PISF Closes the Hosting Layer in Pakistan's Sovereignty Stack
@kawishwaqar|July 14, 2026 (4w ago)29 views
nCERT's Pakistan Information Security Framework is the most detailed cybersecurity instrument Pakistan has issued: 13 control documents, 238 individually numbered controls, turning the National Cyber Security Policy 2021's intent and the CERT Rules 2023's legal authority into requirements an auditor can score. It applies to federal and provincial ministries, autonomous bodies, corporations, CERTs, and designated Critical Information Infrastructure (CII).
Disclosure: I work at Jazz as Principal Evangelist Cloud & AI. This article is written as personal industry analysis. Views are my own.
What the 13 documents cover
| Document | Controls | Sets the baseline for |
|---|---|---|
| Governance | 19 | Independent security function, steering committee, budget |
| Asset & Risk Management | 22 | Asset register, classification, risk treatment |
| Security Training | 9 | Mandatory awareness, role-based certification |
| System & Communication Protection | 25 | Network security, endpoints, logging, backups |
| Identity & Access Management | 9 | Authentication, privileged access, lifecycle |
| Data Protection & Privacy | 19 | Lawful basis, retention, privacy impact assessment |
| Incident Response | 14 | Detection, reporting timelines, BCP/DRP |
| Physical Security | 9 | Facility access, surveillance, fire safety |
| Supply Chain Management | 19 | Vendor due diligence, concentration risk |
| Audit | 11 | Independent review, control self-assessment |
| Data Center & Web Hosting | 35 | DC compliance bar, hosting repatriation |
| SSDLC | 10 | Secure coding, CI/CD security gates |
| CII Protection | 37 | Classification, resilience, sector coordination |
The hosting layer joins the sovereignty stack
I have spent the last several months tracking Pakistan's regulatory direction on cloud, data, and AI: a data layer from SBP, a compute layer from the Cloud First Policy and local IaaS, an application layer from the National AI Policy. PISF adds a fourth, and it is explicit about it. PISF's Data Center and Web Hosting Services document supplies the hosting layer, in a single unambiguous clause:
Organizations hosting their websites and applications outside Pakistan shall plan migration to data centers within Pakistan's geographical boundaries.
A second, separate clause backs it with an enforcement mechanism: any organization using a data center that cannot pass the framework's audit and compliance bar "shall ensure migration of services to a secure and compliant data center." One clause pulls hosting back across the border. The other pushes workloads out of any facility, foreign or domestic, that fails the audit. Together they connect directly to my earlier reads on SBP's Cloud Regulatory Framework, Pakistan's 5G sovereign cloud moment, and PTA's domestic routing mandate.
The bar a data center has to clear
- Next-generation firewalls, WAF, IDS/IPS, DDoS protection, DLP
- Documented server hardening and patch management
- Tested BCP/DRP, SIEM/SOAR/SOC-grade monitoring
- 12 months of retained security logs, minimum
- Encrypted, geographically separated backups
- At least one independent third-party audit a year
- SPF, DKIM, and DMARC (or equivalent) for hosted email
I verified the email-hardening line item against five prominent federal domains, including nCERT's own. All five already had SPF configured, and all five already had DMARC in enforcement mode. The easy, externally checkable control is already met at the top of the pyramid. The harder controls, independent security functions and dedicated budgets, cannot be checked from outside.
Critical infrastructure gets its own tier
CII Protection is the largest document by control count and the most structurally rigorous. It classifies assets into four tiers, mapped against confidentiality, integrity, and availability impact:
| Level | Impact of compromise |
|---|---|
| Most Critical | Catastrophic: extreme safety threats, extreme financial damage, or complete business shutdown |
| Highly Critical | Severe disruption of essential services, high financial damage, safety threats |
| Critical | Noticeable but manageable operational issues, medium financial damage, limited safety threats |
| Non-Critical | Minimal operational effect, tolerable financial impact |
A CII owner has 30 days to notify its sector regulator of any material change to a critical system. Recovery is measured against RTO, RPO, MTTD, and MTTR together, not uptime alone. Breaches on designated CII go to the sectoral CERT within 72 hours, the same cadence GDPR uses for personal data breaches in the EU. Non-critical infrastructure gets 120 hours.
Governance is the real test
The technical controls are specific and checkable. The governance document asks for something harder: an information security function organizationally independent from IT, led by someone reporting directly to the head of the organization, sitting on a formally notified steering committee, with a documented RACI matrix and a dedicated budget line. Organizations without headcount are told to convert redundant positions rather than leave the role unfilled.
For a federal ministry with an existing IT wing, that is demanding but achievable. For a provincial department running IT and security out of the same two people, it is a reorganization, and it has to happen before the other twelve documents mean much in practice.
What to watch
- The first publicly known CII incident disclosed inside the 72-hour window, or the first one that misses it
- The first documented case of a data center losing tenants after failing its annual third-party audit
- Whether provincial departments get budget and headcount to match the governance mandate, or PISF becomes another unfunded compliance line
Where this fits
Part of an ongoing series on Pakistan's cloud, AI, and digital infrastructure from a practitioner's perspective. Previous posts: Pakistan's Domestic Routing Mandate Closes the Network Layer, Pakistan's 5G Moment Is Also a Sovereign Cloud Moment, SBP's Cloud Regulatory Framework, and The 2026 Pakistani Cloud Map.
- Website: https://waqaruddin.com
- Medium: https://medium.waqaruddin.com/