National Information Security Policy and Guidelines | Ministry of Home Affairs Foreword Ministry of Home Affairs (MHA) has been designated as the lead agency for the protection of the “Information” in Cyberspace. The Ministry is tasked with finalizing and issuing guidelines on the codification and classification, of information, and keeping it updated in the ever expanding cyberspace. Earlier, MHA has issued the manual of departmental security instructions 1994 which is presently applicable and is being used today by all the Government Ministries/departments/agencies. The government at all levels, central, state and local, is increasingly using Information and Communication Technologies (ICT) to enhance productivity, improve efficiency in service delivery, speed-up development in all sectors of economy and improve the governance while safeguarding overall Internal Security and National Security interests of the country. Paper based records, which were earlier held in the files and filing cabinets, are now created, stored, processed, accessed, transmitted and destroyed in electronic formats. Such information can be accessed from different parts of the country by authorized personnel; however, this information is also vulnerable to unauthorized access which can compromise confidentiality, availability and integrity of information through cyber-attacks from anywhere in India or from outside the Indian borders. Adoption of international standards and best practices for security of information in the complex and borderless cyber space has, therefore, become paramount to protect national information assets in the overall national security interest. This is more important for organizations dealing with strategic information related to internal security, national security, economic security, and external affairs which handling large data/ information in electronic format. Also, the critical infrastructures such as power, banking and finance, telecommunications, transport, air traffic control etc., which are using ICT for increasing efficiency and productivity, are prone to cyberattacks. This can have a crippling effect on the nation’s stability, economy and security. This policy document on “National Information Security and Guidelines 2014” includes a comprehensive review of the “Manual on Departmental Security Instructions” of 1994 for the present day information security requirements in the Cyber space to address the above mentioned challenges. It will serve as an extension to the existing “Manual on Departmental Security Instructions”, 1994 which primarily addresses the handling of the security of paper based information. The National Information Security Policy and Guidelines (NISPG) has been prepared by the Ministry of Home Affairs, based on the experience of the existing security standards and frameworks and the global best practices and experience of implementation in the wake of expanding information security threat scenario. This policy document will supplement the existing guidelines issued by DeitY, NIC, IB and NTRO for the security of ICT infrastructure, assets, networks, applications, user management, email etc. I hope that the organizations directly involved in handling the information in any form, including the digital form, which is relevant to the internal security and national security shall implement these guidelines and make further suggestions, if any, to improve the next version of NISPG. (Union Home Secretary) NISPG - Version 5.0 Restricted Page 2

Select target paragraph3