National Information Security Policy and Guidelines | Ministry of Home Affairs
characteristics of applications vary from basic versions, to context aware, and Internet rich
usage of apps. These variations at various fronts expose the information processed, stored,
accessed, transacted through these applications to a larger threat landscape
10.1.3.5. Data security: Each data item collected, stored, processed, transmitted and accessed by an
organization has to be protected against cyber-attacks especially that are sensitive or
critical for internal and national security as stated in classification of information. The
entire focus and effort is to secure data. It is this which has led to the evolution of the
discipline of data security - the ultimate goal of an organization’s security
10.1.3.6. Personnel security: Risks due to insider threat and internal security breach undermines all
security measures taken to fortify information systems and data from the outside world.
The personnel security focuses on both the aspects of employee as well as third party
security and focuses on sourcing patterns of an organization which requires specifics
checks from a security viewpoint
10.1.3.7. Threat & vulnerability management: There is an ever increasing rise of security threats
with enhanced capabilities, varieties and scales; exploring new ways to find vulnerabilities
and exploits in an organization’s infrastructure to cause maximum possible damage. Threat
and Vulnerability Management (TVM) ensures that an organization’s resources are
protected against the perennial as well as evolving threats, and provides assurance over
the management of its resources in a way that the relevance of new vulnerabilities,
exploits or malware is immediately tested and that the organization responds swiftly to
them. TVM adds critical value to an organization’s security initiatives, which not only
delivers protection capabilities but also provides means to manage IT infrastructure
securely
10.1.3.8. Security monitoring & incident management: Security Monitoring and incident response
management is a key component of an organization’s information security program, as it
demonstrates its ability to respond to an information breach which might emanate from
external or internal sources
10.1.3.9. Security audit and testing: Security audit, testing and reviews should be conducted on a
continuous basis to check for conformance of security measures deployed by the
organization with security policies, standards and requirements. Specific requirements are
implicit in all disciplines. Moreover, general best practices have been provided as part of
this document
10.1.3.10. Business continuity: Business continuity of the operations has to be planned by the
respective government departments and is kept outside the scope of this policy. However,
this document covers areas which are important from the perspective of ensuring
availability of critical operations and classified information
NISPG - Version 5.0
Restricted
Page 31