National Information Security Policy and Guidelines | Ministry of Home Affairs
natural calamities amongst others
14.5.3.
Hazard protection: The organization must deploy sufficient tools, techniques,
equipment etc., to deal with hazard. Capability for detection, prevention and
control measures such as fire alarms, sprinklers, fire extinguishers, safety
evacuation plans, clear exit markings must be available in each facility housing
classified information
IG 44
14.5.4.
Securing gateways: All entry and exit points to facilities/areas housing
classified information in an organization must have biometric access controls
such as fingerprint scanners or other similar gateway access control
mechanisms
IG 45
14.5.5.
Identity badges: The organization must issue photo identity cards with
additional security features such as smart chips to employees for identification
and entry to facilities
IG 46
a. Appropriate measures must be undertaken to prevent tailgating inside the
organizations facility
14.5.6.
Entry of visitors & external service providers: The organization should
maintain records for visitor entry such as name of visitor, time of visit,
concerned person for visit, purpose of visit, address of the visitor, phone
number of the visitor, ID proof presented, devices on-person etc.
IG 47
a. Entry by visitors such as vendor support staff, maintenance staff, project
teams or other external parties, must not be allowed unless accompanied
by authorized staff
b. Authorized personnel permitted to enter the data center or computer
room must display their identification cards at all instances
c. Visitor access record shall be kept and properly maintained for audit
purpose. The access records may include details such as name and
organisation of the person visiting, signature of the visitor, date of access,
time of entry and departure, purpose of visit, etc.
d. The passage between the data center/computer room and the data control
office, if any, should not be publicly accessible in order to avoid the taking
away of material from the data center/computer room without being
noticed
14.5.7.
Visitor verification: Visitor entry must be permitted only if prior notification
has been shared via email from the concerned personnel.
IG 48
a. Visitors must present a valid photo identification card, preferably issued by
the Government of India at the reception, for verification
b. Visitors must always be escorted by the concerned person into the
designated meeting area in the facility
c. Visitors should be issued a temporary identity card that identifies them as
NISPG - Version 5.0
Restricted
Page 59