National Information Security Policy and Guidelines | Ministry of Home Affairs administrative and technical arrangements. The IT initiatives of an organization need to be revitalized to incorporate the principles of information security. The disciplines of security, presented in this document, need to be carefully and diligently implemented 1.5. Information Security – focus areas 1.5.1. Managing scale and complexity: The increasing scale and complexity of organizations requires a more coordinated and collaborative security approach. The information age demands right proportions of security and requires graduation of security from a technical specialty to an operational strategy. The scope and reach of security function has been expanding with innovative and extensive use of IT for operational transactions, changing the nature of IT infrastructure and the ability of threats that impact the security posture of an organization in different directions and at different layers. Organization should be well equipped to overcome these aspects establish some key objectives which demonstrate its commitment to security 1.5.2. Alignment of security with processes and functions: The ministries, departments, agencies and their subordinate organizations need to distinguish between security related operational tasks from strategic security tasks. They need to estimate all security elements which are distributed across the organizational ecosystem. This requires significant efforts in building security characteristics and aligning the security function with organizational processes and IT, thereby ensuring that security hygiene is reflected across the organization. The management needs to focus its efforts on helping the organization identify enterprise information assets, processes and information resources and the commensurate protection required to secure them. To achieve this, the security function needs to work in close consultation and coordination with the ministries, departments, agencies and their subordinate organizations and sub functions to conduct risk assessments, and help them articulate the confidentiality, integrity and availability requirements of their resources, and develop appropriate security practices to ensure non-repudiation, accountability, authenticity and due authorization for information handling 1.5.3. Compliance with laws and regulations: The responsibilities of, and the extent of the role of security function within an organization is expanding; crossing the traditionally defined boundaries of IT, and covering all horizontal and vertical functions of ministries/ departments/ agencies/ organizations. Based on the nature of work and information handled, each horizontal and vertical function of an organization may need to comply with several laws and regulations. The Secretary/ the top management needs to drive security in all organizations functions and should promote adequacy of role & responsibility and efficacy of skills within its operational units. This will help ensure compliance with information security laws, regulations, standards, and guidance which are applicable to different departments and units, breach of which poses a severe threat not only to the organization's reputation, but also towards national security and internal security of the nation 1.5.4. Formulating effective security functions and divisions: Meeting the information security needs, necessitates ministries, departments, agencies and their subordinate organizations to focus on effective information security practices and functions which integrate security into the strategic and daily operations of an organization, focuses more on information-centric security strategy and ensures that security is part of the design principle and maturity of NISPG - Version 5.0 Restricted Page 17

Select target paragraph3