National Information Security Policy and Guidelines | Ministry of Home Affairs Approach This document elaborates baseline Information security policy and highlights the relevant security concepts and best practices, which government ministries, departments, and organizations must implement to protect their information. The policy recommends creation of a security division within each government organization, with the responsibility of planning, implementing and governing all tasks related with information security in a comprehensive and focused manner. The security division is expected to perform risk analysis based on threat and risk assessment emanating from the adoption of technology. Further, the document provides guidance and control objectives aligned in eight main domains and six additional areas which form the core of information security practices and frameworks globally. These domains are essential for implementation of an effective information security program, since they address the specifics which have become essential for its effectiveness. The contribution of each domain to the success of the information security program is intertwined with the level of maturity and success of all the other domains. Thus, together they help create a baseline for a robust information security program. The following core domains have been covered as part of this document. These are: 1. Network and Infrastructure security 2. Identity, access and privilege management 3. Physical security 4. Application security 5. Data security 6. Personnel security 7. Threat and vulnerability management and 8. Security and incident management Further, guidelines have been provided for technology specific ICT deployment and trends: 1. Cloud computing 2. Mobility and Bring Your Own Device (BYOD) 3. Virtualization 4. Social media Additionally, guidelines for essential security practices have been provided: 1. Security testing 2. Security auditing 3. Business continuity 4. Open source technology Each domain is supported by a brief introduction about its relevance to information security along with an outline of the importance of establishing practices pertinent to that domain. This is supported by essential guidelines which encompass various processes and procedures under which the information may traverse during its lifecycle. NISPG - Version 5.0 Restricted Page 6

Select target paragraph3