National Information Security Policy and Guidelines | Ministry of Home Affairs 5. Supplementary documents and references 5.1. References 5.1.1. The policies and procedures suggested in this document take into account the previous guidelines issued by various competent bodies and authorities of the government e.g. ‘Computer Security Guidelines’ 2006’ by Intelligence Bureau (IB), ‘Cyber Security Policy for Government of India’ by National Informatics Centre (NIC), Guidelines and controls mentioned in “Cyber Security Policy for Government of India” ver 2.0 released 30th August, 2010, Guidelines issued by National Critical Information Infrastructure Protection Centre, National Technical Research Organization and various ‘Security Guidelines’ issued by CERT-In. The directions laid out in this document are inclusive in nature and have referred to the content and suggestions from the above mentioned guidelines, wherever appropriate. However, the ministries, departments, agencies and their subordinate organizations concerned are advised to consult the previous documents on the same subjects as well 5.1.2. MHA has done extensive work of studying various, international and national standards and regulatory guidelines prevalent in the information security domain worldwide. The guidelines have been influenced by, and draw references from, the global standards and practices such as ISO 27001 (2005 as well as 2013), NIST Special Publication 800-53, Federal Information Security Management Act (FISMA) of USA, SANS “20 Critical Security Controls”, Control Objectives for Information and Related Technology (COBIT) for information technology (IT) management and IT governance, PCI –DSS, DSCI Security Framework (DSF) etc. NISPG - Version 5.0 Restricted Page 21

Select target paragraph3