National Information Security Policy and Guidelines | Ministry of Home Affairs The guidelines are reinforced with the help of specific control objectives and statements which will help organizations initiate their journey towards establishing a security baseline and further help them in obtaining maturity in these practices. To help the readers of this document appreciate the work already undertaken globally in the field of information security, the annexures have been updated with a brief summary of some globally accepted information security frameworks, standards and practices. The readers can comprehend the guidelines and controls provided in this document, from the detailed chart which provides mapping of guidelines and controls mentioned in this manual with that of other globally accepted frameworks, standards, practices and controls such as ISO 27001 (2005 as well as 2013), SANS 20, NTRO 40 and FISMA. There are 112 different guidelines and 135 controls and 181 implementation guidelines defined in NISP as against 133 controls in ISO 27001, 40 controls defined by NTRO, 20 controls by SANS and about 200 controls by FISMA. Further, some guidance has also been provided on the methodology which may be used by the organizations for carrying out risk assessments for the purpose of information security. The first and second drafts of the “National Information Security Policy and Guidelines” (NISPG) were circulated by MHA in January 2014. Since then, feedback and suggestions have been received from various ministries, departments and agencies on the guidelines contained in the NISPG. The feedback received has provided valuable insight into specific areas to improve the guidelines. Further guidance was added in Version 3.0 of the document encompassing areas such as business continuity, security testing and security audits. Additionally, guidance on securing technology specific areas has also been incorporated, based on the feedback received from various departments. These guidelines include security measures for cloud computing, BYOD and virtualization. In the current version i.e. NISPG 4.0, implementation guidelines have been added to help organizations in comprehending requirements of each domain, along with additional controls and areas that have emerged after the feedback from some other government agencies. Establishing visibility over information and its lifecycle Organizations need to establish a process of identification and discovery of information at each of its operational processes, relationships and functions. Information is an empowerment and has a strategic as well as an economic value associated with it. The security posture of the organization has to be dynamic and should evolve with the change in the value of information, underlying ICT infrastructure, information access methods and threat ecosystem. It should have the ability to address the security requirements of all data transactions across all possible data leakage scenarios. The security solutions should help address security of information, not only at the different layers of ICT infrastructure, but also in the extended operational ecosystem, i.e. other ministries and agencies may be given access to information. This should also provide guidance for securing emerging technology platforms such as mobility, cloud computing, virtualization etc. While designing the strategy for security, information centric approach in operational lifecycle should be an important consideration. The identified information item and its characteristics such as its origin, sensitivity, strategic and economic value, geography of operation, access methods and the department(s) or the financial ecosystem within which transactions take place along with the operations performed on the information help identify the security requirements. Developing an information centric security framework The consideration of information security in the life cycle is important from people, process and technical design perspective. Information can be classified based on its category or type, sensitivity, NISPG - Version 5.0 Restricted Page 7

Select target paragraph3