National Information Security Policy and Guidelines | Ministry of Home Affairs
12.4.9.
Network traffic segregation : The organization must implement network
access controls to limit traffic within and between network segments to only
those that are required for operations
C9
12.4.10.
LAN security: The organization must implement relevant controls to ensure
security of information traversing the organizations Local Area Network (LAN)
C 10
12.4.11.
Wireless LAN security: The organization should implement appropriate
controls to protect the confidentiality and integrity of information traversing
over WLAN.
C 11
12.4.12.
Disabling unused ports: The organization must disable unused physical ports
on network devices such as switches, routers and wireless access points
C 12
12.4.13.
Personal devices usage policy: The organization must ensure that incase
personally owned devices are permitted to be connected to the organizations
network, a prior security validation must be performed on such devices at
each log-in instance to check for basic system health requirements. Devices
which are non-compliant with health requirements should be quarantined
C 13
12.4.14.
Restricting access to public network: The organization must ensure that
devices are prevented from simultaneously connecting to an organization
controlled network and to a public data network.
C 14
12.4.15.
Network access control: The organization must implement network access
controls on all networks
C 15
12.4.16.
Firmware upgrade: The organization must ensure that firmware for network
devices is kept up to date
C 16
12.4.17.
Network change management: All changes to the network configuration, in
the form of upgrades of software and firmware or in the form of addition or
removal of hardware devices and systems should be undertaken post
approval from competent authority. All changes to the network configuration
should be documented and approved through a formal change control
process
C 17
12.4.18.
Securing transmission media: All cables and encompassing cabinets must be
secured from unauthorized access, physical damage and tampering
C 18
12.4.19.
Default device credentials: The organization must ensure that default
usernames and passwords are changed before network devices are deployed
C 19
12.4.20.
Connecting devices: The organization must deploy appropriate monitoring
and network scanning methodologies to detect systems connecting to the
network and portable devices connected to workstations via USB ports
C 20
12.4.21.
Audit and review: The organization must conduct periodic audits of network
devices which are being added or removed from networks and create an
inventory of authorized network devices
C 21
a. Network logs: The organization must set up logging of access and activity
of network devices. Depending on the scale of the network components,
NISPG - Version 5.0
Restricted
Page 38