National Information Security Policy and Guidelines | Ministry of Home Affairs
12.2.6. The new components and architectural elements incorporated as a part of the plan for
infrastructure transition may introduce serious security issues. Adoption of trends such as
mobility and usage of personally owned devices exposes the network to a new set of threats
12.3. Network and infrastructure security management guidelines
12.3.1.
Inventory of assets and infrastructure: The organization should ensure that a
network diagram illustrating all network devices and other significant devices is
available. Since this contains classified information, such documentation
should be appropriately protected and its distribution should be limited. The
organization must maintain and update a map/inventory of authorized devices
such as:
G1
a. Infrastructure components spread across the organization and connected
to the network endpoints, server systems, applications, databases and data
files, and messaging systems
b. Connectivity and access to users, endpoints, devices, server systems,
applications, databases and messaging systems should be recorded and
maintained
c. The spread of the organizational assets across the operational functions
and geographies and their access requirements should also be recorded
12.3.2.
Security testing of network & infrastructure devices: All infrastructure and
network hardware may be procured, from manufacturers or resellers who are
authorized by manufacturers, with reasonable demonstration of compliance
with global security best practices
G2
12.3.3.
Network perimeter security: The government organization must secure the
network perimeter by deploying competent security solutions
G3
12.3.4.
Network zones: The organization must divide their networks into multiple
functional zones according to the sensitivity or criticality of information or
services in that zone. Wherever possible, physical isolation must be performed
G4
a. Access from external environment: Sensitive IT assets must not be directly
accessible from the external environment
b. Network segmentation technologies: The organization must ensure that
appropriate network segmentation technologies are enforced to logically
and physically isolate the network and protect classified information and
critical services (such as user authentication and user directory
information)
c. Operating zones for users: Environment that allow internal users access to
information assets and systems should be separated from the environment
created for external users
12.3.5.
LAN security: The organization must develop, document and periodically
update security policies and procedures related to Local Area Networks (LAN)
G5
a. The organization must evaluate risks associated with transmission of
NISPG - Version 5.0
Restricted
Page 35