National Information Security Policy and Guidelines | Ministry of Home Affairs
11. Guidelines structure and components
11.1. Structure: Each domain in the National Information Security Policy & Guidelines consists of
five parts, as follows:
11.1.1. Section X.1: Background – This section provides an overview and the coverage of each
domain and states the important evolutions and developments in each area. This section
provides an overview of each domain for the reader to understand the importance and
significance of achieving maturity in each area.
11.1.2. Section X.2: Relevance of domain to information security – This section establishes role and
scope of a domain in context of Information Security. It provides insights into the impact of
compromise of information due to the current and emerging threats and vulnerabilities of
the said domain.
11.1.3. Section X.3: Management guidelines– This section provides domain specific
recommendations in the form of guidelines and objectives. These guidelines will help the
senior management in an organization to institute security processes, procedures and
governance mechanisms. The management guidelines section provides a high level view of
each domain, focusing on areas which are of significant importance in order to establish
practices in each domain.
This section also provides intent to senior management in order to pursue further action in
design, development, implementation and governance of security domain. The management
guidelines can also be used to derive assurance from operating divisions and will help in the
high level performance evaluation of the security function. Each guideline is mapped with a
number of security controls which provide clarity on the diverse elements contained in a
management guideline.
These are denoted by the nomenclature “G” followed by the guideline number. For
example, G1, G2, G3 … G112
11.1.4. Section X.4: Security controls– Provides control statements which are administrative,
technical, operational or procedural and need to be diligently followed. Security controls
provide insight into multiple areas which need to be implemented/ addressed in order to
achieve the objectives laid out in the management guidelines section. Security controls
provide exact direction and articulate expectations needed to develop adequate protection.
Each control statement is further complimented by implementation guidelines, which
provide specific information with respect to area covered in each security control.
These are denoted by the nomenclature “C” followed by the control number. For example,
C1, C2, C3… C135
11.1.5. Section X.5: Implementation guidelines – This section provides specific recommendations to
aid implementation of management guidelines and security controls. Implementation
guidelines offer granular detail on the expectations from each organization, for
implementation of controls and management guidelines. This section provides practical
guidance considering the depth of implementation of various controls, while considering the
value of information based on its classification.
These are denoted by the nomenclature “IG” followed the implementation guideline
number. For example, IG1, IG2, IG3 …IG181
NISPG - Version 5.0
Restricted
Page 33