National Information Security Policy and Guidelines | Ministry of Home Affairs
6. Approach
6.1. Security of classified information
6.1.1. Securing classified information in government and public sector processes lifecycle: The
ministries, departments, agencies and their subordinate organizations should ensure that they
establish appropriate processes and capabilities to secure information throughout its lifecycle
i.e. as information is created, accessed, modified, stored, processed, transacted, transmitted,
deleted, disposed of or destroyed. Information can be classified based on its category or type,
sensitivity, value and the context throughout its lifecycle
6.2. Security risk assessment
6.2.1. Conducting periodic risk assessment: Security risk assessments should be conducted
periodically to evaluate risks and associated threats leading to loss of confidentiality, integrity
and availability of information. Threat and vulnerabilities associated with the information
must also be evaluated for their potential impact, including impact on internal and national
security.
6.2.2. Risk assessment framework: Due to the diverse nature of operations of different
organizations there can be no single approach recommended for risk assessment. However, to
develop a risk based methodology which helps develop resilience to changing threat
environment, ministries, departments, agencies and their subordinate organizations need to
integrate information security risk assessment with the broader risk management framework
for operations. Frameworks such as ISO 27005:2008 or others may be referred to based on
the organization’s requirements
6.2.3. Periodicity of risk assessments: Information security risk assessment should be an on-going
activity, triggered early into the lifecycle of system design and development. It should be
conducted at least once every year or when changes are made to existing information assets
or when threat perception over information and information systems changes. For systems
containing classified data, a thorough risk assessment should be conducted at-least once
every quarterly
6.2.4. Methodology: A comprehensive security risk assessment may include methodologies
prescribed in Section 18 of this document for threat and vulnerability management
6.2.5. Additional insights: A comprehensive information security risk assessment will also provide
insights into expected ICT security expenditure, thereby helping formulate budgets and
estimate costs and help strategic decision making
6.3. Principles for establishing organization wide security framework
6.3.1. Core security goals: Information security frameworks should be designed to ensure
confidentiality, integrity, availability of information to authenticated and authorized users,
while establishing accountability over transactions conducted over the lifecycle of information
and establishing non- repudiation of information, across layers of people, process and
technology
6.3.1.1. Architecture: Adequate steps must be taken for integrating information security measures
with the IT architecture of organizations to address contemporary security threats.
NISPG - Version 5.0
Restricted
Page 22