National Information Security Policy and Guidelines | Ministry of Home Affairs A. Version Control Version Number Version Details Identifier Date 1.0 Final Draft Final draft 17 January 2014 1.1 Final Draft Additional annexures added to Final Draft 19 February 2014 Change 1: Annexure added – Mapping Of Guidelines and Controls Mentioned In the National Information Security Policy Change 2: Annexure added – Mapping of ISO27001:2013 with NISP controls Change 3: Annexure added – Mapping of NISP Guidelines & Controls with NIST Cyber Security Framework 2.0 Final Draft Change 1: Annexure added – Information Security Control Matrix 21 February 2014 Change 2: Revision of guideline titles for G11, G18, G30, G32, G37, G51, G54, G61, G62 Change 3: Revision of guideline text for G1, G10, G11, G13, G36 Change 4: Revision of control titles for C9, C11, C12, C15, C33, C36, C45, C50, C69, C76, C78, C99, C101, C102, C106, C121, C122, C123 Change 5: Revision of control text for C18, C26, C100 2.1 Final Draft Added section 1.5 - Information security – focus areas 21 March 2014 Added section 3.3 - National information security policy and guidelines review and update Revision of text of section 4 - Scope Added section 6.2 - Security Risk Assessment Revision of title for section 6.3 as Principles for establishing security framework NISPG - Version 5.0 Restricted Page 9

Select target paragraph3