National Information Security Policy and Guidelines | Ministry of Home Affairs
Approach
This document elaborates baseline Information security policy and highlights the relevant security
concepts and best practices, which government ministries, departments, and organizations must
implement to protect their information. The policy recommends creation of a security division
within each government organization, with the responsibility of planning, implementing and
governing all tasks related with information security in a comprehensive and focused manner. The
security division is expected to perform risk analysis based on threat and risk assessment emanating
from the adoption of technology. Further, the document provides guidance and control objectives
aligned in eight main domains and six additional areas which form the core of information security
practices and frameworks globally. These domains are essential for implementation of an effective
information security program, since they address the specifics which have become essential for its
effectiveness. The contribution of each domain to the success of the information security program is
intertwined with the level of maturity and success of all the other domains. Thus, together they help
create a baseline for a robust information security program.
The following core domains have been covered as part of this document. These are:
1. Network and Infrastructure security
2. Identity, access and privilege management
3. Physical security
4. Application security
5. Data security
6. Personnel security
7. Threat and vulnerability management and
8. Security and incident management
Further, guidelines have been provided for technology specific ICT deployment and trends:
1. Cloud computing
2. Mobility and Bring Your Own Device (BYOD)
3. Virtualization
4. Social media
Additionally, guidelines for essential security practices have been provided:
1. Security testing
2. Security auditing
3. Business continuity
4. Open source technology
Each domain is supported by a brief introduction about its relevance to information security along
with an outline of the importance of establishing practices pertinent to that domain. This is
supported by essential guidelines which encompass various processes and procedures under which
the information may traverse during its lifecycle.
NISPG - Version 5.0
Restricted
Page 6