National Information Security Policy and Guidelines | Ministry of Home Affairs capabilities in the form of tools, solutions etc. to help implement information security practices and its governance framework 6.5.3. The MHA, through its agencies, may seek compliance in the form of audit reports to demonstrate adherence to controls and guidelines specified in the NISPG from ministries, departments, agencies and their subordinate organizations 6.5.4. In case some guidelines and controls are not adhered to, ministries, departments, agencies and their subordinate organizations should be able to substantiate their stance by reproduction of appropriate documentation specifying at a minimum, the following parameters: 6.5.4.1. Reason for non-conformance to guidelines 6.5.4.2. Risk evaluation reports detailing the risks due to non-conformance 6.5.4.3. Additional controls implemented, if any 6.5.4.4. Timeline for introduction of recommended controls 6.5.5. Such instances should also be brought to the notice of the Information security steering committee (refer section 8) and a formal signoff should be undertaken in all cases, where guidelines specified under the NISPG are not followed NISPG - Version 5.0 Restricted Page 24

Select target paragraph3