National Information Security Policy and Guidelines | Ministry of Home Affairs
Executive summary
The digital world is a reality today in all aspects of our lives. Digital infrastructure is the backbone of
prosperous economies, vigorous research communities, strong militaries, transparent governments
and free societies. Lacs of people across the country rely on the electronic services in cyberspace
every day. As never before, Information and Communication Technology (ICT) is fostering
transnational dialogue and facilitating the global flow of information, goods and services. These
social and trade links have become indispensable to our daily lives as well as the economy of our
country. Critical life-sustaining infrastructures that deliver electricity and water, telecommunication,
Internet and broadband connectivity, control air traffic, and support our financial systems all
depend on networked information systems. The reach of networked technology is pervasive and
global. For all nations, the underlying digital infrastructure has become a critical national asset.
Therefore improving and securing this digital infrastructure in all its dimensions including increased
availability of next generation broadband connectivity, citizen/ customer centric applications and
services, security of information, is critical to India’s future.
Traditionally, information available with the government has been safely managed by keeping it in
paper records throughout its lifecycle i.e. creation, storage, access, modification, distribution, and
destruction. However, to make all government services accessible to the common man in his
locality, through efficient service delivery outlets, along with transparency & reliability, the
government has steadily graduated towards using electronic formats of information. Now, several
forms of information have been converted to the electronic format by the ministries, departments
and agencies, both in the central as well as state governments. The classification, storage and
protection of such information in electronic format have always remained an area of concern. The
challenge, as with the information contained in paper format, remains the same, namely the ability
to categorize, protect, archive, discover, and attribute information during its useful life and eventual
destruction. Even though the lifecycle of information remains the same in electronic documents and
online transactions, the methods to secure information in electronic environment are different. In
the present age, the “Manual of Departmental Security Instructions”, issued in 1994, is no longer
sufficient to protect against the threats facing electronic forms of information.
Information security is one of the important components of cyber security and is gradually taking
centre stage in the national security deliberations and discussions. In fact, it has become a key
component of national security design and is shaping international strategies of nations globally.
Threats to information are increasingly organized and targeted, helping criminals, state actors and
hacktivists to reap immense benefits out of information compromise, theft or espionage.
Cybercriminals can carry out identity theft and financial fraud; steal corporate information such as
intellectual property; conduct espionage to steal state and military secrets; and recruit criminals or
disrupt critical infrastructures by exploiting the vulnerabilities in any system connected to the
Internet. The cybercriminals could be located anywhere in the world and they can target a particular
user, system or a particular service in a country or a region. Worse still, the cybercriminals can cover
their tracks so that they cannot be traced. It is extremely difficult to prove whether the
cybercriminal is an individual, a gang, a group of state actors or a nation-state.
As the government broadens the scope of its drive to move towards e-governance and embraces
technology for citizen-centric services, it faces threats from multiple sources. Each government
process or project introduces a different level of complexity as a result of varied data transactions,
NISPG - Version 5.0
Restricted
Page 3