National Information Security Policy and Guidelines | Ministry of Home Affairs security practices acts as a key differentiator in service delivery. Formulating effective security function in the organization ensures integration and builds collaboration between security, IT and other organizations functions 1.5.5. Allocation of budgets: There is a need for an effective and responsive security organization that is competent and committed in managing the complexity of security affairs and aligned to departmental requirements. For that to happen there is a need for provisioning adequate budgetary commitments towards security. This will help security to act not only as deterrence but as also as an operational advantage. Globally, there are many studies which suggest that budget for security should be proportional to the size of the organization or proportional to its IT budget. On an average, globally the budget for security varies between 8-10% of the ICT budget. However there are various parameters which should be evaluated before defining the security budget, it may be the sensitivity of information that ministries, departments, agencies and their subordinate organizations possess, the amount of transactions through varied platform, involvement of third parties, etc. Ministries, departments, agencies and their subordinate organizations should ensure that security budgets should be based on reasonable analysis and risks to operations and the allocation should depend on threat scenarios and risk to information 1.5.6. Availability of security professionals and tools: Apart from investing in adoption of newer technology platforms for better business effectiveness, ministries, departments, agencies and their subordinate organizations should also be committed towards investment in hiring skilled resources, procuring tools or increasing the efforts of the existing workforce. In order to augment the existing skills and expertise, top executives should be flexible to outsource specialized activities/operations to Subject Matter Experts (SME’s) and be open to hire external consultants and experts post due security vetting. The ministries, departments, agencies and their subordinate organizations should also be flexible in changing procedural aspects of managing security and consult with the hired ICT organization to evaluate and implement effective security technologies and architecture 1.5.7. Building and fostering culture of information security: While protection of information is of paramount importance, ministries, departments, agencies and their subordinate organizations should support the broader aim of securing the enterprise. This requires fostering a culture of information security through commitment from top leadership who need to demonstrate the strategic nature and value of information to its workforce in the enterprise. This may be achieved by establishing the principles of protecting information assets for the organization, as a priority. The ministries, departments, agencies and their subordinate organizations should focus on imbibing a "risk-aware" culture across the ministries, departments, agencies and their subordinate organizations concerned, ensuring that key personnel fully understand the risk implications associated with their assets, processes and information NISPG - Version 5.0 Restricted Page 18

Select target paragraph3