National Information Security Policy and Guidelines | Ministry of Home Affairs
information systems and devices must be communicated as per standard
user access request form containing details such as name of person,
location, designation, department, access level authorization, access
requirement for applications, databases, files, information repositories etc.
b. Any changes or update to user access level must be made only post
approval from head of department
c. User access deactivation request must be submitted immediately upon
termination of employment, instances of non-compliance, suspicious
activity and incase required as part of disciplinary action etc.
d. The organization must ensure that all user access requests are well
documented with details including, but not restricted to, reason for access,
user details, type or user – admin, super user, contractor, visitor etc.,
period of access, HOD approval, information asset/ system owner approval
13.5.4.
Access control policies: The organization must enforce, govern and measure
compliance with access control policy.
IG 26
a. Enforcement of access control policies: Access control policies must be
defined to be enforced on ICT infrastructure components such as network,
endpoints, servers systems, applications, messaging, databases and
security devices
b. Governance of access control policies: Access to the systems, network
resources and information must be governed as per organization’s policies
c. Compliance with access control policies: Non-conformance to policy must
be monitored and dealt with as per standard practice defined by
organization
d. Correlation of logical and physical access: The organization must
implement a mechanism to correlate instances of physical access and
logical access using IP enabled physical security devices, collection and
correlation of logs and rules written to correlate physical and logical
instances
13.5.5.
Need – to – know access: Access privileges to users must be based on
operational role and requirements
IG 27
a. Access to higher category of classified information must not be granted
unless authorized by information owner
b. Access to systems containing higher category of classified information
must be restricted by logical access control
c. Access security matrix must be prepared which contains the access rights
mapped to different roles. This must be done to achieve the objective of
role based access control (RBAC)
d. Access to system must be granted based on access security matrix
NISPG - Version 5.0
Restricted
Page 51