Pakistan Introduces New Security Framework To Strengthen National Cybersecurity Standards

Pakistan Introduces New Security Framework To Strengthen National Cybersecurity Standards

Pakistan is moving towards establishing a unified national cybersecurity standard after National Cyber Emergency Response Team (National CERT) submitted a new security framework to the federal cabinet for approval. The proposal, named the Pakistan Information Security Framework (PISF), has been developed following extensive consultations with federal and provincial governments, regulators, operators of critical infrastructure, and other relevant stakeholders. Once approved, the framework will serve as the country’s baseline cybersecurity standard and will apply to government organizations as well as designated Critical Information Infrastructure (CII) entities across Pakistan. The initiative is intended to strengthen national cyber resilience by introducing consistent security requirements, improving cyber risk management, and enhancing the country’s ability to prevent, detect, and respond to cyber threats.

The proposed framework establishes a comprehensive set of cybersecurity requirements that government institutions will be expected to implement. These include creating clear cybersecurity governance structures, conducting regular risk assessments, and introducing standardized incident response procedures. Organizations will also be required to develop business continuity and disaster recovery plans to ensure the uninterrupted delivery of essential services during cyber incidents. In addition, the framework introduces mandatory cybersecurity controls covering governance, risk management, incident response, data protection, physical security, and supply chain management. It also includes requirements for secure software development, data centre operations, web hosting services, and the protection of critical information infrastructure. According to the proposal, these measures are designed to strengthen Pakistan’s overall cybersecurity posture by creating a consistent security baseline across public sector organizations. The framework will apply to federal and provincial ministries, government departments, autonomous bodies, public corporations, Computer Emergency Response Teams (CERTs), and organizations that have been classified as Critical Information Infrastructure.

Another major component of the Pakistan Information Security Framework is the introduction of mandatory cyber incident reporting timelines. Organizations responsible for managing Critical Information Infrastructure will be required to immediately report verified cyber incidents to the relevant regulator, sectoral CERT, and National CERT. They must also submit a detailed incident report within 72 hours of verification. For verified incidents involving organizations outside the critical infrastructure category, the reporting deadline has been set at 120 hours. The framework also introduces additional security responsibilities for organizations providing data centre, web hosting, and email services. These service providers will be expected to implement stronger protective measures, including multi factor authentication, network security controls, continuous monitoring, vulnerability management, secure backup systems, and annual independent security audits. These requirements are aimed at improving the security and resilience of digital infrastructure while ensuring service providers maintain consistent security practices.

The proposed framework also addresses data hosting requirements by requiring organizations that currently host government websites or applications outside Pakistan to prepare plans for migrating them to data centres within the country. It further requires cybersecurity obligations to be incorporated into agreements with software developers, cloud service providers, and hosting companies to strengthen security across the digital supply chain. The framework promotes security by design principles during software development, strengthens supply chain risk management, and requires regular information security audits. Critical infrastructure operators will also be expected to implement sector specific security controls to improve the protection of essential national services. Organizations covered under the framework will be required to classify critical assets, safeguard personal data, conduct resilience testing, maintain coordination with sectoral CERTs and National CERT, and provide regular cybersecurity awareness training for employees. Once approved by the federal cabinet, the Pakistan Information Security Framework will become Pakistan’s primary cybersecurity standard, with public sector organizations expected to implement its compliance and security requirements as prescribed.

Follow the SPIN IDG WhatsApp Channel for updates across the Smart Pakistan Insights Network covering all of Pakistan’s technology ecosystem.

Post Comment