National Information Security Policy and Guidelines | Ministry of Home Affairs a. The organization must clearly state that it provides computer devices, networks, and other electronic information systems to meet its missions, goals, and initiatives and users must manage them responsibly to maintain the confidentiality, integrity, and availability of the organizations information b. This needs to be elaborate across areas such as email, internet, desktops, information, clear desk policy, password policy etc. c. The organization must obtain user sign-off on acceptable usage policy 13.5.11. Password policy: The organization must define its password policy, with specific focus on password issuance and activation methods along with standard process for governance and communicate the same to user upon creation of user account IG 33 a. All active sessions of a user must be terminated post 15 minutes of inactivity and must be activated only post re-authentication by specified mechanism such as re-entering password etc. b. Passwords must be encrypted when transmitting over an un-trusted communication network c. Issue guidelines to end user to help in selection of strong alphanumeric password comprising of a minimum of 12 characters d. Prevent users from using passwords shorter than a pre-defined length, or re-using previously used passwords e. Passwords must be automatically reset if user accounts are revoked or disabled upon inactivity beyond 30 days of inactivity f. Password communication must on verified alternate channel such as SMS, email, etc. 13.5.12. Default device credentials: The organization must ensure that default login credentials of devices such as routers, firewall, storage equipment etc, are changed prior to the deployment of such devices in the operational environment IG 34 13.5.13. Monitoring and retention of logs: The organization must retain information pertaining to requests for user ID creation, user rights allocation, user rights modification, user password reset request and other instances of change or modification to user profile, as per audit and governance requirements IG 35 13.5.14. Unsuccessful login attempts: The organization must monitor unsuccessful login attempts from each of the authentication mechanisms, to track for consecutive unsuccessful log-in attempts IG 36 a. The user account must be disabled for a pre-defined limit post five unsuccessful log-in attempts b. A random alpha numeric text CAPTCHA should be introduced post second unsuccessful log-in attempt NISPG - Version 5.0 Restricted Page 53

Select target paragraph3