Strategy 2020
•
Advocating a sound, agile, and efficient third-party security assurance mechanism
•
Promote the adoption of standards while selecting, evaluating, deploying, configuring, and
operating devices, solutions, and platforms. Leveraging India's leadership position for
shaping global standards impacting payment industry
•
Developing competent incident and emergency response capabilities for the financial sector
•
Promote responsible and timely disclosure of vulnerability and incident reporting for the
devices, solutions, and platforms deployed for transaction processing
•
Overhauling assurance system, making it more agile, threat aligned, and intelligence-driven
Promoting efforts and collaborations for making people aware of payment security in a targeted,
entrenched, and scalable manner
Sectoral preparedness: Digitization is increasingly leading to the verticalization of IT, where
every sector is evolving to verticalize technology stack for their requirements. Their digital
footprint is increasing, spreading the threat exposures. The sectors may not be ready or fall short
of handling security affairs impacting their prospects.
•
Profiling sectors, their digitization plan, architectural developments, technology adoption,
possible exposures, and likely ramifications, which can be used for ascertaining the priorities
for the interventions
•
Ensuring evaluation of sectors and specific companies in them, for their role in the critical
supply chain to identify possible ramifications to national cybersecurity from a security
breach
•
Providing special attention to the sectors that rely on the operating environment for
enhancing SCADA/OT/IoT security, and integrating that with organizational security
function
•
Keeping watch on sectoral cybersecurity preparedness through developing and maintaining
index and setting up a mechanism for continually monitoring exposures of members of the
sectors
•
Developing regulatory capabilities wherever possible to create and drive the agenda of
cybersecurity in the sectors and making them more contextual and objective to the sectoral
challenges
•
Promoting the development of frameworks, policies, guidance, and technical standards in the
sensitive sectors
•
Ensuring the development of security function and leadership in the companies, empowering
them, and by making the security function independent from routine IT and business
operations
•
Developing an audit, assurance, and assessment ecosystem in the sectors that measure the
level of preparedness and help to build risk management culture
A NASSCOM® Initiative