National Information Security Policy and Guidelines | Ministry of Home Affairs 1.4. Need for an information-centric approach 1.4.1. While designing a strategy for security, information-centric approach in operational lifecycle should be an important consideration. Information and its attributes such as its origin, creator, nature of transaction, life, sensitivity, strategic importance and the operations performed on the information are some of the factors which help identify security requirements. Government ministries, departments, agencies and their subordinate organizations need to establish a process of identification and discovery of information for each of its processes, relationships and functions. The security posture has to be dynamic and should evolve with change in the value of information, information access methods and threat ecosystem. The capability of security processes and infrastructure to address information security should not only cover the different layers of ICT infrastructure, but also address the extended government ecosystem and new trends like mobility, big data and cloud computing. The consideration of information security in the lifecycle of information is also important from people, process and technical design perspective Figure 1: Domains impacting information security 1.4.2. Information can be classified based on its category or type, sensitivity, value and the context throughout its lifecycle. Ministries, departments, agencies and their subordinate organizations should ensure that a structural thought process in designing information security initiatives and measures is taken with respect to formation, grouping and arrangement of countermeasures for security of information. Moreover, they should have capability for responding to emerging threats by gathering intelligence on the nature of threats; deploying tools, techniques and methods to identify threats, build collaboration mechanisms which generate timely response from other security & IT infrastructure management processes 1.4.3. To make all this possible, organizations require a focused accountability and ownership structure for information security, where tasks are clearly distributed with respect to NISPG - Version 5.0 Restricted Page 16

Select target paragraph3