Business

Govt approves Pakistan Information Security Framework 2026

The federal government has approved the Pakistan Information Security Framework (PISF) 2026 to strengthen cybersecurity and reduce the exposure of public sector organisations to growing digital threats.

The government has also directed the framework’s implementation within clear timelines and called for an independent third-party audit to assess compliance and security standards.

The Cabinet appreciated the Ministry of Information Technology and Telecommunication for preparing the framework, noting that the rapid expansion of digital services and e-governance had made stronger cybersecurity measures increasingly necessary.

During the meeting, Cabinet members stressed the need for specific deadlines for implementing the framework. They also recommended independent audits to ensure that government organisations follow the prescribed security standards.

The meeting was informed that the prime minister had already directed all ministries and departments to strictly follow the policy framework for establishing and using data centres. Under the directives, ministries must use data centres already established by the IT ministry for their digital initiatives.

The Ministry of Planning, Development and Special Initiatives will ensure that proposals for independent or new data centres are not approved or included in PC-1 documents.

Officials from the Ministry of IT and Telecommunication said the growing digitalisation of government operations, expansion of e-governance and increased connectivity between public sector systems had significantly increased cybersecurity risks.

Government organisations now depend heavily on information systems for public service delivery, financial operations, citizen data management and communication between departments.

The ministry said differences in institutional capacity and the lack of a common security framework had led to inconsistent cybersecurity practices across the public sector, creating vulnerabilities.

Officials said the National Cyber Security Policy 2021, CERT Rules 2023 and the CERT Council already provide important directions for improving cybersecurity governance, response mechanisms and security controls. The newly approved framework aims to turn these policy directions into a uniform system, strengthen oversight and improve accountability across government organisations.

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button