Information Security Guidelines
X X X X Extracts X X X X
X X X X Extracts X X X X
....nsensus for such cooperation as per globally accepted norms. The Government of a country/jurisdiction will, however, agree to exchange information with another country only if the information exchanged is kept confidential, used only for the specified purposes and disclosed only to authorized person(s) in accordance with the agreement on the basis of which it is exchanged. It is, therefore, essential that for continued assistance by the treaty partners of India, the information received is kept confidential and is used and disclosed strictly as per the terms of the Agreement. 3. An Information Security Committee (ISC) has been constituted in the Central Board of Direct Taxes (CBDT) under the chairmanship of Member (IT) through orders F. No. 500/137/2011-FTTR-III dated 7th April, 2015 and 19th June 2015 with a view to pulling in place a robust Information Security Mechanism in the Department. The ISC shall consist of a Chief Information Security Officer (CISO) and six other members. The responsibilities of the ISC and CI SO arc enclosed at Annexure A. 4. It has now been decided that all Cadre Controlling Pr. CCsIT should set up a Local Information Security Committe....
X X X X Extracts X X X X
X X X X Extracts X X X X
....security (c) Identity, access and privilege management (d) Security monitoring and incident management 9. The Information security guidelines consist of following sections: (a) Background- Provides an overview and the coverage of each domain and states the important evolutions and developments in each area. (b) Relevance of domain to information security-Establishes role and scope of a domain in context of Information Security. (c) Management guidelines- Provides domain specific recommendations in the form of guidelines and objectives. These are denoted by the nomenclature "XX.G" followed by the guideline number, where XX is the code for domain. For example, PH.G1, PH.G2, G3 ... (d) Security controls- Provides control statements which arc administrative, technical, operational or procedural and need to be diligently followed. Security controls provide insight into multiple areas which need to be implemented/addressed in order to achieve the objectives laid out in the management guidelines section. These arc denoted by the nomenclature "XX.C" followed by the control number, where....
X X X X Extracts X X X X
X X X X Extracts X X X X
....icer (CISO). Broad Responsibilities of ISC have been specified as under: (a) Ratification of the Information Security Policies and Procedures (ISPP) suggested by the CISO. (b) Ensure that ISPP is implemented by ensuring the involvement of the business heads. (c) Conduct the management review of the ISPP to ensure continuing suitability, adequacy and effectiveness of ISPP. (d) Initiate internal and external security reviews and ensuring that action is taken to rectify any identified shortfalls. (e) Responsible for disciplinary action in cases of breach of ISPP. Broad Responsibilities of CISO have been specified as under: (a) Responsible for preparing, maintaining and communicating ISPP. (b) Oversee all information security processes and serve as the focal point for all information security issues and concerns. (c) Ensure that responsibilities are defined for and that procedures are in effect to promptly detect, investigate, report and resolve security incidents. (d) Ensure that ongoing information security awareness education and training is provided to all employees. (e) Provide reports ....
X X X X Extracts X X X X
X X X X Extracts X X X X
....option matrix for Physical Security ........................................... 16 2. Personnel Security ..............................................................................19 2.1. Background ...........................................................................19 2.2. Relevance of domain to information security ....................................19 2.3. Personnel security guidelines .......................................................19 2.4. Personnel security controls ...........................................................20 2.5. Personnel security implementation guidelines .................................... 22 2.6. Adoption matrix for Personnel Security ............................................25 3. Identity, access and privilege management ...................................................27 3.1. Background ............................................................................27 3.2. Relevance of domain to information security .................................... 27 3.3. Identity, access and privilege management guidelines ............................27 ....
X X X X Extracts X X X X
X X X X Extracts X X X X
....rsonnel may gain access to sensitive areas. Instances such as theft of information may remain undetected iv. Without processes for physical access provisioning and deprovisioning, governing access to the sensitive physical locations will remain a challenging task. This will have serious impact on security of information and information during their life cycle in a particular physical facility c. Physical and environmental security guidelines • Map and characteristics of physical facilities: The organization must create an map of access point and information assets and systems housed within PH.G1 • Protection from hazard: The organization must ensure that all facilities housing information systems and assets are provided with adequate physical security measures, which include protection from natural and man-made hazard PH.G2 • Physical boundary protection: The organization must deploy an adequate level of perimeter security measures such as barriers, fencing, protective lighting, etc. PH.G3 • Restricting entry: The organization must deploy an adequate level of countermeasures for restricting the entry to the faciliti....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ted in geographically vulnerable areas must undergo annual assessment to check structural strength PH.C2 • Hazard protection: All facilities must be equipped with adequate equipment to counter man-made disasters or accidents such as fire. The facility should have a combination of hazard detection and control measures such as smoke sensors, sprinklers, fire extinguishers etc. Other sensors and alarms should also be installed for early warning PH.C3 • Securing gateways: All entry and exit points to facilities housing information assets and systems must be secured by deploying manpower and appropriate technological solutions PH.C4 • Identity badges: The entry to a facility is restricted to only those users who provide proof of their organizational identity. Users must be aware of the importance of carrying their identity proof with them PH.C5 • Entry of visitors & external service providers: the organization must define process for allowing and revoking access to visitors, partners, third-party service providers and support services PH.C6 • Visitor verification: All visitors to the facility must only be pe....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ated period of time PH.C16 • Protection of access keys and methodology: All access keys, cards, passwords, etc. for entry to any of the information systems and networks shall be physically secured or subject to well-defined and strictly enforced security procedures PH.C17 • Shoulder surfing: The display screen of an information system on which classified information can be viewed shall be carefully positioned so that unauthorized persons cannot readily view it PH.C18 • Categorization of zones: The facilities in the organization must be categorized based on parameters such as the sensitivity of information in the facility, roles of employees in facilities, operational nature of facility, influx of visitors etc. PH.C19 • Access to restricted areas: Visitors requiring access to restricted areas, in - order to perform maintenance tasks or activities must be accompanied by authorized personnel from the concerned department at all times. A record of all equipment being carried inside the facility must be maintained along with equipment identification details. Similarly a record of all equipment being carried outside the faci....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ent tailgating inside the organizations facility PH.IG5 • Entry of visitors & external service providers: The organization should maintain records for visitor entry such as name of visitor, time of visit, concerned person for visit, purpose of visit, address of the visitor, phone number of the visitor, ID proof presented, devices on-person etc. b. Entry by visitors such as vendor support staff, maintenance staff, project teams or other external parties, must not be allowed unless accompanied by authorized staff c. Authorized personnel permitted to enter the data center or computer room must display their identification cards at all instances d. Visitor access record shall be kept and properly maintained for audit purpose. The access records may include details such as name and organisation of the person visiting, signature of the visitor, date of access, time of entry and departure, purpose of visit, etc. e. The passage between the data center/computer room and the data control office, if any, should not be publicly accessible in order to avoid the taking away of material from the data center/computer room without being noticed ....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ave physical access to facility housing systems or devices which enable physical or logical access to sensitive data and systems. This includes areas within the facility which house backup tapes, servers, cables and communication systems etc. b. Access controls should encompass areas containing system hardware, network wiring, backup media, and any other elements required for the system 's operation PH.IG11 • Monitoring & surveillance: The organization must establish mechanism for 24/7 surveillance of all areas inside the physical perimeter by' use of technology such as security cameras (or closed-circuit TV) a. The organization must monitor the areas such as hosting critical/sensitive systems and have video images recorded. The recording of the camera should be retained for at least a month for future review b. Intruder detection systems can be considered to be installed for areas hosting critical/sensitive systems PH.IG12 • Disposal of equipment: Destruction and disposal of hard drives/ memory devices should be performed by techniques such as removing magnets, hammering, burning, degaussing, shredding, secure dele....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ment occurs; this can include such spaces as places where services are provided and information is exchanged. Access by visitors may be limited to specific times of the day or for specific reasons c. Operations zone: an area where access is limited to personnel who work there and to properly-escorted visitors; it must be indicated by a recognizable perimeter and monitored continuously, Examples: typical open office space, or typical electrical room d. Security zone: area to which access is limited to authorized personnel, and to authorized and properly-escorted visitors; it must be indicated by a recognizable perimeter and monitored continuously. Example: an area where secret information is processed or stored e. High security zone: an area to which access is limited to authorized, appropriately-screened personnel and authorized and properly-escorted visitors; it must be indicated by a perimeter built to the specifications, monitored continuously and be an area to which details of access are recorded and audited. Example: an area where high-value assets are handled by selected personnel PH.1G19 • Access to restricted areas: Visitors requir....
X X X X Extracts X X X X
X X X X Extracts X X X X
....rating physical security logs with logical security logs d. Integrating physical security with SIEM solutions e. Real time monitoring of physical security logs for classified information PH.IG22 f. Adoption matrix for Physical Security Top secret Secret Confidential Restricted Unclassified Guidelines Map and characteristics of physical facilities PH.G1 PH.G1 PH.G1 PH.G1 Protection from hazard PH.G2 PH.G2 PH.G2 PH.G2 PH.G2 Physical boundary protection PH.G3 PH.G3 PH.G3 PH.G3 PH.G3 Restricting entry PH.G4 PH.G4 PH.G4 Interior security PH.G5 PH.G5 PH.G5 PH.G5 Security zones PH.G6 PH.G6 PH.G6 PH.G6 Access to restricted area PH.G7 PH.G7 PH.G7 PH.G7 Physical activity monitoring and review PH.G8 PH.G8 PH.G8 ....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... Physical access auditing and review PH.C22 PH.C22 PH.C22 PH.C22 Implementation Guidelines Map and characteristics of physical facilities PH.IGI, PH.IGI(a), (b),(c) PH.IGI, PH.IGI(a), (b),(c) PH.IGI, PH.IGI(a), (b),(c) PH.IGI, PH.IGI(a), (b),(c) Hazard assessment PH.IG2 PH.IG2 PH.IG2 PH.IG2 PH.IG2 Hazard protection PH.IG3 PH.IG3 PH.IG3 PH.IG3 Securing gateways PH.IG4 PH.IG4 PH.IG4 PH.IG4 Identity badges PH.IG5, PH.IG5(a) PH.IG5, PH.IG5(a) PH.IG5, PH.IG5(a) PH.IG5 Entry Of visitors & external service providers PH.IG6, PH.IG6 (a) to (e) PH.IG6, PH.IG6 (a) to (e) PH.IG6, PH.IG6 (a) to (e) PH.IG6 Visitor verification PH.IG7, PH.IG7(a), (b),(c)....
X X X X Extracts X X X X
X X X X Extracts X X X X
....r device management PH.IG21, PH.IG21 (a),(b),(c) PH.IG21, PH.IG21 (a),(b),(c) PH.IG21, PH.IG21 (a),(b) PH.IG21, PH.IG21 (a),(b) Physical access auditing and review PH.IG22, PH.IG22 (a),(b),(c)(d)(e) PH.IG22, PH.IG22 (a),(b),(c)(d)(e) PH.IG22, PH.IG22 (a),(b) PH.IG22, PH.IG22 (a),(b) 2. Personnel Security a. Background i. Insider threat has been a large contributor towards a number of security incidents faced by organizations. Additionally, the sourcing patterns of an organization are increasingly dependent on external service providers, for bridging gaps in their skills and competence, saving costs, augmenting capabilities to improve scalability and for making operations lean and efficient ii. However, granting access to organizations information assets and systems to third-party service providers (TPSP's) increases the security risk. As employees and third parties have access to confidential information during their tenur....
X X X X Extracts X X X X
X X X X Extracts X X X X
....zation owned information assets and systems PE.G3 • Record of authorized users: The organization should maintain an updated record of all users granted access to each information asset and system PE.G4 • Acceptable usage policy: The organization must develop an acceptable usage policy for all information assets and systems including Web and email resources provided to employees, amongst others PE.G5 • Monitoring and review: The organization must implement appropriate monitoring tools and technology to track compliance of personnel with organization 's policies PE.G6 • Limiting exposure of information: The organizations must ensure that coverage of personnel security program limits the exposure of information to unintended recipients, parties or organizations PE.GI d. Personnel security controls • Training and Awareness: The organization must ensure that role based training is provided to all personnel within the organization to familiarize them with their roles and responsibilities in order to support security requirements. The organization must ensure that information security awareness and trai....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... by different functions are maintained in a central repository/ system PE.C6 • Monitoring and review: The organization must define processes to monitor and review access granted to personnel including temporary or emergency access to any information asset or system PE.C7 • Non- disclosure agreements: The organization must incorporate considerations such as signing non-disclosure contracts and agreements in the HR process, both for employees and third parties allowed to access information assets and systems PE.C8 • Legal and contractual obligations: The organization must ensure that employees and third parties are aware of legal and contractual obligations with respect to security of information a. The organization must ensure that users are aware of policies, procedures and guidelines issued with respect to Information Security PE.C9 • Communication practices: The organization must prohibit its employees and external parties from disseminating/ communicating classified information for any other purpose expect its authorized and intended use a. Information regarding security incidents must only' be....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... based on their role; function performed and associated need for access a. Prior to granting physical and logical access to third party personnel, the organization must seek sufficient proof of identity of personnel from the third party employer such as recent background check and verification by competent authority b. Authorization for access to third party personnel must be supported by documented request from head of department, where third party personnel will be deployed c. Organization must strictly monitor all activity conducted by third party personnel d. Organization must strictly monitor physical movement of third party personnel within its facility e. Organization should permit authorized individuals to use an external information system to access or to process, store, or transmit organization-controlled information only post verification of the implementation of required security controls on the external system as specified in the organization's information security policy f. Organization must limit the use of organization-controlled portable storage media by authorized individuals on external information systems....
X X X X Extracts X X X X
X X X X Extracts X X X X
....t a. Non-disclosure agreements should restrict employees and third parties from sharing organizational information publically PE.1G8 • Legal and contractual obligations: Organization must brief all personnel about their legal and contractual obligation to protect the organizations information and to follow all security advisories issued by competent authority so as to prevent disclosure of information, loss of sensitive data amongst and information compromise a. The terms of employment must contain a copy of all relevant policies and guidelines b. The organization must obtain a formal signoff from the employee on all such policies and guidelines such as end user policy, acceptable usage policy etc. PE.IG9 • Communication practices: Organization must establish, documented and implemented policies, procedures and controls to restrict personnel from unintended communication, both internally and with external entities such as media a. Communication messages should be circulated to state security requirements or alert employees must be sent by designated personnel only b. Only official spokesperson/ designated ....
X X X X Extracts X X X X
X X X X Extracts X X X X
....G1 , PE.IG1 (a) to PE.IG1, PE.IG1 (a),(b),(d) to (j) PE.IG1, PE.IG1 (g), (h), (i), (j) Employee verification PE.IG2, PE.IG2 (a),(b),(c) PE.IG2, PE.IG2 (a),(b),(c) PE.IG2, PE.IG2 (a),(b),(c) PE.IG2, PE.IG2 (a),(b),(c) Authorizing access to third parties PE.IG3, PE.IG3 (a) to (f) PE.IG3, PE.IG3 PE.IG3, PE.IG3 (a) to (f) PE.IG3, PE.IG3 (a) to (f) Top secret Secret Confidential Restricted Unclassified Acceptable use policies PE.IG4, PE.IG4 (a), (b), (c) PE.IG4, PE.IG4 (a), (b), (c) PE.IG4, PE.IG4 (a), (b), (c) PE.IG4, PE.IG4 (a), (b), (c) Disciplinary process PE.IG5, PE.IG5(a) PE.IG5, PE.IG5(a) PE.IG5, PE.IG5(a) PE.IG5, PE.IG5(a) Record of authorized users P....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ere is significant complexity of user identities, privileges and access patterns, the organization may struggle to comprehend the exposure of information and exposure of information to unintended persons may get unnoticed iii. Without specific attention on identification, access and privilege management of employees of external service providers and vendors, information may be exposed outside the boundaries of an organization c. Identity, access and privilege management guidelines • Governance procedures for access rights, identity & privileges: The organization must establish appropriate procedures to govern access rights to information systems and assets; establish a process for creation of identities; establish a process for defining user privileges and a devise a mechanism to understand how access to information is provided. a. Each information assets must have an appointed custodian or owner, who should be responsible for classification of data and approving access to the same b. Information about the user identities, privileges, access patterns must be managed in secure manner c. The management oversight must be enforced thr....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... a. Each user action must be distinguished from other users. Any discrepancies must be identified, reviewed and corrected IA.G6 Access record documentation: The organization must ensure that it maintains an updated record of all personnel granted access to a system, reason for access, duration for which access was granted. IA.G7 Linkage of logical and physical access: The organizations must correlate logical access instances with physical access rules for areas where sensitive information is processed and stored IA.G8 Disciplinary actions: The organizations must incorporate provisions for managing discrepancies and non-conformance in the disciplinary processes IA.G9 d. Identity, access and privilege management controls • Operational requirement mapping: The organization must ensure that operational requirements are carefully studied to translate them into access requirements IA.C1 • Unique identity of each user: The organization must ensure that each user identity (User-ID) is uniquely attributable to only one unique user IA.C2 • User access management: The organization must document procedures for approving, gran....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ccess to users IA.C13 • Unsuccessful log-in attempts: The organization must monitor all log-in attempts to information systems and block access to users with consecutive unsuccessful log-in attempts a. The organization must ensure appropriate monitoring mechanism is available to identify fraudulent or malicious activity. The authorization credentials of user accounts suspected of being compromised must be reset immediately IA.C14 • Ad-hoc access to systems: The organization must ensure that prior approval from the head of the department is obtained in-case it is required to connect a departmental information system with another information system under the control of another organization. The security level of the information system being connected shall not be downgraded upon any such interconnect of systems a. Under any circumstances the authorization level should not allow vendors to access sensitive information / database of the organization. If needed proper supervision mechanism may be evolved to watch the activities of the vendors IA.C15 • Remote access: The organization must ensure that security measures are ....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ID's passwords must be changed promptly when the need no longer exists and should be changed frequently if sharing is required on a regular basis f. There must be clear ownership established for shared accounts g. There must be a log maintained as to whom the shared ID was assigned at any given point of time. Multiple parallel sessions of the same ID must be strictly prohibited IA.1G2 • User access management: The organization must establish a process to manage user access across the lifecycle of the user from the initial registration of new users, password delivery, password reset to the final de-registration of users who no longer require access to information systems and services in the organization a. Details of users authorized by the head of the department to access information systems and devices must be communicated as per standard user access request form containing details such as name of person, location, designation, department, access level authorization, access requirement for applications, databases, files, information repositories etc. b. Any changes or update to user access level must be made only post approva....
X X X X Extracts X X X X
X X X X Extracts X X X X
....abuse of system privileges, frequent deletion of data by user etc. IA.1G6 • Special privileges: The organization must ensure that the use of special privileges for users to access additional information systems, resources, devices are granted only post documented approval from information owner a. All such additional privileges must be issued for a pre-notified duration and should lapse post the specified period. b. Allocation of special privileges must be strictly controlled and restricted to urgent operational cases c. All activity conducted with the use of special privileges must be monitored and logged as per organization's policy IA.1G7 • Authentication mechanism for access: The organization must have various levels of authentication mechanisms a. Depending on the sensitivity of information and transactions, authentication type must vary b. For access to sensitive information system, authentication such as 2-factor authentication should be implemented. Authentication levels must be defined to include a combination of any two of the following authentication mechanisms: Level I : PIN number....
X X X X Extracts X X X X
X X X X Extracts X X X X
....utomatically reset if user accounts are revoked or disabled upon inactivity beyond 30 days of inactivity f. Password communication must on verified alternate channel such as SMS, email, etc. IA.IG11 • Default device credentials: The organization must ensure that default login credentials of devices such as routers, firewall, storage equipment etc, are changed prior to the deployment of such devices in the operational environment IA.IG12 • Monitoring and retention of logs: The organization must retain information pertaining to requests for user ID creation, user rights allocation, user rights modification, user password reset request and other instances of change or modification to user profile, as per audit and governance requirements IA.IG13 • Unsuccessful login attempts: The organization must monitor unsuccessful log- in attempts from each of the authentication mechanisms, to track for consecutive unsuccessful log-in attempts a. The user account must be disabled for a pre-defined limit post five unsuccessful log-in attempts b. A random alpha numeric text CAPTCHA should be introduced post second unsuccessfu....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... Authentication & authorization for access IA.G2 IA.G2 IA.G2 IA.G2 Password management IA.G3 IA.G3 IA.G3 IA.G3 Credential monitoring IA.G4 IA.G4 IA.G4 Provisioning personal devices and remote access IA.G5 IA.G5 IA.G5 IA.G5 Segregation of duties IA.G6 IA.G6 IA.G6 IA.G6 Access record documentation IA.G7 IA.G7 IA.G7 Linkage of logical and physical access IA.G8 IA.G8 Disciplinary actions IA.G9 IA.G9 IA.G9 IA.G9 Controls Operational requirement mapping IA.C1 IA.C1 IA.C1 IA.C1 Unique identity of each user IA.C2 IA.C2 IA.C2 IA.C2 User access management IA.C3 IA.C3 ....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... access management IA.IG3, IA.IG3 (a) to (d) IA.IG3, IA.IG3 (a) to (d) IA.IG3, IA.IG3 (a) to (d) IA.IG3, IA.IG3 (a) to (d) Access control policies IA.IG4, IA.IG4(a) to (d) IA.IG4, IA.IG4(a) to (d) IA.IG4, IA.IG4(a) to (d) IA.IG4, IA.IG4 (a),(b),(c) Need - to - know access IA.IG5, IA.IG5 (a) to (d) IA.IG5, IA.IG5 (a) to (d) IA.IG5, IA.IG5 (a),(b),(c) IA.IG5, IA.IG5 (a),(b) Review of user privileges IA.IG6 IA.IG6 IA.IG6 IA.IG6 Special privileges IA.IG7, IA.IG7 (a),(b),(c) IA.IG7, IA.IG7 (a),(b),(c) IA.IG7, IA.IG7 (a),(b),(c) IA.IG7, IA.IG7 (a),(b),(c) Authentication mechanism for access IA.IG8, IA.IG8 (a) to (d) IA.IG8, IA.IG8 (a) to ....
X X X X Extracts X X X X
X X X X Extracts X X X X
....hrough inappropriate account access and malicious transaction activity etc. which have implication such as information leakage resulting in misuse, financial loss and loss of reputation ii. Security monitoring and incident response management is a key component of an organization's information security program as it helps build organizational capability to detect, analyze and respond appropriately to an information breach which might emanate from external or internal sources b. Relevance of domain to information security i. The success of a security program and the value being delivered by security initiatives lies in the organization's responsiveness to an external attack and its ability to sense and manage an internal data breach ii. In the operating cycle of an organization, information is exchanged, processed, stored, accessed and shared. There are multiple ways through which the information may be exposed to unintended persons, it may be intentionally or unintentionally lost or external attackers may able to steal information. This requires continuous monitoring of operations to identify likely instances of information loss iii. I....
X X X X Extracts X X X X
X X X X Extracts X X X X
....stakeholders of incident management team, including reporting measures, escalation metrics, SLAs and their contact information SM.G7 • Incident management awareness and training: The organization must conduct educational, awareness and training programs as well as establish mechanism by virtue of which users can play an active role in the discovery and reporting of information security breaches SM.G8 • Communication of incidents: The organization must establish measures for effective communication of incidents along with its impact, steps taken for containment and response measures to all stakeholders including clients and regulators SM.G9 d. Security monitoring & incident management controls • Security incident monitoring: The organization must build capability to monitor activity over information assets and systems that are being used across its ecosystems SM.C1 • Incident management: The organization must define an information security incident management plan which includes process elements such as incident reporting, incident identification and notification, incident metrics based on the type of incidents, proc....
X X X X Extracts X X X X
X X X X Extracts X X X X
....session or terminal, file services such as file copying, search, log successful and unsuccessful log-in attempts, activities of privileged user-IDs, changes to user access rights, details of password changes, modification to software etc. a. The organization must ensure that time consistency is maintained between all log sources through mechanisms such as time stamping and synchronization of servers SM.C9 • Log information correlation: Organi7ation should ensure that a process is established for regular review and analysis of logs and log reports SM.C10 • Protecting log information: Periodic validation of log records, especially on system/application where classified information is processed/stored, must be performed, to check for integrity and completeness of the log records. a. Any irregularities or system/application errors which are suspected to be triggered as a result of security breaches, shall be logged, reported and investigated b. For sensitive network, all logs should be stored in encrypted form or place tamper proof mechanism for during creation / storing / processing logs SM.C11 • Deployment of ....
X X X X Extracts X X X X
X X X X Extracts X X X X
....cessary guidance on the security incident response and handling process. The procedure must be communicated to all employees, management and third party staff located at the organizations facility a. Organization should establish guidelines for prioritization of information security incidents based on - criticality of information on affected resources (e.g. servers, networks, applications etc.) and potential technical effects of such incidents (e.g. denial of service, information stealing etc.) on usage and access to information b. Organization should assign a category to each type of information security incident based on its sensitivity for prioritization of incidents, arranging proportionate resources, and defining SLAS for remediation services c. Organization must define disciplinary action and consequences in-case employee or authorized third party personnel are responsible for breach or triggering security incident by deliberate action d. Organization must define liability of third party entity in-case breach or incident originates due to deliberate action of such parties SM.1G2 • Incident identification: The organization mu....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... g. Remove user access or login to the system h. Ensure that incidents are reported in timely manner so that fastest possible remedial measures can be taken to reduce further damage to the IT assets SM.IG4 • Escalation processes: The organization must create and periodically update an escalation process to address different types of incidents and facilitate coordination amongst various functions and personnel during the lifecycle of the incident a. The escalation procedure must identify and establish points of contact, at various levels of hierarchy, both within the organization and with vendors and third parties responsible for hardware/ software b. Maintain an updated list containing details of points of contacts from all concerned departments and functions such as technical, legal, operations and maintenance staff, supporting vendors, including the system's hardware or software vendors, application developers, and security consultants etc. c. Establish procedure for incident notification to be shared with the above identified personnel, based on the type and severity of impact caused by the incident, in a timely manner ....
X X X X Extracts X X X X
X X X X Extracts X X X X
....hival, retention and disposal measures should be deployed as per the compliance requirements of the organization SM.IG8 • Log Information: Ensure that system logs contain information capture including all the key events, activity, transactions such as: a. Individual user accesses; b. Rejected systems, applications, file and data accesses; c. Attempts and Other failed actions; d. Privileged, administrative or root accesses; e. Use of identification and authentication mechanisms; f. Remote and wireless accesses; g. Changes to system or application configurations; h. Changes to access rights; i. Use of system utilities; j. Activation or deactivation Of security systems; k. Transfer of classified information l. Deletion and modification of classified information m. System crashes n. Unexpected large deviation on system clock o. Unusual deviation from typical network traffic flows p. Creation or deletion of unexpected user accounts q. Unusual time of usage r. A suspicious last time login or usage of a user....
X X X X Extracts X X X X
X X X X Extracts X X X X
....istrative and privilege accounts activity must also be maintained f. Log information must be protected from modification or unauthorized access SM.IG11 • Deployment of skilled resources: The organization must define the resources and management support needed to effectively maintain and mature an incident response capability a. Individuals conducting incident analyses must have the appropriate skills and technical expertise to analyze the changes to information systems and the associated security ramifications b. The organization must trains personnel in their incident response roles and responsibilities with respect to the information system c. The organization should incorporate simulated events into incident response training to facilitate effective response by personnel in crisis situations d. The organization should develop competencies in cyber forensics and investigations or seek support from authorized cyber investigation agencies SM.IG12 • Incident reporting: The organization must ensure that appropriate procedures are followed to enable reporting of incidents both by employees and partner agencie....
X X X X Extracts X X X X
X X X X Extracts X X X X
....sp; Security incident monitoring SM.C1 SM.C1 SM.C1 SM.C1 Incident Management SM.C2 SM.C2 SM.C2 SM.C2 Incident identification SM.C3 SM.C3 SM.C3 SM.C3 Incident evaluation SM.C4 SM.C4 SM.C4 SM.C4 Escalation process SM.C5 SM.C5 SM.C5 SM.C5 Breach information SM.C6 SM.C6 SM.C6 SM.C6 Configuring devices for logging SM.C7 SM.C7 SM.C7 SM.C7 Activity logging SM.C8 SM.C8 SM.C8 SM.C8 Log information SM.C9 SM.C9 SM.C9 SM.C9 Log information correlation SM.C10 SM.C10 SM.C10 SM.C10 Protecting log information SM.C11 SM.C11 SM.11 SM.C11 Deployment of....
TaxTMI