National Information Security Policy and Guidelines | Ministry of Home Affairs
Foreword
Ministry of Home Affairs (MHA) has been designated as the lead agency for the protection of the
“Information” in Cyberspace. The Ministry is tasked with finalizing and issuing guidelines on the
codification and classification, of information, and keeping it updated in the ever expanding
cyberspace. Earlier, MHA has issued the manual of departmental security instructions 1994 which is
presently
applicable
and
is
being
used
today
by
all
the
Government
Ministries/departments/agencies.
The government at all levels, central, state and local, is increasingly using Information and
Communication Technologies (ICT) to enhance productivity, improve efficiency in service delivery,
speed-up development in all sectors of economy and improve the governance while safeguarding
overall Internal Security and National Security interests of the country.
Paper based records, which were earlier held in the files and filing cabinets, are now created, stored,
processed, accessed, transmitted and destroyed in electronic formats. Such information can be
accessed from different parts of the country by authorized personnel; however, this information is
also vulnerable to unauthorized access which can compromise confidentiality, availability and
integrity of information through cyber-attacks from anywhere in India or from outside the Indian
borders. Adoption of international standards and best practices for security of information in the
complex and borderless cyber space has, therefore, become paramount to protect national
information assets in the overall national security interest. This is more important for organizations
dealing with strategic information related to internal security, national security, economic security,
and external affairs which handling large data/ information in electronic format. Also, the critical
infrastructures such as power, banking and finance, telecommunications, transport, air traffic
control etc., which are using ICT for increasing efficiency and productivity, are prone to cyberattacks. This can have a crippling effect on the nation’s stability, economy and security.
This policy document on “National Information Security and Guidelines 2014” includes a
comprehensive review of the “Manual on Departmental Security Instructions” of 1994 for the
present day information security requirements in the Cyber space to address the above mentioned
challenges. It will serve as an extension to the existing “Manual on Departmental Security
Instructions”, 1994 which primarily addresses the handling of the security of paper based
information.
The National Information Security Policy and Guidelines (NISPG) has been prepared by the Ministry
of Home Affairs, based on the experience of the existing security standards and frameworks and the
global best practices and experience of implementation in the wake of expanding information
security threat scenario. This policy document will supplement the existing guidelines issued by
DeitY, NIC, IB and NTRO for the security of ICT infrastructure, assets, networks, applications, user
management, email etc. I hope that the organizations directly involved in handling the information
in any form, including the digital form, which is relevant to the internal security and national security
shall implement these guidelines and make further suggestions, if any, to improve the next version
of NISPG.
(Union Home Secretary)
NISPG - Version 5.0
Restricted
Page 2