National Information Security Policy and Guidelines | Ministry of Home Affairs diverse set of infrastructure environments, networks, devices, platforms and information assets 1.2. Key areas of national concern for ministries/ departments/ agencies (management) 1.2.1. Meeting dynamic security threats: Protecting information has not typically been considered as a strategic element by the top level executives in the ministries/ departments/ agencies (management); even after promulgating various regulatory measures, global threats and many security incidents. Information security remains an afterthought, either as a line item or – even worse – not addressed at all by the top bureaucracy in the ministries/ departments/ agencies. The growing complexity of managing information security, rising exposure of an organization and close inter-linkage of Government information with the strategic security of the nation necessitates the elevation of the security function. 1.2.2. Creating visibility over activities and operations: The security threat environment is becoming more widespread and dangerous and it is important that ministries/ departments/ agencies have visibility over their activities, functions and operations. Security as a discipline has also evolved over a period of time. The stimuli have been many - the dynamic threat landscape, threats to national security, internal security concerns, strengthening regulatory regime, privacy issues, economic value of information, research & innovation, globalization, business models, emerging technologies, etc. 1.2.3. Intelligence gathering, knowledge management and skill development: For an organization to be secure in today’s technology driven work environment, it is important that it keeps track of all the latest developments in the field of information security – be it skills, technologies or services. An organization is required to provide strategic attention to security through commitment in all the facets of information security i.e. people, process and technology. It should be equipped with adequate knowledge, tools and techniques and human resources for gathering, assessing and presenting information security events to the top executive management levels in the ministries/ departments/ agencies. The aspects of designing, implementing and governing security although a key challenge for a ministries/ departments/ agencies, need to be addressed suitably by a framework for managing the affairs of security 1.3. Ministries/ Departments/ Information security Agencies/ Management commitment towards 1.3.1. Introduction: Information security program implementations often suffer due to inadequate resources—commitment of the ministries/ departments/ agencies, time, budget, human resources or expertise. By understanding the challenges of meeting compliance objectives, an organization can understand and appreciate the level of commitment required towards information security to overcome the obstacles and appreciate the gains achieved through implementing effective security practices. The following concerns emerge as executives in the ministries/ departments/ agencies decode the complexity and inter-linkage of security and performance: 1.3.1.1. Coverage of security risks: The foremost goal of an organization’s risk management process is to protect the organization, and its ability to perform its functions, not just protect its information and assets. Therefore, the security risk management process should be treated as an essential management function of the ministries/ departments/ agencies/ NISPG - Version 5.0 Restricted Page 14

Select target paragraph3