National Information Security Policy and Guidelines | Ministry of Home Affairs 14.4.5. Identity badges: The entry to a facility is restricted to only those users who provide proof of their organizational identity. Users must be aware of the importance of carrying their identity proof with them C 46 14.4.6. Entry of visitors & external service providers: the organization must define process for allowing and revoking access to visitors, partners, third-party service providers and support services C 47 14.4.7. Visitor verification: All visitors to the facility must only be permitted to enter post validation from concerned employee. Visitor must be instructed to record their identity credentials into the visitor register prior to permitting them inside the facility C 48 14.4.8. Infrastructure protection: Power and telecommunications cabling carrying data or supporting information services should be protected from interception or damage C 49 14.4.9. Guarding facility: The organization must ensure that an adequate number of security guards are deployed at the facilities C 50 14.4.10. Vehicle entry: Ensure that an adequate level of security measures are implemented for vehicle entry & exit, vehicle parking areas, loading/unloading docks, storage areas, manholes, and any other area that may provide passage for physical intrusion C 51 14.4.11. Correlation between physical and logical security: The instances of physical access should be analyzed with logical access instances. Restrictions should be imposed for on premise access of information systems to unauthorized personnel. C 52 14.4.12. Monitoring & surveillance: All entry and exit points should be under surveillance round the clock to look for suspicious activity. Further, all security zones inside the facility/ building must be secured by deploying manpower and appropriate security technologies C 53 14.4.13. Disposal of equipment: Physical disposal of computer or electronic office equipment containing non-volatile data storage capabilities must be checked and examined to ensure all information has been removed. Destruction, overwriting or reformatting of media must be approved and performed with appropriate facilities or techniques such as degaussing of hard drives, secure delete technologies etc. (Refer Annexure 7.2) C 54 14.4.14. Protection of information assets and systems: All information assets and systems must be protected with appropriate access control methodologies such as authorized log-in and password control, smart cards or biometric access C 55 14.4.15. Authorization for change: Ensure that security authorization is performed for all changes pertaining to physical security, instances that may introduce security vulnerabilities and exception to the policy C 56 NISPG - Version 5.0 Restricted Page 57

Select target paragraph3