Strategy 2020 • Preparing an aggregate level security baseline of the sector and monitor the progress in the collective improvement of the baseline by closely tracking of security controls, capabilities, solutions deployed, and security management practices • Promoting the efforts in developing advanced skills and expertise in SCADA/OT security, ensuring skilled resource deployment in the security function, and mandating that audit and assessment work to be carried by skilled resources only • Devising areas, depth, norms, frequency, and methods for the audit and assessment to ascertain the level of preparedness against the prevailing and evolving threats • Ensuring an advanced level of Product Security and Incident Response [PSRT] set up by the OEMs, and the solution providers of the sector to provide timely and speedier resolutions of vulnerabilities and incidents • Promoting the development of cyber insurance products that cater to the security risks of SCADA/OT environment Digital Payment: digitization of payment and financial transaction processing would be the prime driver of the digital economy. Careful and concerted efforts would be needed for securing high paced but innovative and experimental transformation of transaction processing. • Promoting exercise for mapping and modeling of: o the supply chain of transaction processing, o architectural ideas under experimentations o devices and platform deployed o type of entities participating in the processing of transactions o enabling technologies and stacks o payment flows and paths o types of interfaces o exchange of data and information • Advocating extensive and routine threat modeling exercises that factor the possible and disclosed vulnerabilities, weaknesses, exposures • Ensuring better coordination and harmonization in regulatory initiatives to enhance the level of preparedness in predictable ways • Promoting the adoption of the framework, architectures, and capabilities emerged in the technology ecosystem for improving the security posture • Promoting threat research and sharing of threat intelligence in a very productive and timely manner. Also, by enabling the sharing of data to make security decisions risk-based • Mandating advanced cybersecurity operations by the primary owners in the chain of transaction processing A NASSCOM® Initiative

Select target paragraph3