File No: 2(35)/2011-CERT-In Ministry of Communication and Information Technology Department of Electronics and Information Technology RRR EEE To implement Cyber Crisis Management Plan for dealing with cyber related incidents impacting critical national processes or endangering public safety and security of the Nation, by way of well coordinated, multi disciplinary approach at the National, Sectoral as well as entity levels. 5) To conduct and facilitate regular cyber security drills & exercises at National, sectoral and entity levels to enable assessment of the security posture and level of emergency preparedness in resisting and dealing with cyber security incidents. . Securing E-Governance services )) To mandate implementation of global security best practices, business continuity management and cyber crisis management plan for all e-Governance initiatives in the country, to reduce the risk of disruption and improve the security posture. 2) To encourage wider usage of Public Key Infrastructure (PKI) within Government for trusted communication and transactions. 3) To engage information security professionals / organisations to assist e-Governance initiatives and ensure conformance to security best practices. . Protection and resilience of Critical Information Infrastructure ) To develop a plan for protection of Critical Information infrastructure and its integration with business plan at the entity level and implement such plan. The plans shall include establishing mechanisms for secure information flow (while in process, handling, storage proactive & transit), guidelines posture assessment security and standards, and crisis forensically management enabled plan, information infrastructure. 2) To Operate (NCIIPC) a 24x7 to National function as the Critical nodal Information Infrastructure critical for agency Protection Centre infrastructure information protection in the country. 3) To facilitate identification, prioritisation, assessment, remediation and protection of on the plan for protection of critical critical infrastructure and key resources based information infrastructure. 4) To mandate management implementation and cyber of global security crisis management best plan practices, business continuity by all critical sector entities, to reduce the risk of disruption and improve the security posture. 5) To encourage and mandate as appropriate, the use of validated and certified IT products. Page 7 of 10

Select target paragraph3