National Information Security Policy and Guidelines | Ministry of Home Affairs 2. Purpose 2.1. Purpose of NISPG 2.1.1. The National Information Security Policy and Guidelines (NISPG), developed by the Ministry of Home Affairs once implemented, will help classify and protect the classified information possessed by ministries, departments, agencies and their subordinate organizations, and public sector undertakings. Breach of such classified information may have an impact on national security, or may cause unfavorable impact on internal security 2.1.2. This document elaborates baseline information security policy and highlights relevant security concepts and best practices, which government ministries, departments, agencies and their subordinate organizations should implement to protect their classified information 2.1.3. These guidelines will help ministries, departments, agencies and their subordinate organizations to establish minimum security processes and controls and devise appropriate information security programs. The ministries, departments, agencies and their subordinate organizations may need to apply enhanced security measures commensurate with risks identified with their specific operating environment and the information being handled by them 2.1.4. These guidelines will help organizations to focus on security objectives and strategy to protect their classified information, during every stage of information lifecycle such as creation, acquiring, storing, accessing, processing, transacting, retaining or disposal. These guidelines will help drive organizations towards designing, implementing and operating focused information security initiatives 2.1.5. The NISPG aims to provide: 2.1.5.1. Guidance to organizations to prioritize and focus attention and efforts in classification of information and securing such classified information 2.1.5.2. Guidance to security staff of ministries, departments, agencies and their subordinate organizations for deriving security measures and controls commensurate with the criticality and sensitivity of classified information 2.1.5.3. Guidance to drive security implementation NISPG - Version 5.0 Restricted Page 19

Select target paragraph3