Cyber Security Byelaw, 2077 Chapter-2 Provisions Relating to General Security Standards and Practices 3. Licensee shall have an updated recorded copy of document where all its technological assets like hardware, software, and license are managed and segregated as per criticality, usage, location, versions, owner, purchase date, update date like details. 4. Licensee shall have its board approved ICT Security Policies for planning, organizing, directing, controlling and monitoring of information management systems. These ICT Security Policies shall be applied/ executed for efficient and effective management of People, Process and Technology. 5. Licensee shall review ICT Security Policies developed at least once a year. However such policies can also be reviewed frequently as per the need or as per major changes in organizational structure, infrastructure or process. 6. Licensee shall have clearly defined and updated organogram with roles and responsibilities for its personnel (system operators, system developers, network administrators, information owners, security officers, users etc.), which shall be reviewed periodically. 7. Licensee shall have employees' related policy addressing the following items. (i) Proper handling of social media. (ii) Usage of Official Devices. (iii) Usage of Personal devices. (iv) Proper handling of official emails/accounts and information. 8. Licensee shall have provision for access control and proper segregation of dedicated computing environment for highly sensitive systems. Also, Access controls shall be configured to ensure that users are restricted to Read, Write, Execute, Delete based on the organizational information access policy. 9. Licensee shall promote information security awareness throughout the organizations and arrange training and education to ensure that all related parties understand the risks, observe the security regulations and requirements, and confirm to security best practices. 10. Licensee shall adopt risk-based approach to identify, prioritize and address the security risks and consequences associated with vulnerabilities of information systems in a consistent and effective manner and determine the mitigation measures to reduce the risks to an acceptable level. Page 3 of 12

Select target paragraph3