National Information Security Policy and Guidelines | Ministry of Home Affairs
8.2.1.5. System Administrator (SA): Responsible for performing functions, that requires system
administration privileges of the user systems, for each location of the Ministry/ Department
8.2.1.6. Network Security Administrator (NSA): Responsible for managing the security of the
networks per location/ Bhawan. This role will be performed by the service provider
8.2.1.7. National Security Operations Center Head (NSOC): Responsible for managing the NSOC
round the clock. This responsibility will be handled by the service provider
8.2.1.8. NSOC Administrator: Responsible for administration of the NSOC round the clock
8.2.1.9. NSOC operator: Responsible for operations of the NSOC round the clock
8.3. Information Security Steering Committee (ISSC)
8.3.1. An Information Security Steering Committee (ISSC) under the chairmanship of the Secretary of
the concerned Ministry should be established
8.3.2. The members of the ISSC should comprise of:
8.3.2.1. IT Head or equivalent
8.3.2.2. Chief Information Security Officer (CISO)
8.3.2.3. Financial Advisor
8.3.2.4. Representative of National Critical Information Infrastructure Protection Center (NCIIPC), or
representative of Department of Electronics and Information Technology (DeitY)
8.3.2.5. Any other expert to be nominated by the ministry or department
9. Framework
9.1. Standard for information security management
9.1.1. The ministries, departments, agencies and their subordinate organizations should ensure
enforcement of a globally accepted standard of information security management and
governance. Reference to the standard used, should be documented in the ministry/
departments security policy, or in some other high level document, developed by the Chief
Information Security Officer (CISO), and approved by the ISSC
9.1.2. The implementation of information security and its governance requires coordinated effort
between designated personnel and well defined framework for governance. The governance
process and the personnel tasked with governance of information security should be stated in
the security policy, and brought to the notice of ISSC
NISPG - Version 5.0
Restricted
Page 28