National Information Security Policy and Guidelines | Ministry of Home Affairs Capability to respond to new issues or threats through integrating internal and external intelligence measures, deployment of tools, techniques and methods in identifying threats, which generate timely and desired response from other security & IT management processes, must be established 6.3.2. Security division structure: The ministries, departments, agencies and their subordinate organizations must establish accountability and ownership structure for information security, where tasks are clearly distributed with respect to administrative and technical arrangements required for information security. The head of security must report directly to the head of the ministries, departments, agencies or organizations and not to the IT head. 6.3.3. Deployment of professionals and skill development: The ministries, departments, agencies and their subordinate organizations must ensure that trained professionals in the field of Information Security are deployed to address their Information Security initiatives, at appropriate levels. Further, adequate measures to train existing users, human resources, to acquaint them with best practices for securing information and align them with the overall objectives of the organization for protection of information and information assets must be undertaken at periodic intervals. Every new employee should go through the information security awareness program which could be organized in-house. Also every employee should be given training in information security atleast once every two years. 6.4. Security audit 6.4.1. Security audits: The ministries, departments, agencies and their subordinate organizations must conduct appropriate evaluation, testing and audits of all organizational structures, mechanisms, policies, procedures, technologies and controls to ensure their alignment with the implementation objectives of the information security policy and guidelines at regular intervals. Areas of improvement should be identified and a mechanism to improve the overall deployment of such structures, mechanisms, policies, procedures, technologies and controls should be undertaken 6.4.2. Identification and response to data breach: The ministries, departments, agencies and their subordinate organizations should develop the ability to identify, alert, evoke responses & resolve a data breach in timely manner 6.4.3. Coordination with agencies: The ministries, departments, agencies and their subordinate organizations should interact with relevant agencies in the domain of information security to gather and share intelligence about threats and vulnerabilities 6.5. Exception to implementation of recommended guidelines and controls 6.5.1. The ministries, departments, agencies and their subordinate organizations are expected to conduct a thorough risk assessment and use the practices outlined in this document to help implement a framework within the organization 6.5.2. The ministries, departments, agencies and their subordinate organizations must exercise its own discretion in customizing and adapting the guidelines mentioned in this document, while upholding the core objectives and principles of the NISPG. Further, the ministries, departments, agencies and their subordinate organizations are free to deploy relevant NISPG - Version 5.0 Restricted Page 23

Select target paragraph3