National Information Security Policy and Guidelines | Ministry of Home Affairs
10. Domains impacting information security
10.1. Overview
10.1.1. Alignment with security framework: While following the above framework, the ministries,
departments, agencies and their subordinate organizations should consider developing
strategy and competence in specific disciplines to enhance security. The NISPG has identified
eight core domains namely, network and infrastructure security, identity and access
management, physical security, application security, data security, personnel security, threat
& vulnerability management, security monitoring & incident management. Additionally, the
areas of security audit, security testing and business continuity, which cut across all domains,
have been covered as part of the guidelines. Further, guidelines for technology specific areas
such as virtualization, cloud computing, mobility and social media are provided in a separate
section
10.1.2. Achieving maturity in security domains: Domains mentioned above need to be understood
critically for security of classified information. Strategies for each of them, along with tactical
guidelines for implementation, and security controls are essential for making security robust.
The ministries, departments, agencies and their subordinate organizations should organize,
allocate and drive resources towards each of these security domains and strive to achieve
maturity over time to counter the increasing threats and attacks
10.1.3. Information security domains
10.1.3.1. Network and infrastructure security: The architectural plan of locating information in a
network arrangement and other infrastructure security arrangements such as internal and
external connections to information, protocols that are used to transfer information,
preparedness to withstand attacks etc. require specific consideration and treatment from
the perspective of securing information
10.1.3.2. Identity and access management: Sensitivity and criticality of information specifies the
requirements with respect to ability of an individual or group of users to access and
perform a set of operations on the said information. The increasing reliance on third
parties and external SMEs makes it imperative for the organization to secure itself against
risk arising from misuse of identities or additional or illegitimate access provided to the
users
10.1.3.3. Physical security: Organizations generally have multiple touch points from where
information can be accessed physically. To add to that, technology enables easy availability
of portable devices. This can defeat traditional physical screenings of individuals. With
more solutions and techniques becoming available in the market, physical security
concepts are also evolving, establishing it as an important discipline for protecting
information security. While it focuses more on restriction to physical intrusion,
technological solutions provide means to raise alarms by detecting anomalies and patterns
of information being accessed which help in detection and containment of information
security incidents
10.1.3.4. Application security: The primary objective of application security is to secure information
as it is processed, transferred or stored during the lifecycle of an application. The
NISPG - Version 5.0
Restricted
Page 30