National Information Security Policy and Guidelines | Ministry of Home Affairs 13.5.6. Review of user privileges: All user accounts must be reviewed periodically by concerned authority by use of system activity logs, log-in attempts to access non-authorized resources, abuse of system privileges, frequent deletion of data by user etc. IG 28 13.5.7. Special privileges: The organization must ensure that the use of special privileges for users to access additional information systems, resources, devices are granted only post documented approval from information owner IG 29 a. All such additional privileges must be issued for a pre-notified duration and should lapse post the specified period. b. Allocation of special privileges must be strictly controlled and restricted to urgent operational cases c. All activity conducted with the use of special privileges must be monitored and logged as per organization’s policy 13.5.8. Authentication mechanism for access: The organization must have various levels of authentication mechanisms IG 30 a. Depending on the sensitivity of information and transactions, authentication type must vary b. For access to sensitive information system, authentication such as 2-factor authentication should be implemented. Authentication levels must be defined to include a combination of any two of the following authentication mechanisms: Level 1: PIN number or password authentication against a user-ID Level 2: Smart card or USB token or One-time password Level 3: Biometric identification c. Credential sharing must be performed on an encrypted channel which is separate from the message relay channel d. Use directory services such as LDAP and X500 13.5.9. Inactive accounts: The organization must ensure the following: IG 31 a. All user accounts which are inactive for 45 days should be disabled b. The authentication credentials of all disabled accounts must also be reset upon deactivation c. All disabled accounts must be reactivated only post verification of the user by concerned security administrator d. All accounts in disabled state for 30 days must be deleted 13.5.10. Acceptable usage of Information assets & systems: The organization must ensure that users are made aware of their responsibility to use their account privileges only for organization mandated use NISPG - Version 5.0 Restricted IG 32 Page 52

Select target paragraph3