National Information Security Policy and Guidelines | Ministry of Home Affairs
denial of service; impersonation (rogue AP, DHCP, or other spoofing)
attacks, and more
h. Logging and monitoring: Organization must have a logging mechanism in
place to record and maintain unauthorized attempts and authorized user
activity
i.
Prevent simultaneous connections: Organization must implement
appropriate technical security controls to separate Wi-Fi network and
wired network, if any. Devices used for connecting the Wi-Fi network
should not be allowed to connect simultaneously to the wired network
such as by explicitly disabling or enabling wireless adapters
j.
Physical isolation: Organization should ensure that there is proper physical
isolation of sensitive and wireless networks. All the terminals or computers
dealing with sensitive/classified information should not have any wireless
equipment including Internet and Bluetooth
k. Disable SSID broadcasting to prevent the access points from broadcasting
the SSID to enable only authorized users with preconfigured configured
SSID to access the network
l.
Disable DHCP and assign static IP addresses to all wireless users
12.5.12.
Disabling unused ports: The organization must identify ports, protocols and
services required to carry out daily operations and block all others, including
all non-IP based and unencrypted protocols, by establishing policies in routers
and wireless access points
IG 12
12.5.13.
Personal devices usage policy: Use of personal devices must be authorized by
concerned personnel of the organization, with documented forms maintained
to reflect approvals and rejections. This documentation should include fields
such as employee name, employee ID, device approved/rejected status, date
and time, device identity and type etc. (refer section 20.2)
IG 13
a. The organization must perform security check of the personal device prior
to authorization for use in official premises. A comprehensive security
evaluation of the device must be performed to ensure no security loophole
is induced in the network due to introduction of such devices. These
checks should include at a minimum checking for malwares, open ports,
installed firewall, antivirus, latest system patches installed amongst others
b. The organization must create a secure data container on the personal
device
c. Classified information marked secret and top secret must be prohibited
from storage, transaction or processing on personal devices
12.5.14.
Restricting access to public network: The organization must disable unused
network adapters in systems and restrict internet connection sharing and
adhoc network creation.
NISPG - Version 5.0
Restricted
IG 14
Page 43