National Information Security Policy and Guidelines | Ministry of Home Affairs optimized implementation of security, organizations need to weigh their strategic and financial options, establish a policy framework to set directions, define or comply with standards for ensuring baseline, establish procedures for ensuring consistency of operations and issue guidelines for implementation which must be carried out in spirit, and not just for the sake of obtaining a certificate. The compliance to the defined Information Security (IS) processes/ guidelines needs to be periodically audited both by internal and external auditors. Organizations are yet to awaken completely to embrace these challenges and incorporate measures and align their efforts to the cause of national security. The drivers for security go beyond securing ICT assets and protection of intellectual property rights (IPRs), where public and private entities have invested the bulk of their resources and efforts. Cyber Security and National Security require adequate priority and attention from organizations, beyond their usual areas of focus. Information security policy measures should address the requirements of legal framework, provide strategic measures and develop a mechanism to address various problems related to standards, procedures and guidelines. The policy needs to be aligned to the requirements of National Security, Cyber Security, IPR and Privacy protection. The National Information Security Policy and Guidelines Ministry of Home Affairs (MHA) has been entrusted with the responsibility of coordinating and overseeing information security initiatives of public as well as private sector. It is empowered to create a National Information Security Policy and Guidelines (NISPG), define procedures for handling information and issue guidelines for security of classified information assets. Accordingly, a Cyber Security Committee under the chairmanship of Joint Secretary, MHA with members from other stakeholder organizations was formed for this purpose. However, draft guidelines on protection of information in cyberspace and codification and classification (of electronic documents), prepared by this committee was not found to be comprehensive. In view of the fact that MHA and Intelligence Bureau (IB) do not have in-house expertise to handle a highly technical and advanced subject like this, it was proposed to outsource the work to National Institute of Smart Governance (NISG)/Data Security Council of India (DSCI) to develop a robust and comprehensive policy document, given DSCI’s experience in developing the DSCI Security Framework (DSF©), which was formulated in consultation with the Indian Industry which has experience in offering secure IT solutions to clients in over 90 countries, and DSCI’s engagement with International Standards Organization (ISO) in the development of global security standards The work plan for creation of NISPG included a study of existing laws, regulations and practices within the Government of India, international best practices followed worldwide and security requirements of various regulatory bodies. A review of global best practices, frameworks and information security standards was undertaken to understand and incorporate global learnings and align the developed practices with the same. Two workshops involving senior representatives from about 40 public sector organizations and Industry were also conducted, in addition to receiving their inputs over email. Based on learnings from these frameworks, emerging disciplines, and viewpoint of the industry, specific guidelines and detailed control objective and statements have been developed. This policy document will supplement the existing guidelines issued by Deity, NIC, IB and NTRO for the security of ICT infrastructure, assets, networks, applications etc. and would serve as an extension to the existing Manual on Departmental Security Instructions of 1994, which primarily addresses the handling of the security of paper based information. NISPG - Version 5.0 Restricted Page 5

Select target paragraph3