National Information Security Policy and Guidelines | Ministry of Home Affairs
organizations, rather than a technical function carried out by the IT system administrators
alone
1.3.1.2. Protection from interruption in services: Ineffective security measures due to inadequate
budget/commitment or inflexibility of the ministries, departments, agencies and their
subordinate organizations to obtain advanced security capability, may cause disruption of
vital services/ offerings. Information is one of the most important assets of an organization.
Ensuring the confidentiality, integrity, and availability of this strategic asset allows
ministries, departments, agencies and their subordinate organizations to carry out their
objectives and realize their goals in a responsible manner
1.3.1.3. Non-availability of information: Risks to operations can arise through a variety of sources,
in some cases resulting in damage to infrastructure and the complete shutdown of the
services. For example, loss of all Internet connectivity, denial of service attacks, APTs,
ransom-ware, physical theft etc and environmental factors (e.g., power outages, floods,
and fires) can result in a loss of availability of key / strategic information, rendering any
ministries, departments, agencies and their subordinate organizations incapable of
achieving their objectives. Investment in security can assist in mitigating risks to operations
1.3.1.4. Financial loss due to disclosure/ theft of information: Inappropriate security measures
may have a huge impact on an organizations financial position. A data breach may not only
have direct financial loss, but will also dissolve the trust of residents, citizens, suppliers,
other government bodies etc. Further, in order to minimize the damage of the breach, the
organization may have to incur additional expenses
1.3.1.5. Non- compliance with legal/ regulatory requirements: The ministries, departments,
agencies and their subordinate organizations may face administrative and/or legal actions
for not complying with security advisories. Security is ultimately the responsibility of
executive management Secretary, Joint Secretary, Managing Directors, CEOs, Directors,
head of the department heads and other senior program officials of the ministries/
departments/ agencies/ organizations. The Management should deploy proactive security
to enable delivery of its services and enhance value of the organization, rather than
viewing security as an afterthought or as a reactionary mechanism to legislation,
regulation, security event and oversight
1.3.1.6. Investment and resource channelization disproportionate with risks: Ignoring security as a
design principle results in ad hoc investments, which more often than not focuses on
adding controls after the systems are made operational—or in the worst case, after an
organization has had a security breach or incident. The ministries, departments, agencies
and their subordinate organizations may not realize the specific performance gains and
financial savings by building security into systems as they are developed. However, these
save the organization from incurring huge unbudgeted costs in covering up post an incident
or breach
NISPG - Version 5.0
Restricted
Page 15