PAKISTAN CLOUD FIRST POLICY 9.3 Registration of Cloud Service Providers CSP that intend to host Open Data (Annex-E) are required to get registered with Cloud Office with minimal registration requirements to ensure provision of quality cloud services. Cloud Office will prioritise the ease of doing business for CSP and ensure business enabling environment for cloud adoption. 9.4 ICT Audits Audits are means to ensure that CSP provide adequate levels of protection for the treatment of information assets in accordance with the standards set by the Cloud Office. This policy mandates that CSP provide satisfactory audit reports or respond to audit requests made by the Cloud Office. Relevant authorities and other certified third parties will be able to monitor and perform audits to validate the contractually agreed controls. Moreover, the CSP should also employ internal audit mechanisms to ensure the prescribed requirements are adhered to. Audits can either be carried out at regular intervals or on as the need be. The Cloud Office can designate any auditing body to carry out the audits based on the criteria outlined by the Cloud Office. 9.5 Cloud Acquisition Office A Cloud Acquisition Office (CAO) will be established in the federal jurisdiction. Similarly, the province that adopts Cloud Policy in line with this policy will establish CAO in their jurisdictions to support provincial PSE in their transition to the cloud. CAO will facilitate PSE in designing, architecting, procuring, building, migrating, and managing their workloads and applications on the cloud. CAO will initiate call offs for the requirements of PSE. Only CSP accredited by the Cloud Office will be eligible to take part in call offs. CSP with the most advantageous offering will be selected in the call off. SLA will be signed between the CSP and PSE accordingly. Any breach of the SLA between PSE and CSP will be reported to CAO by the PSE. CAO will report continued serious non-compliance of SLA by CSP to Cloud Office. Apart from other remedies available to PSE, the Cloud Office will take appropriate action depending upon the nature and seriousness of non-compliance. 9.6 Restrictions on Investments in Fragmented ICT infrastructure With the approval of this policy GoP will require all PSE to review any projects which involve setting up a data center/ICT infrastructure/Server Room and will prioritise cloud-based solutions for any future ICT investments. Same provisions will apply on any projects in the public sector implemented via a third-party or donor agency. Federal Government will also advise provincial governments to share the same directives to its subordinate organizations to restrict investments on fragment ICT infrastructure and prioritise cloud. After 1st July 2022, all new ICT investments should adhere to the directions of Cloud Office. 9.7 Data Classification Data classification is the process of organizing data into categories so that the data can be utilized according to its sensitivity and criticality. PSE will have different types of information and that information will be associated with varying levels of sensitivity. Data classification framework provides a tool to classify and categorize data based on respective sensitivities and hence enable PSE to define controls against each classification category. A clear data classification framework is essential to ensure that the critical benefits of cloud computing are achieved cost-effectively. This ultimately enables decision-makers to better understand what types of data can be stored on each type of cloud model. Such a framework can be used when considering any type of cloud service as this will allow PSE to better align costs for bespoke security technology Page 11 of 21

Select target paragraph3