National Information Security Policy and Guidelines | Ministry of Home Affairs
security practices acts as a key differentiator in service delivery. Formulating effective security
function in the organization ensures integration and builds collaboration between security, IT
and other organizations functions
1.5.5. Allocation of budgets: There is a need for an effective and responsive security organization
that is competent and committed in managing the complexity of security affairs and aligned to
departmental requirements. For that to happen there is a need for provisioning adequate
budgetary commitments towards security. This will help security to act not only as deterrence
but as also as an operational advantage. Globally, there are many studies which suggest that
budget for security should be proportional to the size of the organization or proportional to its
IT budget. On an average, globally the budget for security varies between 8-10% of the ICT
budget. However there are various parameters which should be evaluated before defining the
security budget, it may be the sensitivity of information that ministries, departments, agencies
and their subordinate organizations possess, the amount of transactions through varied
platform, involvement of third parties, etc. Ministries, departments, agencies and their
subordinate organizations should ensure that security budgets should be based on reasonable
analysis and risks to operations and the allocation should depend on threat scenarios and risk
to information
1.5.6. Availability of security professionals and tools: Apart from investing in adoption of newer
technology platforms for better business effectiveness, ministries, departments, agencies and
their subordinate organizations should also be committed towards investment in hiring skilled
resources, procuring tools or increasing the efforts of the existing workforce. In order to
augment the existing skills and expertise, top executives should be flexible to outsource
specialized activities/operations to Subject Matter Experts (SME’s) and be open to hire
external consultants and experts post due security vetting. The ministries, departments,
agencies and their subordinate organizations should also be flexible in changing procedural
aspects of managing security and consult with the hired ICT organization to evaluate and
implement effective security technologies and architecture
1.5.7. Building and fostering culture of information security: While protection of information is of
paramount importance, ministries, departments, agencies and their subordinate organizations
should support the broader aim of securing the enterprise. This requires fostering a culture of
information security through commitment from top leadership who need to demonstrate the
strategic nature and value of information to its workforce in the enterprise. This may be
achieved by establishing the principles of protecting information assets for the organization,
as a priority. The ministries, departments, agencies and their subordinate organizations should
focus on imbibing a "risk-aware" culture across the ministries, departments, agencies and
their subordinate organizations concerned, ensuring that key personnel fully understand the
risk implications associated with their assets, processes and information
NISPG - Version 5.0
Restricted
Page 18