National Information Security Policy and Guidelines | Ministry of Home Affairs
access, duration for which access was granted.
13.3.8.
Linkage of logical and physical access: The organizations must correlate logical
access instances with physical access rules for areas where sensitive
information is processed and stored
G 17
13.3.9.
Disciplinary actions: The organizations must incorporate provisions for
managing discrepancies and non-conformance in the disciplinary processes
G 18
13.4. Identity, access and privilege management controls
13.4.1.
Operational requirement mapping: The organization must ensure that
operational requirements are carefully studied to translate them into access
requirements
C 23
13.4.2.
Unique identity of each user: The organization must ensure that each user
identity (User-ID) is uniquely attributable to only one unique user
C 24
13.4.3.
User access management: The organization must document procedures for
approving, granting and managing user access including user registration/deregistration, password delivery and password reset. The procedures must be
updated in a periodic manner as per policy
C 25
a. Authorization for access: The organization must not allow access to
information unless authorized by the relevant information or information
system owners
13.4.4.
Access control policies: The organization must define access control policies
which are integrate-able with existing architecture and technological,
administrative and physical controls
C 26
13.4.5.
Need – to – know access: Access rights to information and information
systems must only be granted to users based on a need-to-know basis
C 27
13.4.6.
Review of user privileges: The organization must enforce a process to review
user privileges periodically
C 28
13.4.7.
Special privileges: The organization must ensure that the use of special
privileges shall be restricted, controlled and monitored as per organization’s
policy
C 29
13.4.8.
Authentication mechanism for access: The organization must enforce
appropriate authentication mechanism to allow access to information and
information systems which is commensurate with the sensitivity of the
information being accessed.
C 30
13.4.9.
Inactive accounts: Inactive accounts must be disabled as per organizations
policy
C 31
13.4.10.
Acceptable usage of Information assets & systems: The organization must
define an acceptable usage policy and procedures specifying the security
requirements and user responsibility for ensuring only organization mandated
C 32
NISPG - Version 5.0
Restricted
Page 48