National Information Security Policy and Guidelines | Ministry of Home Affairs natural calamities amongst others 14.5.3. Hazard protection: The organization must deploy sufficient tools, techniques, equipment etc., to deal with hazard. Capability for detection, prevention and control measures such as fire alarms, sprinklers, fire extinguishers, safety evacuation plans, clear exit markings must be available in each facility housing classified information IG 44 14.5.4. Securing gateways: All entry and exit points to facilities/areas housing classified information in an organization must have biometric access controls such as fingerprint scanners or other similar gateway access control mechanisms IG 45 14.5.5. Identity badges: The organization must issue photo identity cards with additional security features such as smart chips to employees for identification and entry to facilities IG 46 a. Appropriate measures must be undertaken to prevent tailgating inside the organizations facility 14.5.6. Entry of visitors & external service providers: The organization should maintain records for visitor entry such as name of visitor, time of visit, concerned person for visit, purpose of visit, address of the visitor, phone number of the visitor, ID proof presented, devices on-person etc. IG 47 a. Entry by visitors such as vendor support staff, maintenance staff, project teams or other external parties, must not be allowed unless accompanied by authorized staff b. Authorized personnel permitted to enter the data center or computer room must display their identification cards at all instances c. Visitor access record shall be kept and properly maintained for audit purpose. The access records may include details such as name and organisation of the person visiting, signature of the visitor, date of access, time of entry and departure, purpose of visit, etc. d. The passage between the data center/computer room and the data control office, if any, should not be publicly accessible in order to avoid the taking away of material from the data center/computer room without being noticed 14.5.7. Visitor verification: Visitor entry must be permitted only if prior notification has been shared via email from the concerned personnel. IG 48 a. Visitors must present a valid photo identification card, preferably issued by the Government of India at the reception, for verification b. Visitors must always be escorted by the concerned person into the designated meeting area in the facility c. Visitors should be issued a temporary identity card that identifies them as NISPG - Version 5.0 Restricted Page 59

Select target paragraph3