Information security system okayed
Information security system okayed
The government has approved the Pakistan Information Security Framework (PISF) 2026 aimed at reducing risk exposure for public sector orginsations while directing to specify clear implementation timelines and include a provision for an independent third-party audit.
It has also directed the Ministry of Planning, Development and Special Initiatives that no proposal of any ministry regarding independent and new data centres would be approved or included in PC-1s.
During discussions in a recent meeting, the cabinet members appreciated the Ministry of Information Technology and Telecommunication for timely formulation of the Pakistan Information Security Framework 2026, which was urgently required in view of the growing cybersecurity threats.
They, however, observed that the framework should specify clear implementation timelines and should also include a provision for an independent third-party audit.
On a query, the meeting was informed that the prime minister had already issued strict directives that the policy framework prepared by the IT ministry for the establishment and use of data centres should be strictly adhered to and enforced. Also, it should be ensured that the data centres already established by the IT ministry are used by every ministry for any of their initiatives and the Ministry of Planning will ensure that no proposal of any ministry regarding independent/new data centre is approved/included in the PC-1.
Sources in the Ministry of IT and Telecom told The Express Tribune that the cabinet was informed that increasing digitalisation of government functions, expansion of e-governance initiatives and growing interconnectivity of public sector systems had significantly increased exposure to cyber risks and "government entities now rely extensively on information systems for service delivery, financial operations, citizen data management and inter-organisational coordination/ communication".
The ministry further said that variations in institutional capacity and the absence of a unified reference framework had resulted in inconsistent security practices across the public sector, leading to vulnerabilities and exposures. The National Cyber Security Policy 2021, the CERT Rules 2023 and CERT Council emphasise the strengthening of governance, coordinated response mechanisms and standardised implementation of information security controls, therefore, a nationally approved framework is required to translate policy direction into a uniform operational structure, enable regulatory oversight and ensure accountability.
The approval and implementation of PISF will enable the achievement of objectives, in line with the National Cyber Security Policy 2021, which include establishing a standardised national information security baseline across all public and private sector entities and designated critical sectors. It will also strengthen the protection of government information assets, digital platforms and citizen data, while enhancing institutional capacity to prevent, detect and respond to cyber incidents.
The maturity-based compliance mechanism will help in evidence-based decision-making, targeted investment in information/ cybersecurity capabilities, secure digital transformation initiatives and continuity of essential government services.
It will also enhance public trust in government digital services and strengthen national resilience in the digital domain. The Ministry of IT said that the PISF may be notified as the national baseline information security standard for all public and private sector entities (federal or provincial), including autonomous/ semi-autonomous, corporations, CERTs, and the designated critical information infrastructure in order to establish standardised information security governance and strengthen the national cyber security posture.