National Information Security Policy and Guidelines | Ministry of Home Affairs 11. Guidelines structure and components 11.1. Structure: Each domain in the National Information Security Policy & Guidelines consists of five parts, as follows: 11.1.1. Section X.1: Background – This section provides an overview and the coverage of each domain and states the important evolutions and developments in each area. This section provides an overview of each domain for the reader to understand the importance and significance of achieving maturity in each area. 11.1.2. Section X.2: Relevance of domain to information security – This section establishes role and scope of a domain in context of Information Security. It provides insights into the impact of compromise of information due to the current and emerging threats and vulnerabilities of the said domain. 11.1.3. Section X.3: Management guidelines– This section provides domain specific recommendations in the form of guidelines and objectives. These guidelines will help the senior management in an organization to institute security processes, procedures and governance mechanisms. The management guidelines section provides a high level view of each domain, focusing on areas which are of significant importance in order to establish practices in each domain. This section also provides intent to senior management in order to pursue further action in design, development, implementation and governance of security domain. The management guidelines can also be used to derive assurance from operating divisions and will help in the high level performance evaluation of the security function. Each guideline is mapped with a number of security controls which provide clarity on the diverse elements contained in a management guideline. These are denoted by the nomenclature “G” followed by the guideline number. For example, G1, G2, G3 … G112 11.1.4. Section X.4: Security controls– Provides control statements which are administrative, technical, operational or procedural and need to be diligently followed. Security controls provide insight into multiple areas which need to be implemented/ addressed in order to achieve the objectives laid out in the management guidelines section. Security controls provide exact direction and articulate expectations needed to develop adequate protection. Each control statement is further complimented by implementation guidelines, which provide specific information with respect to area covered in each security control. These are denoted by the nomenclature “C” followed by the control number. For example, C1, C2, C3… C135 11.1.5. Section X.5: Implementation guidelines – This section provides specific recommendations to aid implementation of management guidelines and security controls. Implementation guidelines offer granular detail on the expectations from each organization, for implementation of controls and management guidelines. This section provides practical guidance considering the depth of implementation of various controls, while considering the value of information based on its classification. These are denoted by the nomenclature “IG” followed the implementation guideline number. For example, IG1, IG2, IG3 …IG181 NISPG - Version 5.0 Restricted Page 33

Select target paragraph3