National Information Security Policy and Guidelines | Ministry of Home Affairs classified information over LAN on a periodic basis b. The organization must clearly define roles and responsibility of personnel for supporting planning and implementing of LAN security, through appropriate job functions c. The organization must ensure that appropriate security measures, tools and methodologies are implemented to protect transmission of classified information over LAN. Traffic over LAN should be protected with use of appropriate encryption methodologies 12.3.6. Wireless architecture: The organization must ensure that Wireless LAN (WLAN) planning and implementation incorporates security best practices G6 a. Confidentiality and integrity: The organization must implement appropriate encryption for transmission of classified information over WLAN b. Administration of access points: The access to WLAN key distribution program should be controlled and limited to the administrators only c. Logging of device activities and audit trails: Network traffic and access to the WLAN should be logged by using suitable methodologies 12.3.7. Network security management: Network security management processes should be created and documented. These processes should define the governing procedures for any security mechanism, changes or modification to the network configuration, the approval matrix, backup mechanisms, guidelines for testing and failover switching amongst others. The organization should ensure that all network security management tasks are approved and performed under the aegis of a single authority or team G7 12.3.8. Unauthorized device connection: Organizations should implement stringent measures to minimize the risk of unauthorized devices from accessing the network. The necessary countermeasures must be deployed to deter the attempts of unauthorized access G8 12.3.9. Extending connectivity to third parties: The government organizations must integrate the infrastructure security with other security solutions such as identity & access management, security monitoring & incident management for integrated defense and response against the threats G9 NISPG - Version 5.0 Restricted Page 36

Select target paragraph3