National Information Security Policy and Guidelines | Ministry of Home Affairs 13.5.15. Ad-hoc access to systems: The organization must ensure that authentication credentials of information systems which are disclosed to vendors for maintenance and support are reset on a periodic basis or upon termination of maintenance activity, as defined under the organization’s policy IG 37 13.5.16. Remote access: Appropriate device configuration must be maintained and security capability must be deployed, to prevent remote access to information systems and data from outside the organizations boundary, unless approved by the head of the department. IG 38 a. Implement appropriate security technologies to protect information or information systems being accessed via remote access, such as using VPN based on SSL/TLS, SSTP or IPsec b. Enable capture of logs of all activity conducted via remote access c. Audit logs of all activity conducted via remote access 13.5.17. Provisioning of personal devices: Refer section 20.3 IG 39 13.5.18. Segregation of duties: The organization must ensure the following: IG 40 a. Separate duties of individuals as necessary, to prevent malevolent activity without collusion b. Documents separation of duties c. Implements separation of duties through assigned information system access authorizations d. Restricts mission functions and creates distinct information system support functions are divided among different individuals/roles e. Prevent different individuals perform information system support functions (e.g., system management, systems programming, configuration management, quality assurance and testing, network security) f. Separate security personnel who administer access control functions from performing administer audit functions g. Create different administrator accounts for different roles 13.5.19. User awareness & liability: Refer section 17.4 NISPG - Version 5.0 Restricted IG 41 Page 54

Select target paragraph3