PAKISTAN CLOUD FIRST POLICY for a subset of highly sensitive information that requires such protection and different security for products or services for other less sensitive information. The data can be classified by PSE as outlined by the Government of Pakistan and the guidelines issued by the Cloud Office in this regard. Annex-D: Data Classification Guidelines Annex-E: Cloud Selection Matrix 9.8 Security Framework Information Security is a set of practices to keep the data secure from unauthorized access, alterations, disclosure, disruption, or destruction whether the data is at rest, in motion or in processing. It is intended to ensure confidentiality, integrity, and security of the data. In a traditional data center, the organization itself is responsible for security across the entire operating environment. In a cloud environment, the security of the contracted cloud solution is shared between the contracting organization and the CSP. Each party maintains complete control over the assets, processes, and functions they own. The responsibilities of each party vary depending on the services procured and how those services are integrated into the overall environment. Both parties should ensure that the confidentiality, integrity, and availability of the data is maintained in this shared responsibility model. The use of any cloud service must remain compliant with applicable laws and regulations of Pakistan. Data classification is often designed together with information security requirements that are appropriate for managing each level of information. The cloud model that hosts the classified data must meet security requirements for that model. This policy mandates the Cloud Office to define security baselines, based on domestic and international standards, for different cloud models designated to host different data classes for PSE. The CSP and the PSE must maintain utmost integrity to protect the data and meet the security requirements set forth by the Cloud Office and/or any other relevant authority. The failure to satisfy any of the liabilities or obligations shall constitute a breach. Any data breach must be disclosed to the Cloud Office and any other relevant authorities as soon as the breach is discovered. Cloud Office and/or other relevant authorities, as determined in applicable regulations, may seek incident reports and determine appropriate response measures. In addition to meeting baseline security standards, audits and security monitoring mechanisms must be in place to ensure cloud services meet the data integrity, confidentiality requirements and that there have been no data breaches, and that the data and workloads are continuously available. Procurement Government procurement is a very relevant aspect of the development of cloud computing. PSE must consider cloud services for all of their new ICT procurement decisions. Any new ICT procurement decision to select services except cloud must have approval by the Cloud Office. Moreover, PSE will also seek approval from Cloud Office to host data on private cloud and will have to demonstrate the need for hosting on private cloud. Similarly, an organization intending to establish its own Private Cloud must have approval of the Cloud Office. Upon the government approval of this policy, the selection of cloud-based ICT will be prioritized in new ICT procurement. This will apply to infrastructure, hardware, software, information security, licensing, storage, and provision of data, as well as services like security, development, virtualisation, Page 12 of 21

Select target paragraph3