National Information Security Policy and Guidelines | Ministry of Home Affairs
Capability to respond to new issues or threats through integrating internal and external
intelligence measures, deployment of tools, techniques and methods in identifying threats,
which generate timely and desired response from other security & IT management
processes, must be established
6.3.2. Security division structure: The ministries, departments, agencies and their subordinate
organizations must establish accountability and ownership structure for information security,
where tasks are clearly distributed with respect to administrative and technical arrangements
required for information security. The head of security must report directly to the head of the
ministries, departments, agencies or organizations and not to the IT head.
6.3.3. Deployment of professionals and skill development: The ministries, departments, agencies
and their subordinate organizations must ensure that trained professionals in the field of
Information Security are deployed to address their Information Security initiatives, at
appropriate levels. Further, adequate measures to train existing users, human resources, to
acquaint them with best practices for securing information and align them with the overall
objectives of the organization for protection of information and information assets must be
undertaken at periodic intervals. Every new employee should go through the information
security awareness program which could be organized in-house. Also every employee should
be given training in information security atleast once every two years.
6.4. Security audit
6.4.1. Security audits: The ministries, departments, agencies and their subordinate organizations
must conduct appropriate evaluation, testing and audits of all organizational structures,
mechanisms, policies, procedures, technologies and controls to ensure their alignment with
the implementation objectives of the information security policy and guidelines at regular
intervals. Areas of improvement should be identified and a mechanism to improve the overall
deployment of such structures, mechanisms, policies, procedures, technologies and controls
should be undertaken
6.4.2. Identification and response to data breach: The ministries, departments, agencies and their
subordinate organizations should develop the ability to identify, alert, evoke responses &
resolve a data breach in timely manner
6.4.3. Coordination with agencies: The ministries, departments, agencies and their subordinate
organizations should interact with relevant agencies in the domain of information security to
gather and share intelligence about threats and vulnerabilities
6.5. Exception to implementation of recommended guidelines and controls
6.5.1. The ministries, departments, agencies and their subordinate organizations are expected to
conduct a thorough risk assessment and use the practices outlined in this document to help
implement a framework within the organization
6.5.2. The ministries, departments, agencies and their subordinate organizations must exercise its
own discretion in customizing and adapting the guidelines mentioned in this document, while
upholding the core objectives and principles of the NISPG. Further, the ministries,
departments, agencies and their subordinate organizations are free to deploy relevant
NISPG - Version 5.0
Restricted
Page 23