PAKISTAN CLOUD FIRST POLICY
for a subset of highly sensitive information that requires such protection and different security for
products or services for other less sensitive information. The data can be classified by PSE as outlined
by the Government of Pakistan and the guidelines issued by the Cloud Office in this regard.
Annex-D: Data Classification Guidelines
Annex-E: Cloud Selection Matrix
9.8
Security Framework
Information Security is a set of practices to keep the data secure from unauthorized access, alterations,
disclosure, disruption, or destruction whether the data is at rest, in motion or in processing. It is intended
to ensure confidentiality, integrity, and security of the data.
In a traditional data center, the organization itself is responsible for security across the entire operating
environment. In a cloud environment, the security of the contracted cloud solution is shared between
the contracting organization and the CSP. Each party maintains complete control over the assets,
processes, and functions they own. The responsibilities of each party vary depending on the services
procured and how those services are integrated into the overall environment. Both parties should ensure
that the confidentiality, integrity, and availability of the data is maintained in this shared responsibility
model. The use of any cloud service must remain compliant with applicable laws and regulations of
Pakistan.
Data classification is often designed together with information security requirements that are
appropriate for managing each level of information. The cloud model that hosts the classified data must
meet security requirements for that model. This policy mandates the Cloud Office to define security
baselines, based on domestic and international standards, for different cloud models designated to host
different data classes for PSE. The CSP and the PSE must maintain utmost integrity to protect the data
and meet the security requirements set forth by the Cloud Office and/or any other relevant authority.
The failure to satisfy any of the liabilities or obligations shall constitute a breach. Any data breach must
be disclosed to the Cloud Office and any other relevant authorities as soon as the breach is discovered.
Cloud Office and/or other relevant authorities, as determined in applicable regulations, may seek
incident reports and determine appropriate response measures.
In addition to meeting baseline security standards, audits and security monitoring mechanisms must be
in place to ensure cloud services meet the data integrity, confidentiality requirements and that there
have been no data breaches, and that the data and workloads are continuously available.
Procurement
Government procurement is a very relevant aspect of the development of cloud computing. PSE must
consider cloud services for all of their new ICT procurement decisions. Any new ICT procurement
decision to select services except cloud must have approval by the Cloud Office. Moreover, PSE will
also seek approval from Cloud Office to host data on private cloud and will have to demonstrate the
need for hosting on private cloud. Similarly, an organization intending to establish its own Private Cloud
must have approval of the Cloud Office.
Upon the government approval of this policy, the selection of cloud-based ICT will be prioritized in
new ICT procurement. This will apply to infrastructure, hardware, software, information security,
licensing, storage, and provision of data, as well as services like security, development, virtualisation,
Page 12 of 21