National Information Security Policy and Guidelines | Ministry of Home Affairs section 14.4.13 as C58 Added control on Vulnerabilities knowledge management in section 18.4.4 as C114 Added control on Sharing of log information with law enforcement agencies in section 19.4.5 as C129 Added control on Log information correlation in section 19.4.7 as C131 Added control Communication of incidents in section 19.4.14 as C138 Revision of guideline titles for G29, G30, and G32 Revision of guideline text for G42, G44 and G45 Revision of control titles for C6, C11, C73, C88, and C91 Revision of control texts for C25, C39, C42, C92, C96, C99, C100, C103, C107, C127, C133, C136, C137 Revised annexure 14 – Risk Assessment for information security Revised annexure 15 – Glossary Added Annexure 17 – Feedback received from various Ministries/ Departments on NISPG 4.0 Final Draft Addition of new domains/ areas - Social media, open source technology 26 July 2014 Addition of Information handling guidance in section 28 Realignment of section 20 and section 21 to present each area separately Addition of implementation guidelines to all domains/ areas Revision of Annexures 5.0 Final NISPG - Version 5.0 Draft Approved 11 March 2019 Restricted Page 11

Select target paragraph3