National Information Security Policy and Guidelines | Ministry of Home Affairs
administrative and technical arrangements. The IT initiatives of an organization need to be
revitalized to incorporate the principles of information security. The disciplines of security,
presented in this document, need to be carefully and diligently implemented
1.5. Information Security – focus areas
1.5.1. Managing scale and complexity: The increasing scale and complexity of organizations requires
a more coordinated and collaborative security approach. The information age demands right
proportions of security and requires graduation of security from a technical specialty to an
operational strategy. The scope and reach of security function has been expanding with
innovative and extensive use of IT for operational transactions, changing the nature of IT
infrastructure and the ability of threats that impact the security posture of an organization in
different directions and at different layers. Organization should be well equipped to
overcome these aspects establish some key objectives which demonstrate its commitment to
security
1.5.2. Alignment of security with processes and functions: The ministries, departments, agencies
and their subordinate organizations need to distinguish between security related operational
tasks from strategic security tasks. They need to estimate all security elements which are
distributed across the organizational ecosystem. This requires significant efforts in building
security characteristics and aligning the security function with organizational processes and IT,
thereby ensuring that security hygiene is reflected across the organization. The management
needs to focus its efforts on helping the organization identify enterprise information assets,
processes and information resources and the commensurate protection required to secure
them. To achieve this, the security function needs to work in close consultation and
coordination with the ministries, departments, agencies and their subordinate organizations
and sub functions to conduct risk assessments, and help them articulate the confidentiality,
integrity and availability requirements of their resources, and develop appropriate security
practices to ensure non-repudiation, accountability, authenticity and due authorization for
information handling
1.5.3. Compliance with laws and regulations: The responsibilities of, and the extent of the role of
security function within an organization is expanding; crossing the traditionally defined
boundaries of IT, and covering all horizontal and vertical functions of ministries/ departments/
agencies/ organizations. Based on the nature of work and information handled, each
horizontal and vertical function of an organization may need to comply with several laws and
regulations. The Secretary/ the top management needs to drive security in all organizations
functions and should promote adequacy of role & responsibility and efficacy of skills within its
operational units. This will help ensure compliance with information security laws, regulations,
standards, and guidance which are applicable to different departments and units, breach of
which poses a severe threat not only to the organization's reputation, but also towards
national security and internal security of the nation
1.5.4. Formulating effective security functions and divisions: Meeting the information security
needs, necessitates ministries, departments, agencies and their subordinate organizations to
focus on effective information security practices and functions which integrate security into
the strategic and daily operations of an organization, focuses more on information-centric
security strategy and ensures that security is part of the design principle and maturity of
NISPG - Version 5.0
Restricted
Page 17