Islamabad: The Federal Cabinet has approved the Pakistan Information Security Framework 2026 to establish a common baseline for information security across the public sector and designated critical infrastructure.
The framework was developed by the National CERT under the Ministry of Information Technology and Telecommunication in response to growing cyber security risks arising from increased digitalisation and interconnected government systems.
It sets out common security controls covering areas including governance, risk management, data protection, identity and access management, incident response, secure software development and protection of critical information infrastructure.
The framework also aims to strengthen the protection of government information, digital services and citizen data, while improving the ability of public sector organisations to prevent, detect and respond to cyber incidents.
During discussions, the Cabinet welcomed the framework but directed the Ministry to specify clear timelines for implementation. It also required provision for independent third party audits to assess compliance.
The approval comes as government institutions increasingly rely on digital systems for public services, financial operations, data management and communication.
The framework is intended to support a more consistent approach to cyber security and strengthen resilience across Pakistan's growing digital infrastructure.





