The following words used in the Information Technology Security Guidelines shall be interpreted as follows :-
shall: The guideline defined is a mandatory requirement, and therefore must be complied with.
should: The guideline defined is a recommended requirement. Non-compliance shall be documented and approved by the management. Where appropriate, compensating controls shall be implemented.
must: The guideline defined is a mandatory requirement, and therefore must be complied with.
may: The guideline defined is an optional requirement. The implementation of this guideline is determined by the organisation's requirement.