India Law Chronicle Logo
Notifications
Home

Sikkim Government Mandates National Cyber Security Policies Across State Entities

Copy LinkShareSave

The Government of Sikkim issued Notification No. 641/DIT/2025 on August 28, 2025, through its Department of Information Technology. This instrument formally adopted several national cyber security and information security policies for mandatory implementation across all its Departments, Directorates, Autonomous Bodies, and State Public Sector Enterprises. The notification was issued in response to recommendations from the Ministry of Electronics Information Technology (MeitY), Government of India, and to comply with stringent security requirements set by regulatory bodies such as the Reserve Bank of India (RBI) and the National Payments Corporation of India (NPCI) for the protection of citizen data and electronic transactions. The policies adopted include the National Cyber Security Policy, the National Information Security Policy and Guidelines (NISPG), and the User-Level Security Policy, all issued by the Government of India. These policies are applicable to all Information and Communication Technology (ICT) and Information Technology (IT) systems, applications, databases, and communication networks owned, operated, or maintained by the State Government. Departments involved in citizen services, financial transactions, and Direct Benefit Transfer (DBT) systems (where benefits are directly transferred to beneficiaries' accounts) were specifically directed to ensure strict compliance with NPCI security advisories. All projects under e-Governance, Digital India, and State IT initiatives must align with these newly adopted policies to ensure the confidentiality, integrity, and availability of information assets. The notification came into force forthwith upon its publication in the Official Gazette on September 19, 2025.

The primary objective behind this adoption was to establish a robust and formal cyber security and information security framework within the State of Sikkim, addressing the absence of an existing State-specific policy. The legislative intent was to safeguard sensitive citizen data and government records from evolving cyber threats, hacking, and unauthorized access, thereby mitigating risks of financial fraud, ransomware, phishing, and data breaches. Furthermore, the notification aimed to standardize security practices across all government departments in alignment with national guidelines, ensuring uniformity and enhancing the resilience of the State's digital infrastructure through improved incident response and disaster recovery capabilities. The move also supports national priorities on cyber hygiene, secure digital transactions, and trusted governance platforms, aligning with the broader Digital India initiative. The legislation provided: “Establish a formal cyber security and information security framework in the State of Sikkim in the absence of an existing State-specific policy.” To facilitate implementation, the Home Department and the Department of Information Technology, Government of Sikkim, were designated as the Nodal Departments responsible for monitoring and review. Chief Information Security Officers (CISOs) from all departments, directorates, autonomous bodies, and State Public Sector Enterprises are tasked with coordinating inter-departmental compliance, overseeing cyber incident response, and reporting on the State's overall security posture to the Government of India as required. All government departments and agencies are mandated to strictly enforce these policies, conduct regular compliance checks, and ensure proper IT asset management, user accountability, and data protection measures.

Keywords: Sikkim, Cyber Security, Information Technology, Data Protection, Government Policies, Digital India, RBI, NPCI, e-Governance Geo Tags: India, Sikkim District: Not Applicable