National Information Security Policy and Guidelines | Ministry of Home Affairs
factors such as conflict of privileges
13.4.19.
13.5.
13.5.1.
User awareness & liability: The organization must ensure that all users are
made aware of their responsibilities towards secure access to and usage of the
organizations information and information systems. All users shall be
accountable and responsible for all activities performed with their User-IDs
C 41
Identity, access and privilege implementation guidelines
Operational requirement mapping: The organization must develop a formal
procedure to govern allocation of user identification and access mechanism.
All privileges associated with a user-ID must also be governed as per standard
procedure
IG 23
a. Operational roles must be mapped to corresponding IT roles
b. IT roles must be grouped for performing particular operations
c. Credential requirements of the roles must be mapped carefully
d. Operational rules for granting and revoking access must be studied and an
inventory should be created of the same
13.5.2.
Unique identity of each user: All employees including temporary and contract
workers must be allotted a unique ID. The system for managing user IDs must
function directly under the head of the department or his authorized
representative
IG 24
a. User identity schemes must be defined and enforced
b. Identity provisioning workflow must be defined with proper checks and
balances
c. Identity provisioning process must be audited at periodic interval
d. Any sharing of user ID’s should be restricted to special instances, which are
duly approved by the information or information system owner
e. The shared ID’s passwords must be changed promptly when the need no
longer exists and should be changed frequently if sharing is required on a
regular basis
f.
There must be clear ownership established for shared accounts
g. There must be a log maintained as to whom the shared ID was assigned at
any given point of time. Multiple parallel sessions of the same ID must be
strictly prohibited
13.5.3.
User access management: The organization must establish a process to
manage user access across the lifecycle of the user from the initial registration
of new users, password delivery, password reset to the final de-registration of
users who no longer require access to information systems and services in the
organization
IG 25
a. Details of users authorized by the head of the department to access
NISPG - Version 5.0
Restricted
Page 50