National Information Security Policy and Guidelines | Ministry of Home Affairs
involvement of multiple players, and exposure to increasing compliance requirements, diverse
operational and infrastructure environments and embracing of technological innovations. This
complexity is true of the private sector as well, even though they are early adopters of technology
and innovation. Such complexity associated with the lifecycle of information poses serious
challenges in managing and governing security and ensuring compliance. Thus, it is essential to
establish a focused policy initiative for the security of information and to sensitize public and private
sector towards national security concerns and drive their actions for securing information. This will
not only secure the IT systems but also instill trust in IT services provided by the government
agencies, which can further expand and help in improved e-governance services to various
stakeholders.
Information security brings up a set of different problems that have the potential to challenge the
comfort in the conventional methods of managing security concerns. Cyber threats do not respect
physical boundaries. They explore and innovate, discovering new methods for compromising
security. Further, the identity of the attacker and the source is difficult to ascertain. Attribution in
cyberspace has emerged as an intimidating challenge. In most cases, it is extremely difficult to
collect irrefutable evidence against a cyber-attacker, and almost impossible to link any cyber-attack
to nation-states, even if clearly established.
Current symptoms of problem in India
Securing sensitive information is important for the strategic security and defense of a country.
Economic stability of the country depends on uninterrupted operations of banking and finance;
critical infrastructure such as power generation and distribution, transport systems of rail, road, air
and sea; which in turn are critical dependent on ICT. It is important for national security and
continued prosperity of people. For example, the financial sector in India uses ICT extensively – it is
an early adopter of leading and emerging technologies. It is not surprising to note that intellectual
property developed both in public and private sector also contributes to the economic growth of a
nation in a knowledge based economy. Cyberattacks are specially targeted at companies and
organizations to steal intellectual property in what is known as economic espionage. Malware like
Stuxnet and Flame have provided evidence of cyberattacks leading to kinetic and long lasting
damage to strategic capabilities of a nation, and of espionage, respectively.
The public sector, although increasingly relying on ICT, has not fully awakened to the challenges of
information security. The private sector, which makes investments in information security for
intrinsic requirements, needs to ensure that these security practices are also aligned with national
security concerns. So far, even though focus has been on improving ICT systems and providing egovernance services by various institutions, the IT systems and business processes have not placed
the desired emphasis on Information Security. The time has come to drive both sectors towards a
strong information security culture, which is sensitive to national imperatives. There have been
revisions of Departmental Security Instructions and Guidelines from DeitY, IB, NIC and NTRO to
streamline and tighten up the various aspects of documentation, personnel and physical security
procedures. However, a comprehensive approach for managing information security was missing.
Consideration of the underlying causes of the problem
Information security is not merely a technology problem; it requires alignment with organizational
processes as well as the legal and regulatory framework in the nation. However, for successful and
NISPG - Version 5.0
Restricted
Page 4