National Information Security Policy and Guidelines | Ministry of Home Affairs
13. Identity, access and privilege management
13.1. Background
13.1.1. Users have a diverse set of access requirements based on their roles and privileges that lead
to complex authentication, access, role & privilege management scenarios in respect of
access to information and information systems
13.1.2. The access requirements vary widely from providing access to endpoints to network, server
systems, applications, data and databases, messaging systems, and so on. Organization’s
information is stored, processed and shared over these components of infrastructure. Access
to these systems may expose the users to the information
13.1.3. Further, users and user groups, with their respective operational roles, seek access to
different information assets for diverse purposes and through various platforms and means.
Changing operational ecosystem introduces significant level of dynamism in access
requirements in the life cycle of information and information systems
13.2. Relevance of domain to information security
13.2.1. Identity breach is one of the most common threats for organization: intruders try and defeat
the organizations authentication scheme; or might steal a critical element of their identity; or
might misuse an attribute of their identity to engage in fraud
13.2.2. As there is significant complexity of user identities, privileges and access patterns, the
organization may struggle to comprehend the exposure of information and exposure of
information to unintended persons may get unnoticed
13.2.3. Without specific attention on identification, access and privilege management of employees
of external service providers and vendors, information may be exposed outside the
boundaries of an organization
13.3. Identity, access and privilege management guidelines
13.3.1.
Governance procedures for access rights, identity & privileges: The
organization must establish appropriate procedures to govern access rights to
information systems and assets; establish a process for creation of identities;
establish a process for defining user privileges and a devise a mechanism to
understand how access to information is provided.
G 10
a. Each information assets must have an appointed custodian or owner, who
should be responsible for classification of data and approving access to the
same
b. Information about the user identities, privileges, access patterns must be
managed in secure manner
c. The management oversight must be enforced through the process of
approval, monitoring and review to manage identity, users and privileges
through their life cycles- identity request, creation, assignment, operations
and revocation
NISPG - Version 5.0
Restricted
Page 46