National Information Security Policy and Guidelines | Ministry of Home Affairs
14.3.5.
Interior security: The organization must ensure that all information systems
and assets are accessed by only authorized staff and protected by adequate
interior security measures
G 23
14.3.6.
Security zones: The organization must ensure that appropriate zones are
created to separate areas accessed by visitors from areas housing classified
information assets and systems
G 24
a. Basis information classification: Appropriate security zones must be
created inside the premises/ building based on the location of information
assets and systems, commensurate with the classification of information
b. Marking of zones: Zones must be clearly marked to indicate type of
personnel allowed access to the said zone within the premise
c. Security and monitoring of zones: Strict security measures in addition to
round the clock monitoring of such areas must be done
14.3.7.
Access to restricted area: Access of people and equipment movement and
disposal from the restricted area should be regulated and governed. A special
care must be taken for wearable devices. Such clearances should be done by
the concerned head of the department. The organization must establish a
methodology to ensure coordination between internal functions and staff for
the same
G 25
14.3.8.
Physical activity monitoring and review: All physical access to information
assets and systems should be monitored and tracked. User should not be
allowed to carry external devices such as laptops; USB drives etc. without prior
approval and authorization, into areas which house critical information
infrastructure such as data centers etc.
G 26
14.4. Physical and environmental security controls
14.4.1.
Map and characteristics of physical facilities: The organization must obtain
visibility over physical facilities and information systems housed within
C 42
a. A list of persons who are authorized to gain access to information assets
and systems housed in data centers or other areas supporting critical
activities, where computer equipment and data are located or stored, shall
be kept up-to-date and should be reviewed periodically
14.4.2.
Hazard assessment: The facility housing information assets and systems must
be protected from natural hazard and man-made hazard. All facilities located
in geographically vulnerable areas must undergo annual assessment to check
structural strength
C 43
14.4.3.
Hazard protection: All facilities must be equipped with adequate equipment to
counter man-made disasters or accidents such as fire. The facility should have
a combination of hazard detection and control measures such as smoke
sensors, sprinklers, fire extinguishers etc. Other sensors and alarms should also
be installed for early warning
C 44
14.4.4.
Securing gateways: All entry and exit points to facilities housing information
assets and systems must be secured by deploying manpower and appropriate
technological solutions
C 45
NISPG - Version 5.0
Restricted
Page 56