National Information Security Policy and Guidelines | Ministry of Home Affairs
upgrades
d. Appropriate permissions should be obtained from the concerned
department
e. Significant changes to network configuration must be approved by the ISSC
12.5.18.
Securing transmission media: All cables and encompassing cabinets must be
secured from unauthorized access, physical damage and tampering
IG 18
a. Ensure proper mapping and labeling of transmission media
b. Physical access to cables must be restricted
c. All connectivity points must be secured inside a cabinet
12.5.19.
Default device credentials: The organization must ensure that default
credentials of network devices and information systems such as usernames,
passwords, tokens are changed prior to their deployment or first use
IG 19
12.5.20.
Connecting devices: The organization must identify active hosts connected to
its network using tools and techniques such as IP scanners, network security
scanners etc.
IG 20
a. Deploy client-side digital certificates for devices to authorize access to
network or information resources
12.5.21.
Audit & review: Refer section 21.2
IG 21
12.5.22.
Extending connectivity to third parties:
IG 22
a. The organization must restrict the use of ports, service, protocols etc. used
for extending access of organizations network to third parties
b. The organization must limit the access granted to third parties to the
purpose of granting such access and to the time duration specified for
completion of defined tasks
c. The organization must ensure that network documentation provided to a
third party, such as to a commercial provider, must only contain
information necessary for them to undertake their contractual services
and functions. Detailed network configuration information must not be
published in documentation
d. All traffic emanating from third partied must be monitored
NISPG - Version 5.0
Restricted
Page 45