File No: 2(35)/2011-CERT-In Ministry of Communication and Information Technology Department of Electronics and Information Technology fone enti 7) To encourage entities all to periodically test and evaluate the adequacy and effectiveness of technical and operational security control measures implemented in IT systems and in networks. . Encouraging Open Standards 1) To encourage use of open standards to facilitate interoperability and data exchange among different products or services. 2) To promote a consortium of Government and private sector to enhance the availability of tested and certified IT products based on open standards. . Strengthening the Regulatory framework 1) To develop a dynamic legal framework and its periodic review to address the cyber security challenges arising out of technological developments in cyber space (such as cloud computing, harmonization mobile computing, with international periodic audit and encrypted services including frameworks and social those media) and its to Internet related governance. 2) To mandate evaluation of the adequacy and effectiveness of security of information infrastructure as may be appropriate, with respect to regulatory framework. 3) To enable, educate and facilitate awareness of the regulatory framework. . Creating mechanisms for security threat early warning, vulnerability management and response to security threats 1) To create National level systems, processes, structures and mechanisms to generate necessary situational scenario of existing and potential cyber security threats and enable timely information sharing for proactive, preventive and protective actions by individual entities. To operate a 24x7 National Level Computer Emergency Response Team (CERT-In) to function as a Nodal Agency for coordination of all efforts for cyber security emergency response and crisis management. CERT-In will function as an umbrella as organization in enabling creation and operationalization of sectoral CERTs as well facilitating communication and coordination actions in dealing with cyber crisis situations. To operationalise 24x7 sectoral CERTs for all coordination and communication actions within the respective sectors for effective incidence response & resolution and cyber crisis management. Page 6 of 10

Select target paragraph3