National Information Security Policy and Guidelines | Ministry of Home Affairs
value and the context throughout its life cycle. The departments should ensure that there exists a
structural thought process in designing information security initiatives, such that adequate
measures are taken with respect to formation, grouping and arrangement of countermeasures for
security of information. It is also important that adequate efforts are taken for integrating
information security measures with the enterprise ICT architecture to address contemporary and
changing threats to information. Moreover, an organization should have capability towards
responsiveness to the new issues or threats through integrating internal and external intelligence
measures, deployment of tools, techniques and methods in identifying threats, collaboration
mechanisms which generate timely and desired response from other security and ICT infrastructure
management processes. Finally, departments should have the ability to identify, alert, evoke
responses and resolve a data breach in a timely manner. This requires integration with other
security processes and ICT infrastructure management processes, arrangement and relationships
with external parties or bodies and standardization of procedures defined and deployed for handling
data breaches. To make all this possible, departments need to focus on establishing accountability
through design and implementation of an ownership structure for information security, where tasks
and responsibilities are clearly distributed with respect to administrative and technical
arrangements required for information security.
The way forward
Increasing digitization of information, expanding exposure of government organizations due to
connectivity and the use of external providers, rising dependence on the global ICT supply chain are
posing serious threats to information security. Growing instances of cyber espionage involving
serious information breaches, call for action at a higher level. The Government of India recognizes
this challenge – more so in the context of national security.
National Information Security Policy and Guidelines, which focuses on security of information
possessed both by public (Government and PSUs) and private sector, is an important step towards
achieving new age goals of national cyber security. The policy is directed to build and foster an
ecosystem for information security in the organizations (operating in public as well as private
domain) that addresses the National Security requirements.
Joint Secretary (Cyber & Information Security Division)
Ministry of Home Affairs, Government of India
NISPG - Version 5.0
Restricted
Page 8