National Information Security Policy and Guidelines | Ministry of Home Affairs 13. Identity, access and privilege management 13.1. Background 13.1.1. Users have a diverse set of access requirements based on their roles and privileges that lead to complex authentication, access, role & privilege management scenarios in respect of access to information and information systems 13.1.2. The access requirements vary widely from providing access to endpoints to network, server systems, applications, data and databases, messaging systems, and so on. Organization’s information is stored, processed and shared over these components of infrastructure. Access to these systems may expose the users to the information 13.1.3. Further, users and user groups, with their respective operational roles, seek access to different information assets for diverse purposes and through various platforms and means. Changing operational ecosystem introduces significant level of dynamism in access requirements in the life cycle of information and information systems 13.2. Relevance of domain to information security 13.2.1. Identity breach is one of the most common threats for organization: intruders try and defeat the organizations authentication scheme; or might steal a critical element of their identity; or might misuse an attribute of their identity to engage in fraud 13.2.2. As there is significant complexity of user identities, privileges and access patterns, the organization may struggle to comprehend the exposure of information and exposure of information to unintended persons may get unnoticed 13.2.3. Without specific attention on identification, access and privilege management of employees of external service providers and vendors, information may be exposed outside the boundaries of an organization 13.3. Identity, access and privilege management guidelines 13.3.1. Governance procedures for access rights, identity & privileges: The organization must establish appropriate procedures to govern access rights to information systems and assets; establish a process for creation of identities; establish a process for defining user privileges and a devise a mechanism to understand how access to information is provided. G 10 a. Each information assets must have an appointed custodian or owner, who should be responsible for classification of data and approving access to the same b. Information about the user identities, privileges, access patterns must be managed in secure manner c. The management oversight must be enforced through the process of approval, monitoring and review to manage identity, users and privileges through their life cycles- identity request, creation, assignment, operations and revocation NISPG - Version 5.0 Restricted Page 46

Select target paragraph3