are extensively utilized through virtualization. This provides multiple opportunities by which security can be compromised 12.2. Relevance of domain to Information Security 12.2.1. Network plays an important role as it binds all the information assets together and provides a means for operational transaction where different entities can participate, exchange information and carry operations over the information by making use of specific ports, protocols and services provided by the network. This may create the possibilities of exposure of information 12.2.2. Network plays a role in provisioning users and devices access to data as it is the first point of connects. Users seek flexibility in accessing data across different devices and access paths. This may expose organization’s information through these devices and the way users access information 12.2.3. Network infrastructure typically spreads across geographies, providing access, facilitating exchange of information and executing a variety of transactions. A combination of network solutions and devices are required in order for these transactions to be successful. They may create possibilities of compromising security of information at various levels 12.2.4. Traffic flow, connections, devices and traffic patterns introduce significant vulnerabilities and weaknesses. These vulnerabilities and weaknesses may lead to serious security threats to information 12.2.5. Insiders have easy access information and IT systems. Network aids their access to the information and IT systems. They may be source or reason for compromise of security of information NISPG - Version 5.0 Restricted Page 34

Select target paragraph3