National Information Security Policy and Guidelines | Ministry of Home Affairs
d. The changes should be approved by a designated authority
e. The changes should be recorded for any future analysis
13.3.2.
Authentication & authorization for access: The organizations must establish
processes for authenticating each user accessing information systems or
assets. The access requests should be authorized based on predetermined
rules that consider type of information, access types, access requirements,
users roles and security requirements (Refer section 7.2)
G 11
a. Instances that authenticate users and authorize their access to critical
information must be recorded
b. Inactive accounts must be disabled as per the organization's policy
13.3.3.
Password management: The organizations must have standardized, reliable
and secure way of managing passwords of users
G 12
a. A standard for password must be defined length, type of characters
permitted
b. Password history, password change duration etc. should be determined
depending on the sensitivity of information and transactions
c. Password reset requests must be handled carefully and securely
d. Password of privileged user accounts should be handled with additional
care
e. Shared passwords with vendors must be changed regularly
13.3.4.
Credential monitoring: The organization must ensure that instances of user
access provisioning, identification, authentication, access authorization,
credential changes and deprovisioning are logged
G 13
a. The access instances should be monitored and reviewed for identifying
discrepancies
b. Malicious attempts of authentication should be prevented, recorded and
reviewed
13.3.5.
Provisioning personal devices and remote access: The organizations must
ensure that provisioning of access to employees of external service providers
and vendors is managed in a standardized and secure manner
G 14
13.3.6.
Segregation of duties: The organization must ensure that user roles are
appropriately segregated for performing operations. It should be ensured that
user levels and their designated actions are segregated based on the criticality
of information and transactions
G 15
a. Each user action must be distinguished from other users. Any
discrepancies must be identified, reviewed and corrected
13.3.7.
Access record documentation: The organization must ensure that it maintains
an updated record of all personnel granted access to a system, reason for
NISPG - Version 5.0
Restricted
G 16
Page 47