Strategy 2020
•
Calling for well-thought governance process for timely resolution of identified issues and
non-conformances
•
Develop regulatory capabilities, wherever possible, to broaden the reach of audit and
assurance to sectors and targets emerging as a target for cyberattacks
Incident/Crisis Management: The best-invested security program would not be spared from the
possibility of an incident that could lead to significant crises. Science, process innovation, and
technology contributing a lot in identifying and managing the incidents and handles resultant
crises more predictably and productively.
•
Promoting the efforts for continuous identification and inventorization of the scenarios.
Prioritizing them to ascertain which one leads to the significant ramification
•
Advocating scenarios planning of incident and crisis management plan devising roles and
responsibilities for its execution
•
Conducting scenario planning and simulation exercises:
o
Scaling up the effort of cybersecurity drill to extend its reach and include real-life
scenarios
o
Advocating the enterprise-level exercises for clarity on what incident cause the
more significant ramification and requiring national attention
o
Calling for simulation exercises for critical sectors: at the levels of enterprise,
industry sector, and national, within and cross-sections
o
Inter-country simulation exercises for cross-border scenarios
•
Ensuring the knowledge gained from the incidents and crises maintained for its productively
managing future incidents
•
Promoting the use of state-of-art threat information sharing mechanisms, threat intel
gathering, threat hunting operations, and security research to identify the possible weakness
and exploitations
•
Promoting the use of contemporary technology for identifying incident, timely notifications,
ensuring desired actions, dissemination of actionable intelligence, and managing the process
in an effective way
•
Promoting participation in the global work and communities that engaged in incident
categorization, finding IOC and IOAs of new attacks, and suggesting procedural steps
Data Security and Governance: Foundations of the digitization are based on data-centric
products and services. There is a significant rise in digitizing records, collecting data, enriching
decisions with data, finding new ways and ideas of making use of data, and sharing it to serve
other purposes. National cybersecurity strategy, hence, should emphasize enhancing the data
governance in the country to systematize the security of data.
A NASSCOM® Initiative