File No: 2(35)/2011-CERT-In Ministry of Communication and Information Technology Department of Electronics and Information Technology aki / processes products ekiee and in general specifically for addressing National Security requirements. To 7) improve visibility of the products of ICT integrity establishing by services and infrastructure for testing & validation of security of such products. 8) professionals skilled in cyber security in the next 5 To create a workforce of 500,000 years through capacity building, skill development and training. 9) To provide fiscal benefits to businesses for adoption of standard security practices and processes. 10) To enable protection of information while in process, handling, storage & transit so as to safeguard privacy of citizen's data and for reducing economic losses due to cyber crime or data theft. 11) To enable effective prevention, investigation and prosecution of crime cyber and enhancement of law enforcement capabilities through appropriate legislative intervention. 12) To create a culture of cyber security and privacy enabling responsible user behaviour & actions through an effective communication and promotion strategy. 13) To develop effective public private partnerships and collaborative engagements through technical and operational cooperation and contribution for enhancing the security of cyberspace. 14) To enhance global cooperation promoting by shared and understanding leveraging relationships for furthering the cause of security of cyberspace. IVs Strategies Creating a secure cyber ecosystem 1) To designate a National nodal agency to coordinate all matters related to cyber security in the country, with clearly defined roles & responsibilities. 2) To encourage all organizations, private and public to designate a member of senior management, as Chief Information Security Officer (CISO), responsible for cyber security efforts and initiatives. 3) To encourage all organizations to develop information security policies duly integrated with their business plans and implement such policies as per international best practices. Such policies should include establishing standards and mechanisms for secure information flow (while in process, handling, storage & transit), crisis Page 4 of 10

Select target paragraph3