National Information Security Policy and Guidelines | Ministry of Home Affairs value and the context throughout its life cycle. The departments should ensure that there exists a structural thought process in designing information security initiatives, such that adequate measures are taken with respect to formation, grouping and arrangement of countermeasures for security of information. It is also important that adequate efforts are taken for integrating information security measures with the enterprise ICT architecture to address contemporary and changing threats to information. Moreover, an organization should have capability towards responsiveness to the new issues or threats through integrating internal and external intelligence measures, deployment of tools, techniques and methods in identifying threats, collaboration mechanisms which generate timely and desired response from other security and ICT infrastructure management processes. Finally, departments should have the ability to identify, alert, evoke responses and resolve a data breach in a timely manner. This requires integration with other security processes and ICT infrastructure management processes, arrangement and relationships with external parties or bodies and standardization of procedures defined and deployed for handling data breaches. To make all this possible, departments need to focus on establishing accountability through design and implementation of an ownership structure for information security, where tasks and responsibilities are clearly distributed with respect to administrative and technical arrangements required for information security. The way forward Increasing digitization of information, expanding exposure of government organizations due to connectivity and the use of external providers, rising dependence on the global ICT supply chain are posing serious threats to information security. Growing instances of cyber espionage involving serious information breaches, call for action at a higher level. The Government of India recognizes this challenge – more so in the context of national security. National Information Security Policy and Guidelines, which focuses on security of information possessed both by public (Government and PSUs) and private sector, is an important step towards achieving new age goals of national cyber security. The policy is directed to build and foster an ecosystem for information security in the organizations (operating in public as well as private domain) that addresses the National Security requirements. Joint Secretary (Cyber & Information Security Division) Ministry of Home Affairs, Government of India NISPG - Version 5.0 Restricted Page 8

Select target paragraph3