National Information Security Policy and Guidelines | Ministry of Home Affairs
optimized implementation of security, organizations need to weigh their strategic and financial
options, establish a policy framework to set directions, define or comply with standards for ensuring
baseline, establish procedures for ensuring consistency of operations and issue guidelines for
implementation which must be carried out in spirit, and not just for the sake of obtaining a
certificate. The compliance to the defined Information Security (IS) processes/ guidelines needs to
be periodically audited both by internal and external auditors. Organizations are yet to awaken
completely to embrace these challenges and incorporate measures and align their efforts to the
cause of national security. The drivers for security go beyond securing ICT assets and protection of
intellectual property rights (IPRs), where public and private entities have invested the bulk of their
resources and efforts. Cyber Security and National Security require adequate priority and attention
from organizations, beyond their usual areas of focus. Information security policy measures should
address the requirements of legal framework, provide strategic measures and develop a mechanism
to address various problems related to standards, procedures and guidelines. The policy needs to be
aligned to the requirements of National Security, Cyber Security, IPR and Privacy protection.
The National Information Security Policy and Guidelines
Ministry of Home Affairs (MHA) has been entrusted with the responsibility of coordinating and
overseeing information security initiatives of public as well as private sector. It is empowered to
create a National Information Security Policy and Guidelines (NISPG), define procedures for handling
information and issue guidelines for security of classified information assets. Accordingly, a Cyber
Security Committee under the chairmanship of Joint Secretary, MHA with members from other
stakeholder organizations was formed for this purpose. However, draft guidelines on protection of
information in cyberspace and codification and classification (of electronic documents), prepared by
this committee was not found to be comprehensive. In view of the fact that MHA and Intelligence
Bureau (IB) do not have in-house expertise to handle a highly technical and advanced subject like
this, it was proposed to outsource the work to National Institute of Smart Governance (NISG)/Data
Security Council of India (DSCI) to develop a robust and comprehensive policy document, given
DSCI’s experience in developing the DSCI Security Framework (DSF©), which was formulated in
consultation with the Indian Industry which has experience in offering secure IT solutions to clients
in over 90 countries, and DSCI’s engagement with International Standards Organization (ISO) in the
development of global security standards
The work plan for creation of NISPG included a study of existing laws, regulations and practices
within the Government of India, international best practices followed worldwide and security
requirements of various regulatory bodies. A review of global best practices, frameworks and
information security standards was undertaken to understand and incorporate global learnings and
align the developed practices with the same. Two workshops involving senior representatives from
about 40 public sector organizations and Industry were also conducted, in addition to receiving their
inputs over email. Based on learnings from these frameworks, emerging disciplines, and viewpoint
of the industry, specific guidelines and detailed control objective and statements have been
developed. This policy document will supplement the existing guidelines issued by Deity, NIC, IB and
NTRO for the security of ICT infrastructure, assets, networks, applications etc. and would serve as
an extension to the existing Manual on Departmental Security Instructions of 1994, which primarily
addresses the handling of the security of paper based information.
NISPG - Version 5.0
Restricted
Page 5