National Information Security Policy and Guidelines | Ministry of Home Affairs 10. Domains impacting information security 10.1. Overview 10.1.1. Alignment with security framework: While following the above framework, the ministries, departments, agencies and their subordinate organizations should consider developing strategy and competence in specific disciplines to enhance security. The NISPG has identified eight core domains namely, network and infrastructure security, identity and access management, physical security, application security, data security, personnel security, threat & vulnerability management, security monitoring & incident management. Additionally, the areas of security audit, security testing and business continuity, which cut across all domains, have been covered as part of the guidelines. Further, guidelines for technology specific areas such as virtualization, cloud computing, mobility and social media are provided in a separate section 10.1.2. Achieving maturity in security domains: Domains mentioned above need to be understood critically for security of classified information. Strategies for each of them, along with tactical guidelines for implementation, and security controls are essential for making security robust. The ministries, departments, agencies and their subordinate organizations should organize, allocate and drive resources towards each of these security domains and strive to achieve maturity over time to counter the increasing threats and attacks 10.1.3. Information security domains 10.1.3.1. Network and infrastructure security: The architectural plan of locating information in a network arrangement and other infrastructure security arrangements such as internal and external connections to information, protocols that are used to transfer information, preparedness to withstand attacks etc. require specific consideration and treatment from the perspective of securing information 10.1.3.2. Identity and access management: Sensitivity and criticality of information specifies the requirements with respect to ability of an individual or group of users to access and perform a set of operations on the said information. The increasing reliance on third parties and external SMEs makes it imperative for the organization to secure itself against risk arising from misuse of identities or additional or illegitimate access provided to the users 10.1.3.3. Physical security: Organizations generally have multiple touch points from where information can be accessed physically. To add to that, technology enables easy availability of portable devices. This can defeat traditional physical screenings of individuals. With more solutions and techniques becoming available in the market, physical security concepts are also evolving, establishing it as an important discipline for protecting information security. While it focuses more on restriction to physical intrusion, technological solutions provide means to raise alarms by detecting anomalies and patterns of information being accessed which help in detection and containment of information security incidents 10.1.3.4. Application security: The primary objective of application security is to secure information as it is processed, transferred or stored during the lifecycle of an application. The NISPG - Version 5.0 Restricted Page 30

Select target paragraph3