National Information Security Policy and Guidelines | Ministry of Home Affairs characteristics of applications vary from basic versions, to context aware, and Internet rich usage of apps. These variations at various fronts expose the information processed, stored, accessed, transacted through these applications to a larger threat landscape 10.1.3.5. Data security: Each data item collected, stored, processed, transmitted and accessed by an organization has to be protected against cyber-attacks especially that are sensitive or critical for internal and national security as stated in classification of information. The entire focus and effort is to secure data. It is this which has led to the evolution of the discipline of data security - the ultimate goal of an organization’s security 10.1.3.6. Personnel security: Risks due to insider threat and internal security breach undermines all security measures taken to fortify information systems and data from the outside world. The personnel security focuses on both the aspects of employee as well as third party security and focuses on sourcing patterns of an organization which requires specifics checks from a security viewpoint 10.1.3.7. Threat & vulnerability management: There is an ever increasing rise of security threats with enhanced capabilities, varieties and scales; exploring new ways to find vulnerabilities and exploits in an organization’s infrastructure to cause maximum possible damage. Threat and Vulnerability Management (TVM) ensures that an organization’s resources are protected against the perennial as well as evolving threats, and provides assurance over the management of its resources in a way that the relevance of new vulnerabilities, exploits or malware is immediately tested and that the organization responds swiftly to them. TVM adds critical value to an organization’s security initiatives, which not only delivers protection capabilities but also provides means to manage IT infrastructure securely 10.1.3.8. Security monitoring & incident management: Security Monitoring and incident response management is a key component of an organization’s information security program, as it demonstrates its ability to respond to an information breach which might emanate from external or internal sources 10.1.3.9. Security audit and testing: Security audit, testing and reviews should be conducted on a continuous basis to check for conformance of security measures deployed by the organization with security policies, standards and requirements. Specific requirements are implicit in all disciplines. Moreover, general best practices have been provided as part of this document 10.1.3.10. Business continuity: Business continuity of the operations has to be planned by the respective government departments and is kept outside the scope of this policy. However, this document covers areas which are important from the perspective of ensuring availability of critical operations and classified information NISPG - Version 5.0 Restricted Page 31

Select target paragraph3