National Information Security Policy and Guidelines | Ministry of Home Affairs
1.4. Need for an information-centric approach
1.4.1. While designing a strategy for security, information-centric approach in operational lifecycle
should be an important consideration. Information and its attributes such as its origin, creator,
nature of transaction, life, sensitivity, strategic importance and the operations performed on
the information are some of the factors which help identify security requirements.
Government ministries, departments, agencies and their subordinate organizations need to
establish a process of identification and discovery of information for each of its processes,
relationships and functions. The security posture has to be dynamic and should evolve with
change in the value of information, information access methods and threat ecosystem. The
capability of security processes and infrastructure to address information security should not
only cover the different layers of ICT infrastructure, but also address the extended
government ecosystem and new trends like mobility, big data and cloud computing. The
consideration of information security in the lifecycle of information is also important from
people, process and technical design perspective
Figure 1: Domains impacting information security
1.4.2. Information can be classified based on its category or type, sensitivity, value and the context
throughout its lifecycle. Ministries, departments, agencies and their subordinate organizations
should ensure that a structural thought process in designing information security initiatives
and measures is taken with respect to formation, grouping and arrangement of
countermeasures for security of information. Moreover, they should have capability for
responding to emerging threats by gathering intelligence on the nature of threats; deploying
tools, techniques and methods to identify threats, build collaboration mechanisms which
generate timely response from other security & IT infrastructure management processes
1.4.3. To make all this possible, organizations require a focused accountability and ownership
structure for information security, where tasks are clearly distributed with respect to
NISPG - Version 5.0
Restricted
Page 16