Strategy 2020 • Calling for well-thought governance process for timely resolution of identified issues and non-conformances • Develop regulatory capabilities, wherever possible, to broaden the reach of audit and assurance to sectors and targets emerging as a target for cyberattacks Incident/Crisis Management: The best-invested security program would not be spared from the possibility of an incident that could lead to significant crises. Science, process innovation, and technology contributing a lot in identifying and managing the incidents and handles resultant crises more predictably and productively. • Promoting the efforts for continuous identification and inventorization of the scenarios. Prioritizing them to ascertain which one leads to the significant ramification • Advocating scenarios planning of incident and crisis management plan devising roles and responsibilities for its execution • Conducting scenario planning and simulation exercises: o Scaling up the effort of cybersecurity drill to extend its reach and include real-life scenarios o Advocating the enterprise-level exercises for clarity on what incident cause the more significant ramification and requiring national attention o Calling for simulation exercises for critical sectors: at the levels of enterprise, industry sector, and national, within and cross-sections o Inter-country simulation exercises for cross-border scenarios • Ensuring the knowledge gained from the incidents and crises maintained for its productively managing future incidents • Promoting the use of state-of-art threat information sharing mechanisms, threat intel gathering, threat hunting operations, and security research to identify the possible weakness and exploitations • Promoting the use of contemporary technology for identifying incident, timely notifications, ensuring desired actions, dissemination of actionable intelligence, and managing the process in an effective way • Promoting participation in the global work and communities that engaged in incident categorization, finding IOC and IOAs of new attacks, and suggesting procedural steps Data Security and Governance: Foundations of the digitization are based on data-centric products and services. There is a significant rise in digitizing records, collecting data, enriching decisions with data, finding new ways and ideas of making use of data, and sharing it to serve other purposes. National cybersecurity strategy, hence, should emphasize enhancing the data governance in the country to systematize the security of data. A NASSCOM® Initiative

Select target paragraph3