National Information Security Policy and Guidelines | Ministry of Home Affairs
12. Network and infrastructure security
12.1. Background
12.1.1. The increased adoption of information technologies has created immense opportunities to
connect, expand and integrate different entities. This led to the expansion of the network
capabilities and adoption of emerging connectivity techniques
12.1.2. The network infrastructure itself has evolved with various options of network topologies,
types of routing and switching devices and different connectivity options. Networks are
playing important role in providing access to information and information systems; providing
new ways for executing transactions and helping organizations leverage fruits of globalization
and hyper specialization. The diversity of these topologies, devices and connections
contributes to creating immense possibilities, however; it also introduces several new
security issues and concerns
12.1.3. The organizational ecosystem is undergoing transformation, extending its boundaries by
increasingly providing access to third parties and vendors, integrating external interfaces,
adopting innovations in endpoint, mobility and wireless technologies, while relaxing norms of
standardization and ownership of connecting devices. Enterprise architectures are becoming
more complex, multiple new system components are under deployment, and their
capabilities are extensively utilized through virtualization. This provides multiple
opportunities by which security can be compromised
12.2. Relevance of domain to Information Security
12.2.1. Network plays an important role as it binds all the information assets together and provides a
means for operational transaction where different entities can participate, exchange
information and carry operations over the information by making use of specific ports,
protocols and services provided by the network. This may create the possibilities of exposure
of information
12.2.2. Network plays a role in provisioning users and devices access to data as it is the first point of
connects. Users seek flexibility in accessing data across different devices and access paths.
This may expose organization’s information through these devices and the way users access
information
12.2.3. Network infrastructure typically spreads across geographies, providing access, facilitating
exchange of information and executing a variety of transactions. A combination of network
solutions and devices are required in order for these transactions to be successful. They may
create possibilities of compromising security of information at various levels
12.2.4. Traffic flow, connections, devices and traffic patterns introduce significant vulnerabilities and
weaknesses. These vulnerabilities and weaknesses may lead to serious security threats to
information
12.2.5. Insiders have easy access information and IT systems. Network aids their access to the
information and IT systems. They may be source or reason for compromise of security of
information
NISPG - Version 5.0
Restricted
Page 34