In a recent cyber security audit conducted across various Ministries and Departments, critical oversights and non-conformities have emerged, raising concerns about the overall digital security posture of the government. The audit, spearheaded by the National Telecommunication and Information Security Board (NTISB), has shed light on recurring issues, including vulnerabilities in internal network connectivity with the internet, lax password management policies, and instances of credentials sharing.
The NTISB has responded to these findings by issuing a ‘Cyber Security Advisory – User Level Common Oversights.’ The key points highlighted in the advisory are as follows:
1. Connectivity of Internal Networks with the Internet:
The audit revealed that internal networks within various government entities were inadequately secured, allowing potentially unauthorized access points from the internet.
2. Ineffective Password Management Policy:
A major concern identified was the lack of a robust password management policy. The advisory emphasizes the need for stringent enforcement of password policies, with a minimum character length requirement, including at least one special character and one uppercase letter.
3. Credentials Sharing:
Instances of sharing login credentials, comprising usernames and passwords, were identified as a recurring issue. The advisory strongly discourages this practice, urging strict adherence to individualized access.
4. Device Control Mechanisms:
Inadequate device control mechanisms, especially concerning USBs, were observed. The advisory recommends a more rigorous policy to govern the use of USB devices after whitelisting.
Recommendations for Remedial Measures:
To mitigate these vulnerabilities and enhance cyber resilience, the NTISB suggests the following remedial measures:
1. Isolation of Internal Network Systems:
All internal-network-based IT systems and user terminals, including official correspondence systems, are advised not to be connected to the internet.
2. Enforcement of Password Policies:
Stringent enforcement of password policies is recommended, with a minimum character length requirement and guidelines against saving passwords in browsers or writing/pasting them on desks.
3. Credential Security:
Strict avoidance of credential sharing is stressed upon, with the advisory urging all individuals to safeguard their access information.
4. Secure Use of USBs:
After whitelisting, the use of separate USBs for official systems is recommended to ensure a secure and controlled environment.
5. Device Control Policy:
A strict device-control policy, particularly concerning USBs, should be implemented to prevent unauthorized data transfers.
6. Email Security Measures:
The forwarding of official emails to personal email accounts is strongly discouraged, emphasizing the importance of keeping sensitive information within secure channels.
The implementation of these recommendations is crucial to fortify the government’s cyber defenses and protect against potential cyber incidents. The NTISB emphasizes the collective responsibility of all appointments to adhere to these measures and contribute to a more secure digital environment.





