National Information Security Policy and Guidelines | Ministry of Home Affairs 14.4.16. Inactivity timeout: All information systems must be configured to time-out a user’s activity post inactivity for a designated period of time C 57 14.4.17. Protection of access keys and methodology: All access keys, cards, passwords, etc. for entry to any of the information systems and networks shall be physically secured or subject to well-defined and strictly enforced security procedures C 58 14.4.18. Shoulder surfing: The display screen of an information system on which classified information can be viewed shall be carefully positioned so that unauthorized persons cannot readily view it C 59 14.4.19. Categorization of zones: The facilities in the organization must be categorized based on parameters such as the sensitivity of information in the facility, roles of employees in facilities, operational nature of facility, influx of visitors etc. C 60 14.4.20. Access to restricted areas: Visitors requiring access to restricted areas, in – order to perform maintenance tasks or activities must be accompanied by authorized personnel from the concerned department at all times. A record of all equipment being carried inside the facility must be maintained along with equipment identification details. Similarly a record of all equipment being carried outside the facility must be recorded and allowed post validation and written consent from employee concerned C 61 14.4.21. Visitor device management: Visitors must be instructed to avoid carrying any personal computing devices or storage devices inside facilities housing classified information, unless written permission is obtained from the head of the department C 62 14.4.22. Physical access auditing and review: All attempts of physical access must be audited on a periodic basis C 63 14.5. 14.5.1. Physical security implementation guidelines Map and characteristics of physical facilities: The organization must appropriately position security and monitoring measures commensurate with criticality of Physical facilities, information and IT systems housed within these facilities IG 42 a. Create map of facilities, their entry & exit points, deployment of IT systems and people b. Create list of authorized personnel, permitted to access areas/ facility housing sensitive information systems/ devices, should be maintained at all entry points c. Physical access to such areas/facility must be granted only post verification of person as well as by user authentication by use of smart cards, etc. 14.5.2. Hazard assessment: The organization must undergo hazard assessment at regular intervals to counter disasters or accidents such as fire safety risk assessment, seismic safety assessment, flood control assessment and other NISPG - Version 5.0 Restricted IG 43 Page 58

Select target paragraph3