National Information Security Policy and Guidelines | Ministry of Home Affairs
13.5.6.
Review of user privileges: All user accounts must be reviewed periodically by
concerned authority by use of system activity logs, log-in attempts to access
non-authorized resources, abuse of system privileges, frequent deletion of
data by user etc.
IG 28
13.5.7.
Special privileges: The organization must ensure that the use of special
privileges for users to access additional information systems, resources,
devices are granted only post documented approval from information owner
IG 29
a. All such additional privileges must be issued for a pre-notified duration and
should lapse post the specified period.
b. Allocation of special privileges must be strictly controlled and restricted to
urgent operational cases
c. All activity conducted with the use of special privileges must be monitored
and logged as per organization’s policy
13.5.8.
Authentication mechanism for access: The organization must have various
levels of authentication mechanisms
IG 30
a. Depending on the sensitivity of information and transactions,
authentication type must vary
b. For access to sensitive information system, authentication such as 2-factor
authentication should be implemented. Authentication levels must be
defined to include a combination of any two of the following
authentication mechanisms:
Level 1: PIN number or password authentication against a user-ID
Level 2: Smart card or USB token or One-time password
Level 3: Biometric identification
c. Credential sharing must be performed on an encrypted channel which is
separate from the message relay channel
d. Use directory services such as LDAP and X500
13.5.9.
Inactive accounts: The organization must ensure the following:
IG 31
a. All user accounts which are inactive for 45 days should be disabled
b. The authentication credentials of all disabled accounts must also be reset
upon deactivation
c. All disabled accounts must be reactivated only post verification of the user
by concerned security administrator
d. All accounts in disabled state for 30 days must be deleted
13.5.10.
Acceptable usage of Information assets & systems: The organization must
ensure that users are made aware of their responsibility to use their account
privileges only for organization mandated use
NISPG - Version 5.0
Restricted
IG 32
Page 52