National Information Security Policy and Guidelines | Ministry of Home Affairs Disclaimer The Ministry of Home Affairs (MHA), Government of India, is aware of the cyber security policies, guidelines, and standards as identified and practiced by various government organizations in India. The role of MHA is specialized and focuses on establishing guidelines to help secure the “information” which may impact internal security and national security. These guidelines are based on the analysis of existing global security standards, and frameworks; and the emerging trends and discourse in the wake of persistent threats, and cyber-attacks on critical infrastructure of nations globally. The scope of MHA’s “National Information Security Policy & Guidelines” encompasses Government and Public Sector organizations and associated entities and third parties, for protecting the information under their control or ownership during information’s life-cycle including creation, storage, processing, accessing, transmission, destruction etc. The objective of this document is to improve the information security posture of an organization possessing any information, including classified information, and does not restrict organizations from adopting additional stringent practices over and above these guidelines. Organizations may evaluate various additional measures for the security of information they possess for protecting their information depending upon the sensitivity, criticality and importance of such information in the overall Internal Security and National Security interest of the country. NISPG - Version 5.0 Restricted Page 1

Select target paragraph3