Strategy 2020 • Advocating a sound, agile, and efficient third-party security assurance mechanism • Promote the adoption of standards while selecting, evaluating, deploying, configuring, and operating devices, solutions, and platforms. Leveraging India's leadership position for shaping global standards impacting payment industry • Developing competent incident and emergency response capabilities for the financial sector • Promote responsible and timely disclosure of vulnerability and incident reporting for the devices, solutions, and platforms deployed for transaction processing • Overhauling assurance system, making it more agile, threat aligned, and intelligence-driven Promoting efforts and collaborations for making people aware of payment security in a targeted, entrenched, and scalable manner Sectoral preparedness: Digitization is increasingly leading to the verticalization of IT, where every sector is evolving to verticalize technology stack for their requirements. Their digital footprint is increasing, spreading the threat exposures. The sectors may not be ready or fall short of handling security affairs impacting their prospects. • Profiling sectors, their digitization plan, architectural developments, technology adoption, possible exposures, and likely ramifications, which can be used for ascertaining the priorities for the interventions • Ensuring evaluation of sectors and specific companies in them, for their role in the critical supply chain to identify possible ramifications to national cybersecurity from a security breach • Providing special attention to the sectors that rely on the operating environment for enhancing SCADA/OT/IoT security, and integrating that with organizational security function • Keeping watch on sectoral cybersecurity preparedness through developing and maintaining index and setting up a mechanism for continually monitoring exposures of members of the sectors • Developing regulatory capabilities wherever possible to create and drive the agenda of cybersecurity in the sectors and making them more contextual and objective to the sectoral challenges • Promoting the development of frameworks, policies, guidance, and technical standards in the sensitive sectors • Ensuring the development of security function and leadership in the companies, empowering them, and by making the security function independent from routine IT and business operations • Developing an audit, assurance, and assessment ecosystem in the sectors that measure the level of preparedness and help to build risk management culture A NASSCOM® Initiative

Select target paragraph3