Pakistan to Bring Overseas-Hosted Government Websites Back to Local Data Centres

The new cybersecurity framework mandates stronger monitoring, annual security audits, penetration testing and multi-factor authentication across government digital systems

The federal government has decided to gradually move government websites, applications, and other digital services currently hosted overseas to data centers located in Pakistan, according to an official document.

The move is aimed at strengthening the security, oversight, and digital sovereignty of government systems while reducing reliance on foreign hosting infrastructure.

The National Cyber Emergency Response Team has prepared the Pakistan Information Security Framework, which sets out a series of mandatory cybersecurity measures for government institutions, data centers, web applications, and official email systems.

Under the framework, public-sector organizations will be required to prepare a phased migration plan for transferring their websites and applications to local data centers.

The document states that government data centers must deploy advanced firewalls, continuous cyber monitoring, and systems capable of detecting threats at an early stage. They will also be required to establish security operations centers and implement modern cybersecurity monitoring tools.

Government departments will have to maintain secure backups, conduct regular vulnerability assessments, and ensure continuous monitoring of their digital infrastructure. An independent third-party security audit will also be mandatory at least once a year.

Official email systems will be required to include advanced protection against phishing attempts, spam, and malware. Multi-factor authentication will be compulsory for administrative accounts and webmail access.

The framework also calls for the implementation of secure backup, archiving, and domain authentication technologies across government email services.

All government web applications will have to be developed using secure software development practices and strong authentication mechanisms. Regular security assessments, penetration testing, and the timely removal of identified vulnerabilities will also be compulsory.

Public-sector organizations will also be responsible for monitoring the cybersecurity obligations of developers, hosting companies, and cloud service providers working on their behalf.

The framework introduces additional requirements for the physical and operational security of data centers. These include backup power systems, generators, and round-the-clock monitoring of environmental conditions.

Data centers will be required to adopt special safeguards against fire, flooding, water leakage, and other environmental hazards that could disrupt government digital services or damage critical infrastructure.

The document further states that environmental control systems must undergo regular inspections and maintenance. Any incident involving such systems will have to be investigated as part of the government’s broader risk management process.

The proposed measures signal a broader shift towards locally controlled digital infrastructure and stricter cybersecurity standards across government institutions. However, the effectiveness of the policy will depend on implementation capacity, technical expertise, funding and compliance across federal and provincial departments.

Also read:

Sindh Govt’s Important Websites go down due to a Malfunction at NTC

Mobile Phone Taxes Portal

Find the PTA Taxes on All Phones on a Single Page using our Taxes Portal.

Note: Mobile phone tax rates and calculations fall under the jurisdiction of the Federal Board of Revenue (FBR), not the Pakistan Telecommunication Authority (PTA).

Explore NowFollow us on Google News!

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
>