National Information Security Policy and Guidelines | Ministry of Home Affairs 3. Document distribution, applicability and review 3.1. Distribution 3.1.1. The MHA shall distribute this document to all ministries, who will be further responsible for circulating the same to their departments, agencies and subordinate organizations and bodies including public sector undertakings (PSUs) and e-Governance projects etc., under their purview 3.2. Applicability 3.2.1. All ministries, departments, organizations, bodies, agencies including public sector undertakings (PSUs) and e-Governance projects etc., of the Government of India 3.2.2. All organizations included in the list above, shall ensure that the policy, guidelines, procedures and controls detailed in this document, are also adhered to by the private enterprises those support, maintain, manage or operate the information systems, facilities, communication networks, manpower etc. and in the process the information is created, accessed, stored, transacted, disposed and processed by or on behalf of the ministries, departments, agencies and their subordinate organizations through appropriate means. 3.3. NISPG review and update 3.3.1. The guidelines and controls detailed in this document shall be reviewed and updated to reflect the updated /current environment, or atleast once in every two year, whichever is earlier 3.3.2. The “Guidelines for technology specific ICT deployment” shall be reviewed and updated to reflect current technological environment or atleast once every year, whichever is earlier 3.3.3. The “Guidelines for essential security practices” shall be reviewed and updated to reflect the current technological environment or atleast once every year, whichever is earlier 4. Scope 4.1. Scope 4.1.1. The NISPG issued by MHA provide guidance in setting up baseline information security practices within government ministries, departments, agencies and their subordinate organizations. 4.1.2. The following guidelines, procedures and controls shall be implemented at all levels within ministries, departments, agencies and their subordinate organizations., including all eGovernance projects, to protect the confidentiality, integrity and availability of information created, accessed, stored, processed, transacted or retained or disposed of by them; while establishing and maintaining accountability, and non- repudiation of actions over classified information in its lifecycle 4.1.3. This policy extends to all of the following within ministries, departments, agencies and their subordinate organizations: top management, users, system owners, staff/managers, system administrators, developers and operators, including contractors and third party service providers or any other party on their behalf, which maintain, manage, operate or support information systems, facilities, and/or communications networks etc. NISPG - Version 5.0 Restricted Page 20

Select target paragraph3