National Information Security Policy and Guidelines | Ministry of Home Affairs 1. Overview 1.1. Background 1.1.1. Traditionally, information available with the government has been safely managed by keeping it in paper records throughout its life cycle i.e. when it is created, stored, accessed, modified, distributed, and destroyed. This information could be strategic, demographical, historical, legal, or may contain financial statements, procedural documents, data of citizens, industry or resources etc. Even though the lifecycle of information remains the same in electronic documents, the methods to secure information in electronic environment are significantly different. The challenges, as with the information contained in paper format, remain of similar nature, namely the ability to categorize, protect, archive, discover, transmit and attribute information during its useful life and eventual destruction 1.1.2. Information and Communication Technology (ICT) has empowered the government to create generate, store, transmit, and access information with much ease and efficiency. However, the importance of incorporating effective, state-of-the-art information security measures is being realized now. The departments, agencies and divisions recognize the security concerns in the electronic environment and are creating policies to secure the information in all stages of information lifecycle. The government and its officers have tremendous experience in securing paper documents. For example, several manual methods such as use of catalogs and paper-based chain-of-custody logs help keep track of the locations of files within secure record rooms. It is also known that information in the paper format may be exposed to physical damage, fraud or modification which may be sometimes difficult to track. The government is aware of the benefits of electronic form of information - it has not only been able to identify and gain visibility over the type of information available with its various departments, and agencies, but also attribute changes or modification to this information to specific personnel, thus making it easier to categorize, archive, discover and attribute 1.1.3. The government organizations deploy a number of technologies and in the process access, store and analyze vast amount of information. While the ease of access to information in the electronic format has helped revitalize governance, there are a number of threats which are emerging and required to be tackled on top priority. Today, information has acquired critical status for regulatory initiatives, policies and strategies, e-Governance, user services, financial transactions; however, security threats are becoming more organized and targeted, which pose serious threats – and in the event of any compromise of information, it could lead to major threats to internal and national security, and/or embarrassment to the government. Information is the reason for empowerment as well as a concern of threat for government organizations and needs a specific and granular focus on information which is created, stored, processed, transacted or accessed. Additionally, the IT infrastructure of a government organization is getting significantly transformed through increasing use of technical innovations, work-flow applications, mobility and extension to allow its usage by other stakeholders, partners, and service providers from the private sector 1.1.4. Complexity of information is a big hurdle in managing and governing security, privacy and compliance. Each government process or project introduces a different level of complexity as a result of wide-ranging data transactions, involvement of multiple stakeholders, exposure to NISPG - Version 5.0 Restricted Page 13

Select target paragraph3