National Information Security Policy and Guidelines | Ministry of Home Affairs Executive summary The digital world is a reality today in all aspects of our lives. Digital infrastructure is the backbone of prosperous economies, vigorous research communities, strong militaries, transparent governments and free societies. Lacs of people across the country rely on the electronic services in cyberspace every day. As never before, Information and Communication Technology (ICT) is fostering transnational dialogue and facilitating the global flow of information, goods and services. These social and trade links have become indispensable to our daily lives as well as the economy of our country. Critical life-sustaining infrastructures that deliver electricity and water, telecommunication, Internet and broadband connectivity, control air traffic, and support our financial systems all depend on networked information systems. The reach of networked technology is pervasive and global. For all nations, the underlying digital infrastructure has become a critical national asset. Therefore improving and securing this digital infrastructure in all its dimensions including increased availability of next generation broadband connectivity, citizen/ customer centric applications and services, security of information, is critical to India’s future. Traditionally, information available with the government has been safely managed by keeping it in paper records throughout its lifecycle i.e. creation, storage, access, modification, distribution, and destruction. However, to make all government services accessible to the common man in his locality, through efficient service delivery outlets, along with transparency & reliability, the government has steadily graduated towards using electronic formats of information. Now, several forms of information have been converted to the electronic format by the ministries, departments and agencies, both in the central as well as state governments. The classification, storage and protection of such information in electronic format have always remained an area of concern. The challenge, as with the information contained in paper format, remains the same, namely the ability to categorize, protect, archive, discover, and attribute information during its useful life and eventual destruction. Even though the lifecycle of information remains the same in electronic documents and online transactions, the methods to secure information in electronic environment are different. In the present age, the “Manual of Departmental Security Instructions”, issued in 1994, is no longer sufficient to protect against the threats facing electronic forms of information. Information security is one of the important components of cyber security and is gradually taking centre stage in the national security deliberations and discussions. In fact, it has become a key component of national security design and is shaping international strategies of nations globally. Threats to information are increasingly organized and targeted, helping criminals, state actors and hacktivists to reap immense benefits out of information compromise, theft or espionage. Cybercriminals can carry out identity theft and financial fraud; steal corporate information such as intellectual property; conduct espionage to steal state and military secrets; and recruit criminals or disrupt critical infrastructures by exploiting the vulnerabilities in any system connected to the Internet. The cybercriminals could be located anywhere in the world and they can target a particular user, system or a particular service in a country or a region. Worse still, the cybercriminals can cover their tracks so that they cannot be traced. It is extremely difficult to prove whether the cybercriminal is an individual, a gang, a group of state actors or a nation-state. As the government broadens the scope of its drive to move towards e-governance and embraces technology for citizen-centric services, it faces threats from multiple sources. Each government process or project introduces a different level of complexity as a result of varied data transactions, NISPG - Version 5.0 Restricted Page 3

Select target paragraph3