National Information Security Policy and Guidelines | Ministry of Home Affairs encryption for all remote connections to the router/switch/server d. Traffic monitoring: Deploy traffic management capabilities which continuously monitors and controls IP network e. Allocating IP address: Ensure that IP addresses allocated to each network appliance/system/server is associated with their respective MAC address and is not user modifiable 12.5.11. Wireless LAN security: The organization must implement the following for wireless LAN security: IG 11 a. Limiting coverage of access points: Organization must evaluate physical perimeter to define positioning of wireless device thereby limiting radio transmission and coverage, inside the physical premises or intended coverage area b. Device configuration: Organization owned systems with ability to connect wireless network should be preconfigured with relevant and appropriate drivers by the relevant ICT personnel. Configuration of wireless access including Wi-Fi/Bluetooth and similar technologies should not be user configurable c. Wireless encryption: Organization must ensure that communication between user system and wireless AP are secured using highest graded encryption (WPA-2 or higher) for data confidentiality and integrity. Under no circumstances, should open APs be deployed in the network d. Using secure protocols: Organization must ensure that all available measures are applied on Access Points (APs) or WLAN switches to secure them from unauthorized access, use of plaintext protocols such as SNMP, Telnet or HTTP for access management services should not be done. Restrict systems from which management access is permitted e. Wireless security gateway: Organization should place firewalls or application proxies between client and server subnets and before network admission of any new devices proper security scanning should be done. f. Visitor access to WLAN: If the organization sets up external WLANs primarily to provide Internet access to visitors; such WLANs should be architected so that their traffic does not traverse the organization’s internal trusted networks such as configuring a guest WLAN access with a second SSID for limiting guest access to Internet only. Organization should further ensure use of guest accounts and require login (guest authentication) g. Perform a WLAN security audit to identify vulnerabilities: Organization with WLANs should conduct regular periodic security audit to see if organization’s WLAN networks are vulnerable to attacks resulting from configuration errors; if equipment or software used have critical flaws that attackers can exploit to penetrate the network; if network is vulnerable to NISPG - Version 5.0 Restricted Page 42

Select target paragraph3