National Information Security Policy and Guidelines | Ministry of Home Affairs
13.5.15.
Ad-hoc access to systems: The organization must ensure that authentication
credentials of information systems which are disclosed to vendors for
maintenance and support are reset on a periodic basis or upon termination of
maintenance activity, as defined under the organization’s policy
IG 37
13.5.16.
Remote access: Appropriate device configuration must be maintained and
security capability must be deployed, to prevent remote access to information
systems and data from outside the organizations boundary, unless approved
by the head of the department.
IG 38
a. Implement appropriate security technologies to protect information or
information systems being accessed via remote access, such as using VPN
based on SSL/TLS, SSTP or IPsec
b. Enable capture of logs of all activity conducted via remote access
c. Audit logs of all activity conducted via remote access
13.5.17.
Provisioning of personal devices: Refer section 20.3
IG 39
13.5.18.
Segregation of duties: The organization must ensure the following:
IG 40
a.
Separate duties of individuals as necessary, to prevent malevolent activity
without collusion
b. Documents separation of duties
c. Implements separation of duties through assigned information system
access authorizations
d. Restricts mission functions and creates distinct information system
support functions are divided among different individuals/roles
e. Prevent different individuals perform information system support
functions (e.g., system management, systems programming, configuration
management, quality assurance and testing, network security)
f.
Separate security personnel who administer access control functions from
performing administer audit functions
g. Create different administrator accounts for different roles
13.5.19.
User awareness & liability: Refer section 17.4
NISPG - Version 5.0
Restricted
IG 41
Page 54