National Information Security Policy and Guidelines | Ministry of Home Affairs
14.4.16.
Inactivity timeout: All information systems must be configured to time-out a
user’s activity post inactivity for a designated period of time
C 57
14.4.17.
Protection of access keys and methodology: All access keys, cards,
passwords, etc. for entry to any of the information systems and networks shall
be physically secured or subject to well-defined and strictly enforced security
procedures
C 58
14.4.18.
Shoulder surfing: The display screen of an information system on which
classified information can be viewed shall be carefully positioned so that
unauthorized persons cannot readily view it
C 59
14.4.19.
Categorization of zones: The facilities in the organization must be categorized
based on parameters such as the sensitivity of information in the facility, roles
of employees in facilities, operational nature of facility, influx of visitors etc.
C 60
14.4.20.
Access to restricted areas: Visitors requiring access to restricted areas, in –
order to perform maintenance tasks or activities must be accompanied by
authorized personnel from the concerned department at all times. A record of
all equipment being carried inside the facility must be maintained along with
equipment identification details. Similarly a record of all equipment being
carried outside the facility must be recorded and allowed post validation and
written consent from employee concerned
C 61
14.4.21.
Visitor device management: Visitors must be instructed to avoid carrying any
personal computing devices or storage devices inside facilities housing
classified information, unless written permission is obtained from the head of
the department
C 62
14.4.22.
Physical access auditing and review: All attempts of physical access must be
audited on a periodic basis
C 63
14.5.
14.5.1.
Physical security implementation guidelines
Map and characteristics of physical facilities: The organization must
appropriately position security and monitoring measures commensurate with
criticality of Physical facilities, information and IT systems housed within these
facilities
IG 42
a. Create map of facilities, their entry & exit points, deployment of IT systems
and people
b. Create list of authorized personnel, permitted to access areas/ facility
housing sensitive information systems/ devices, should be maintained at
all entry points
c. Physical access to such areas/facility must be granted only post verification
of person as well as by user authentication by use of smart cards, etc.
14.5.2.
Hazard assessment: The organization must undergo hazard assessment at
regular intervals to counter disasters or accidents such as fire safety risk
assessment, seismic safety assessment, flood control assessment and other
NISPG - Version 5.0
Restricted
IG 43
Page 58