File No: 2(35)/2011-CERT-In Ministry of Communication and Information Technology Department of Electronics and Information Technology Indra management plan, proactive security posture assessment and forensically enabled information infrastructure. 4) To ensure that all organizations earmark a specific budget for implementing cyber security initiatives and for meeting emergency response arising out of cyber incidents. 5) To provide fiscal schemes and incentives to encourage entities to install, strengthen and upgrade information infrastructure with respect to cyber security. 6) To prevent occurrence and recurrence of cyber incidents by way of incentives for technology development, cyber security compliance and proactive actions. 7) To establish a mechanism for sharing information and for identifying and responding to cyber security incidents and for cooperation in restoration efforts. 8) To encourage entities to adopt guidelines for procurement of trustworthy ICT products and provide for procurement of indigenously manufactured ICT products that have security implications. . Creating an assurance framework 1) To promote adoption of global best practices in information security and compliance and thereby enhance cyber security posture. 2) To create infrastructure for conformity assessment and certification of compliance to cyber security certification, best IS practices, system audits, standards and Penetration guidelines testing (Eg. ISO / Vulnerability 27001 ISMS assessment, application security testing, web security testing). 3) To enable implementation of global security best practices in formal risk assessment and risk management management processes, business continuity management and cyber crisis plan by all entities within Government and in critical sectors, to reduce the risk of disruption and improve the security posture. 4) To identify and classify information infrastructure facilities and assets at entity level with respect to risk perception for undertaking commensurate security protection measures. 5) To encourage secure application / software development processes based on global best practices. 6) To create conformity assessment framework for periodic verification of compliance to best practices, standards and guidelines on cyber security. Page 5 of 10

Select target paragraph3