National Information Security Policy and Guidelines | Ministry of Home Affairs access, duration for which access was granted. 13.3.8. Linkage of logical and physical access: The organizations must correlate logical access instances with physical access rules for areas where sensitive information is processed and stored G 17 13.3.9. Disciplinary actions: The organizations must incorporate provisions for managing discrepancies and non-conformance in the disciplinary processes G 18 13.4. Identity, access and privilege management controls 13.4.1. Operational requirement mapping: The organization must ensure that operational requirements are carefully studied to translate them into access requirements C 23 13.4.2. Unique identity of each user: The organization must ensure that each user identity (User-ID) is uniquely attributable to only one unique user C 24 13.4.3. User access management: The organization must document procedures for approving, granting and managing user access including user registration/deregistration, password delivery and password reset. The procedures must be updated in a periodic manner as per policy C 25 a. Authorization for access: The organization must not allow access to information unless authorized by the relevant information or information system owners 13.4.4. Access control policies: The organization must define access control policies which are integrate-able with existing architecture and technological, administrative and physical controls C 26 13.4.5. Need – to – know access: Access rights to information and information systems must only be granted to users based on a need-to-know basis C 27 13.4.6. Review of user privileges: The organization must enforce a process to review user privileges periodically C 28 13.4.7. Special privileges: The organization must ensure that the use of special privileges shall be restricted, controlled and monitored as per organization’s policy C 29 13.4.8. Authentication mechanism for access: The organization must enforce appropriate authentication mechanism to allow access to information and information systems which is commensurate with the sensitivity of the information being accessed. C 30 13.4.9. Inactive accounts: Inactive accounts must be disabled as per organizations policy C 31 13.4.10. Acceptable usage of Information assets & systems: The organization must define an acceptable usage policy and procedures specifying the security requirements and user responsibility for ensuring only organization mandated C 32 NISPG - Version 5.0 Restricted Page 48

Select target paragraph3