National Information Security Policy and Guidelines | Ministry of Home Affairs use of user account privileges 13.4.11. Password policy: The organization must define a password policy C 33 a. Password standards- such as minimum password length, restricted words and format, password life cycle, and include guidelines on user password selection b. Password reset process must be set in order to secure the credential in the process 13.4.12. Default device credentials: The organization must ensure that all vendorsupplied default passwords for equipment and information systems are changed before any information system is put into operation C 34 13.4.13. Monitoring and retention of logs: The organization must monitor and retain records for all activity related to granting access to users C 35 13.4.14. Unsuccessful log-in attempts: The organization must monitor all log-in attempts to information systems and block access to users with consecutive unsuccessful log-in attempts C 36 a. The organization must ensure appropriate monitoring mechanism is available to identify fraudulent or malicious activity. The authorization credentials of user accounts suspected of being compromised must be reset immediately 13.4.15. Ad-hoc access to systems: The organization must ensure that prior approval from the head of the department is obtained in-case it is required to connect a departmental information system with another information system under the control of another organization. The security level of the information system being connected shall not be downgraded upon any such interconnect of systems C 37 a. Under any circumstances the authorization level should not allow vendors to access sensitive information / database of the organization. If needed proper supervision mechanism may be evolved to watch the activities of the vendors 13.4.16. Remote access: The organization must ensure that security measures are in place to govern the remote access to information systems C 38 a. Appropriate security technologies must be implemented to protect information or information systems being accessed via remote access. These may include use of protocols such as SSL, TLS, SSH and IPsec 13.4.17. Provisioning of personal devices: The organization must govern provisioning of access to personal computing devices such as smartphones, tablets, and memory devices to its internal network as per its security policy C 39 13.4.18. Segregation of duties: The organization must ensure that duties, roles, responsibilities and functions of individual users are segregated, considering C 40 NISPG - Version 5.0 Restricted Page 49

Select target paragraph3