File No: 2(35)/2011-CERT-In
Ministry of Communication and Information Technology
Department of Electronics and Information Technology
Indra
management
plan, proactive security posture assessment
and forensically enabled
information infrastructure.
4)
To ensure that all organizations earmark
a specific budget for implementing
cyber
security initiatives and for meeting emergency response arising out of cyber incidents.
5)
To provide fiscal schemes and incentives to encourage entities to install, strengthen
and upgrade information infrastructure with respect to cyber security.
6)
To prevent occurrence
and recurrence of cyber incidents by way
of incentives for
technology development, cyber security compliance and proactive actions.
7)
To establish a mechanism for sharing information and for identifying and responding
to cyber security incidents and for cooperation in restoration efforts.
8)
To encourage entities to adopt guidelines for procurement of trustworthy ICT products
and provide for procurement of indigenously manufactured
ICT products that have
security implications.
. Creating an assurance framework
1)
To promote adoption of global best practices in information security and compliance
and thereby enhance cyber security posture.
2)
To create infrastructure for conformity assessment and certification of compliance to
cyber
security
certification,
best
IS
practices,
system
audits,
standards
and
Penetration
guidelines
testing
(Eg.
ISO
/ Vulnerability
27001
ISMS
assessment,
application security testing, web security testing).
3)
To enable implementation of global security best practices in formal risk assessment
and risk management
management
processes, business continuity management
and cyber crisis
plan by all entities within Government and in critical sectors, to reduce
the risk of disruption and improve the security posture.
4)
To identify and classify information infrastructure facilities and assets at entity level
with
respect
to risk perception
for undertaking
commensurate
security
protection
measures.
5)
To encourage secure application / software development processes based on global
best practices.
6)
To create conformity assessment framework for periodic verification of compliance to
best practices, standards and guidelines on cyber security.
Page 5 of 10