Cyber Security Audit of Ministries Exposes Weaknesses That Could Lead to Data Leaks

Cyber Security audit of different Ministries and Departments has revealed repetitive critical oversights and non-conformities, particularly connectivity of internal networks with the internet, ineffective password management policy, and credentials sharing.

The National Telecommunication and Information Security Board (NTISB) has issued a ‘Cyber Security Advisory – User Level Common Oversights’ while saying that cyber security audit of different Ministries/Departments has revealed repetitive critical oversights/non-conformities, particularly the following:

  1. Connectivity of internal networks with the internet.
  2. Ineffective password management policy.
  3. Credentials sharing.
  4. Device control mechanisms are observed.
Recommendations

Following remedial measures to safeguard against falling prey to Cyber incidents are emphasized:

  1. All internal-network-based IT systems/user terminals (including official correspondence system) should not be connected to internet.
  2. Password policy be enforced on all systems. Minimum criteria should include 10x character length (at least 1x special and 1x upper case character).
  3. Passwords must not be saved in browsers nor written/pasted on desks. Clear desk/clear screen policy be ensured by all appointments.
  4. Sharing of credentials (user name/password) be strictly avoided.
  5. Separate USBs (after whitelisting) be used for official systems.
  6. Strict device-control policy, particularly on USBs be implemented.
  7. Forwarding of official e-mails to personal e-mail accounts be strictly avoided.


  • Govt employees who can hardly speak Urdu don’t even know what cyber security beast is. For them “conpooter” is an another planet thing. Better to replace the staff with good one.


  • Get Alerts

    Follow ProPakistani to get latest news and updates.


    ProPakistani Community

    Join the groups below to get latest news and updates.



    >