National Information Security Policy and Guidelines | Ministry of Home Affairs organizations, rather than a technical function carried out by the IT system administrators alone 1.3.1.2. Protection from interruption in services: Ineffective security measures due to inadequate budget/commitment or inflexibility of the ministries, departments, agencies and their subordinate organizations to obtain advanced security capability, may cause disruption of vital services/ offerings. Information is one of the most important assets of an organization. Ensuring the confidentiality, integrity, and availability of this strategic asset allows ministries, departments, agencies and their subordinate organizations to carry out their objectives and realize their goals in a responsible manner 1.3.1.3. Non-availability of information: Risks to operations can arise through a variety of sources, in some cases resulting in damage to infrastructure and the complete shutdown of the services. For example, loss of all Internet connectivity, denial of service attacks, APTs, ransom-ware, physical theft etc and environmental factors (e.g., power outages, floods, and fires) can result in a loss of availability of key / strategic information, rendering any ministries, departments, agencies and their subordinate organizations incapable of achieving their objectives. Investment in security can assist in mitigating risks to operations 1.3.1.4. Financial loss due to disclosure/ theft of information: Inappropriate security measures may have a huge impact on an organizations financial position. A data breach may not only have direct financial loss, but will also dissolve the trust of residents, citizens, suppliers, other government bodies etc. Further, in order to minimize the damage of the breach, the organization may have to incur additional expenses 1.3.1.5. Non- compliance with legal/ regulatory requirements: The ministries, departments, agencies and their subordinate organizations may face administrative and/or legal actions for not complying with security advisories. Security is ultimately the responsibility of executive management Secretary, Joint Secretary, Managing Directors, CEOs, Directors, head of the department heads and other senior program officials of the ministries/ departments/ agencies/ organizations. The Management should deploy proactive security to enable delivery of its services and enhance value of the organization, rather than viewing security as an afterthought or as a reactionary mechanism to legislation, regulation, security event and oversight 1.3.1.6. Investment and resource channelization disproportionate with risks: Ignoring security as a design principle results in ad hoc investments, which more often than not focuses on adding controls after the systems are made operational—or in the worst case, after an organization has had a security breach or incident. The ministries, departments, agencies and their subordinate organizations may not realize the specific performance gains and financial savings by building security into systems as they are developed. However, these save the organization from incurring huge unbudgeted costs in covering up post an incident or breach NISPG - Version 5.0 Restricted Page 15

Select target paragraph3