Strategy 2020 • Adopt a risk-based approach by promoting the development of lightweight, agile, and dynamism mechanism for product testing that can co-exist with well-established schemes like common-criteria • Promote and incentivize the public and private investment in testing labs and infrastructure and skill development that can serve both domestic and export market requirements • Leverage the country's leadership in semiconductor design, ERnD (Engineering Research and Design) and emerging destination for deep-tech innovation for driving supply-chain security agenda globally at strategic, tactical and technical levels Critical Information Infrastructure Protection: The increased focus of cyberattacks, systematically planned and executed by non-state as well as state actors, to the target CII sectors causing more substantial or kinetic impact, demand concerted and smart strategies. • The focus of the efforts for CII protection should be to ensure the delivery of essential services even in the time of the attack, assuring the economic growth, and promising safety of the citizens • Empowering security leadership, ensuring adequate resources with it, and making it independent from routine ICT and business operations. Moreover, by devising specific responsibility for the SCADA/OT security and integrating with enterprise security. • Developing regulatory capabilities, wherever possible, that would further development of more contextual and objective norms and guidance • Augmenting the due diligence to draw technology profile of the CII sectors by closely monitoring the digitization and technology adoption, evaluating devices and solutions planned to deploy for the security, and maintaining a repository of vulnerabilities and exploits likely to affect them • Harmonizing national security efforts to make the compliance more productive and effective for the organizations falling in the CII • Adopting differentiated approaches that cater to specific requirements of the plant, transport, distribution, and retail deployment of SCADA/OT solutions to ensure risk-based treatment, specific solutions, and ensure proportionate actions at the desired level • Mandating a security-by-design culture in the technical transformation, however, facilitating that with investing in the aggregate level efforts of security evaluation and testing devices, issuing guidance and directives, and by notifying reference architectures • Promotion of innovation and co-creation for the development of SCADA/OT security solutions by incentivizing user enterprises, providing funding support to the start-ups and incubators working in the area, and creating a conducive environment for commercialization of the research work A NASSCOM® Initiative

Select target paragraph3