National Information Security Policy and Guidelines | Ministry of Home Affairs 6. Approach 6.1. Security of classified information 6.1.1. Securing classified information in government and public sector processes lifecycle: The ministries, departments, agencies and their subordinate organizations should ensure that they establish appropriate processes and capabilities to secure information throughout its lifecycle i.e. as information is created, accessed, modified, stored, processed, transacted, transmitted, deleted, disposed of or destroyed. Information can be classified based on its category or type, sensitivity, value and the context throughout its lifecycle 6.2. Security risk assessment 6.2.1. Conducting periodic risk assessment: Security risk assessments should be conducted periodically to evaluate risks and associated threats leading to loss of confidentiality, integrity and availability of information. Threat and vulnerabilities associated with the information must also be evaluated for their potential impact, including impact on internal and national security. 6.2.2. Risk assessment framework: Due to the diverse nature of operations of different organizations there can be no single approach recommended for risk assessment. However, to develop a risk based methodology which helps develop resilience to changing threat environment, ministries, departments, agencies and their subordinate organizations need to integrate information security risk assessment with the broader risk management framework for operations. Frameworks such as ISO 27005:2008 or others may be referred to based on the organization’s requirements 6.2.3. Periodicity of risk assessments: Information security risk assessment should be an on-going activity, triggered early into the lifecycle of system design and development. It should be conducted at least once every year or when changes are made to existing information assets or when threat perception over information and information systems changes. For systems containing classified data, a thorough risk assessment should be conducted at-least once every quarterly 6.2.4. Methodology: A comprehensive security risk assessment may include methodologies prescribed in Section 18 of this document for threat and vulnerability management 6.2.5. Additional insights: A comprehensive information security risk assessment will also provide insights into expected ICT security expenditure, thereby helping formulate budgets and estimate costs and help strategic decision making 6.3. Principles for establishing organization wide security framework 6.3.1. Core security goals: Information security frameworks should be designed to ensure confidentiality, integrity, availability of information to authenticated and authorized users, while establishing accountability over transactions conducted over the lifecycle of information and establishing non- repudiation of information, across layers of people, process and technology 6.3.1.1. Architecture: Adequate steps must be taken for integrating information security measures with the IT architecture of organizations to address contemporary security threats. NISPG - Version 5.0 Restricted Page 22

Select target paragraph3