National Information Security Policy and Guidelines | Ministry of Home Affairs
The guidelines are reinforced with the help of specific control objectives and statements which will
help organizations initiate their journey towards establishing a security baseline and further help
them in obtaining maturity in these practices. To help the readers of this document appreciate the
work already undertaken globally in the field of information security, the annexures have been
updated with a brief summary of some globally accepted information security frameworks,
standards and practices. The readers can comprehend the guidelines and controls provided in this
document, from the detailed chart which provides mapping of guidelines and controls mentioned
in this manual with that of other globally accepted frameworks, standards, practices and controls
such as ISO 27001 (2005 as well as 2013), SANS 20, NTRO 40 and FISMA. There are 112 different
guidelines and 135 controls and 181 implementation guidelines defined in NISP as against 133
controls in ISO 27001, 40 controls defined by NTRO, 20 controls by SANS and about 200 controls by
FISMA. Further, some guidance has also been provided on the methodology which may be used by
the organizations for carrying out risk assessments for the purpose of information security.
The first and second drafts of the “National Information Security Policy and Guidelines” (NISPG)
were circulated by MHA in January 2014. Since then, feedback and suggestions have been received
from various ministries, departments and agencies on the guidelines contained in the NISPG. The
feedback received has provided valuable insight into specific areas to improve the guidelines.
Further guidance was added in Version 3.0 of the document encompassing areas such as business
continuity, security testing and security audits. Additionally, guidance on securing technology
specific areas has also been incorporated, based on the feedback received from various
departments. These guidelines include security measures for cloud computing, BYOD and
virtualization. In the current version i.e. NISPG 4.0, implementation guidelines have been added to
help organizations in comprehending requirements of each domain, along with additional controls
and areas that have emerged after the feedback from some other government agencies.
Establishing visibility over information and its lifecycle
Organizations need to establish a process of identification and discovery of information at each of its
operational processes, relationships and functions. Information is an empowerment and has a
strategic as well as an economic value associated with it. The security posture of the organization
has to be dynamic and should evolve with the change in the value of information, underlying ICT
infrastructure, information access methods and threat ecosystem. It should have the ability to
address the security requirements of all data transactions across all possible data leakage scenarios.
The security solutions should help address security of information, not only at the different layers of
ICT infrastructure, but also in the extended operational ecosystem, i.e. other ministries and agencies
may be given access to information. This should also provide guidance for securing emerging
technology platforms such as mobility, cloud computing, virtualization etc. While designing the
strategy for security, information centric approach in operational lifecycle should be an important
consideration. The identified information item and its characteristics such as its origin, sensitivity,
strategic and economic value, geography of operation, access methods and the department(s) or
the financial ecosystem within which transactions take place along with the operations performed
on the information help identify the security requirements.
Developing an information centric security framework
The consideration of information security in the life cycle is important from people, process and
technical design perspective. Information can be classified based on its category or type, sensitivity,
NISPG - Version 5.0
Restricted
Page 7