National Information Security Policy and Guidelines | Ministry of Home Affairs
use of user account privileges
13.4.11.
Password policy: The organization must define a password policy
C 33
a. Password standards- such as minimum password length, restricted words
and format, password life cycle, and include guidelines on user password
selection
b. Password reset process must be set in order to secure the credential in the
process
13.4.12.
Default device credentials: The organization must ensure that all vendorsupplied default passwords for equipment and information systems are
changed before any information system is put into operation
C 34
13.4.13.
Monitoring and retention of logs: The organization must monitor and retain
records for all activity related to granting access to users
C 35
13.4.14.
Unsuccessful log-in attempts: The organization must monitor all log-in
attempts to information systems and block access to users with consecutive
unsuccessful log-in attempts
C 36
a. The organization must ensure appropriate monitoring mechanism is
available to identify fraudulent or malicious activity. The authorization
credentials of user accounts suspected of being compromised must be
reset immediately
13.4.15.
Ad-hoc access to systems: The organization must ensure that prior approval
from the head of the department is obtained in-case it is required to connect a
departmental information system with another information system under the
control of another organization. The security level of the information system
being connected shall not be downgraded upon any such interconnect of
systems
C 37
a. Under any circumstances the authorization level should not allow vendors
to access sensitive information / database of the organization. If needed
proper supervision mechanism may be evolved to watch the activities of
the vendors
13.4.16.
Remote access: The organization must ensure that security measures are in
place to govern the remote access to information systems
C 38
a. Appropriate security technologies must be implemented to protect
information or information systems being accessed via remote access.
These may include use of protocols such as SSL, TLS, SSH and IPsec
13.4.17.
Provisioning of personal devices: The organization must govern provisioning
of access to personal computing devices such as smartphones, tablets, and
memory devices to its internal network as per its security policy
C 39
13.4.18.
Segregation of duties: The organization must ensure that duties, roles,
responsibilities and functions of individual users are segregated, considering
C 40
NISPG - Version 5.0
Restricted
Page 49