Strategy 2020
•
Emphasizing incorporation of cyber security in the larger public reskilling efforts for
widening pool of the workforce
•
Concerted efforts of building niche skills by promoting hosting of hackathons and
challenges, conducting hands-on workshops, focusing on technology development aspects,
and setting up simulations and cyber ranges
•
Special programs for capacity building of government and public sector enterprises
concentrating on technology, operations, governance, and leadership aspects
•
Creation of 'cyber security services' leveraging Indian Engineering Services to create a pool
of security leaders for government and public enterprises
•
Attracting bright young minds to the field of cyber security through awareness, targeted
campaigns, and providing enticing career opportunities. Run national programs for
transitioning non-computer science graduates/ post-graduates to cyber security, especially
from the areas like electronics and mathematics
•
Close monitoring of demand-supply gaps through continual research, study, and tracking
Supporting the efforts for closing diversity gaps in cyber security field
Audit and assurance: The security threat landscape is continuously evolving for more targeted,
advanced, and persistent attacks. On the other hand, digitization momentum is increasingly
increasing the digital footprint and hence exposures. The audit and assurance function need to be
overhauled to address scale, pace, and complexity.
•
•
Advocating a more nuanced approach for developing audit and assurance ecosystem for the
country Increasing robustness of auditor/ assessor empanelment process
o
Making the assessment standards or references more specific, granular, and
relevant to factor all key possible scenarios of compromises
o
Ensuring deployment of skilled resources on the audit, assessment, and assurance
projects
o
Making the assessment, audit and assurance process intelligent driven to measure
preparedness against the newly identified vulnerabilities and threats
o
Calling for continual monitoring and evaluation instead of one-off exercises
o
Advocating the use of technology for monitoring readiness, baseline
improvement, and risk quantification
o
Calling for regular training and skilling of audit professionals
o
Keeping a close watch on the new devices, solutions, and architectures deployed.
Notifying standards, practices, and guidelines for auditing them
Advocating the development of intelligence on assessment and audits for benchmarking and
security baseline monitoring
A NASSCOM® Initiative