Strategy 2020 • Emphasizing incorporation of cyber security in the larger public reskilling efforts for widening pool of the workforce • Concerted efforts of building niche skills by promoting hosting of hackathons and challenges, conducting hands-on workshops, focusing on technology development aspects, and setting up simulations and cyber ranges • Special programs for capacity building of government and public sector enterprises concentrating on technology, operations, governance, and leadership aspects • Creation of 'cyber security services' leveraging Indian Engineering Services to create a pool of security leaders for government and public enterprises • Attracting bright young minds to the field of cyber security through awareness, targeted campaigns, and providing enticing career opportunities. Run national programs for transitioning non-computer science graduates/ post-graduates to cyber security, especially from the areas like electronics and mathematics • Close monitoring of demand-supply gaps through continual research, study, and tracking Supporting the efforts for closing diversity gaps in cyber security field Audit and assurance: The security threat landscape is continuously evolving for more targeted, advanced, and persistent attacks. On the other hand, digitization momentum is increasingly increasing the digital footprint and hence exposures. The audit and assurance function need to be overhauled to address scale, pace, and complexity. • • Advocating a more nuanced approach for developing audit and assurance ecosystem for the country Increasing robustness of auditor/ assessor empanelment process o Making the assessment standards or references more specific, granular, and relevant to factor all key possible scenarios of compromises o Ensuring deployment of skilled resources on the audit, assessment, and assurance projects o Making the assessment, audit and assurance process intelligent driven to measure preparedness against the newly identified vulnerabilities and threats o Calling for continual monitoring and evaluation instead of one-off exercises o Advocating the use of technology for monitoring readiness, baseline improvement, and risk quantification o Calling for regular training and skilling of audit professionals o Keeping a close watch on the new devices, solutions, and architectures deployed. Notifying standards, practices, and guidelines for auditing them Advocating the development of intelligence on assessment and audits for benchmarking and security baseline monitoring A NASSCOM® Initiative

Select target paragraph3