National Information Security Policy and Guidelines | Ministry of Home Affairs
organisation may be also evolving to have automated alert systems
wherever there is a deviation in the acceptable log parameters
12.4.22.
Extending connectivity to third parties: The connectivity to third party must
be securely managed
C 22
12.5. Network and Infrastructure security implementation guidelines
12.5.1.
Identification and classification: The organization must ensure that classified
information is mapped with the infrastructure elements through which it will
be transmitted, processed or stored.
IG 1
a. All infrastructure devices should be categorized as per classification of
information that they manage
12.5.2.
Network diagram: The organization must develop an accurate mapping of the
core components, connections and information of the network to build
organization’s network diagram including network components such as
routers, switches, firewall and computer systems, IP addresses, data flow
routes, blacklisted or white listed systems/IP addresses, open/entry ports,
subnet mask, administrative interface, zones, access control lists, network
name amongst others
IG 2
a. All amendments to network diagram should be documented with reason
of change, nature of change, person responsible
b. All previous configuration diagram must also be retained for reference
12.5.3.
Network configuration: Organization must review network configuration
periodically by using configuration audit and configuration comparison tools
IG 3
a. The organization must establish a mechanism that compares the running
configuration of network devices against the documented configuration
b. There must be documented standards/procedures for configuring network
devices (e.g. routers, hubs, bridges, concentrators, switches, firewalls, IPS,
IDS etc.), which cover - security architecture, device configuration, access
control to network devices, vulnerability and patch management, changes
to routing tables and settings in network devices and regular review of
network device configuration and set-up.
c. Security controls applied to network devices must incorporate security
architecture principles (e.g. ‘secure by design’, 'defense in depth', ‘secure
by default’, ‘default deny’, ‘fail secure’, 'secure in deployment' and
'usability and manageability').
12.5.4.
Testing and certification of network & infrastructure device: Devices
deployed must be tested and certified prior to their implementation in the
organization’s environment
IG 4
b. Network and infrastructure devices must be self-certified by the
manufacturer
NISPG - Version 5.0
Restricted
Page 39