PISF 2026 Explained: What the Essential Governance Controls Actually Ask For

PKCERT has released the Essential Governance Controls document under the Pakistan Information Security Framework 2026 (PISF 2026). This is the first of 13 control documents that make up PISF, and it lays out 27 numbered controls that decide how information security is supposed to be organised inside a government body before anything else in the framework can work properly.

This document applies to federal and provincial ministries, divisions and departments, autonomous bodies, corporations, CERTs, and any system officially designated as Critical Information Infrastructure. It covers not just the organization’s own staff, but contractors and third parties as well.

We are starting this series with Governance for a simple reason. Firewalls, backups, and audit checklists only work if someone is clearly responsible for them, has a budget to run them, and answers to someone senior when they fail. That is what this document tries to fix first.

pisf-banner-1-money-and-people

Money and people, before anything technical

The document opens with what it calls the implementation ecosystem, and it is refreshingly direct about money and staffing.

Every organization is required to set aside dedicated funds in its annual budget for information security, covering solutions, training, certification, and audits. This has to be planned for, not found later.

On staffing, the document gives two paths. An organization can either convert redundant, vacant, or underused positions into dedicated information security roles, or hire new people for the job. If an organization does not have the in-house expertise for consultancy, risk assessment, or audits, it is allowed to outsource this work, but only to firms registered with the National CERT, the relevant regulator, or a sectoral CERT, and only through PPRA-compliant bidding, meaning the normal government procurement rules still apply.

Oversight sits above all of this. Compliance audits are carried out by the National CERT, NTISB, sectoral CERTs, and the relevant regulator, so an organization cannot mark its own homework.

pisf-banner-2-who-owns-it

Someone has to own it, and that person cannot also run IT

This is the part of the document that will actually change how offices are structured, and it is worth reading carefully.

The head of the organization, the principal accounting officer, or the governing board is ultimately accountable for information security governance, risk management, oversight, and compliance. That responsibility cannot be delegated away and forgotten.

Below that, a dedicated information security function has to be set up, and it must be independent from the IT department. This is repeated more than once in the document, so it is clearly a point PKCERT wants organizations to take seriously. The person leading this function, whatever title they carry (CISO, CIO, CRO, or an officer of BS-20 grade or equivalent) reports directly to the head of the organization, and the document specifically says this reporting line must not create a conflict of interest with IT. In other words, the person checking whether systems are secure should not be reporting to, or be the same person as, the one who built and runs those systems.

A steering committee for information security has to be formally set up and notified, led by the organization’s top management, with the security lead sitting on it as a member. This committee is where roles and responsibilities actually get defined, documented, and approved, again with the same instruction that no conflict of interest should arise from how those roles are assigned. The committee is also required to document a RACI matrix (Responsible, Accountable, Consulted, Informed) for all data, systems, and processes, so that when something goes wrong, there is no confusion about who does what.

There is also a staffing rule that is easy to miss but matters in practice: security roles and IT roles have to be filled by full-time, qualified people, and staff in these roles cannot be pulled into unrelated administrative or support work. In a lot of Pakistani government offices, IT staff end up handling anything vaguely technical, from fixing printers to managing procurement software. PISF is explicitly telling organizations to stop doing that with security and IT roles specifically.

The steering committee has to report regularly to top management, not just file a document once a year. And the organization has to build a proactive monitoring mechanism for its own systems and controls, so leadership has a real, current picture of its security posture rather than finding out during an audit.

Written policies, not just good intentions

The information security function is responsible for writing, documenting, and implementing the organization’s actual security policies and procedures. These have to be formally approved by the steering committee before they are shared with staff, and they have to line up with whatever guidance the National CERT or the relevant sector regulator issues from time to time. A security policy that exists only as an unwritten understanding among two IT staff does not meet this bar.

Leadership has four specific jobs, not just a signature

The document spells out exactly what “leadership commitment” means, and it is more concrete than the phrase usually implies. The head of the organization or top management has to make sure four things happen: a written information security strategy exists and lines up with relevant laws, a roadmap exists to actually implement that strategy and gets reviewed on a set schedule, an organizational structure exists with the staff and budget needed to run security properly, and senior management actively oversees this work, including making sure security training is mandatory and its effectiveness is actually checked, not just delivered.

pisf-banner-3-no-change-without-process

Nothing changes without going through a process

Any change to information systems, applications, infrastructure, configurations, or security controls has to go through a formal, approved change management process. Before a change is made, the information security function has to assess it for security risk, compliance impact, and effect on operations. No change goes ahead without proper authorisation based on clearly defined roles. The only exception is genuine emergency changes needed to deal with an active incident or vulnerability, and even those have to be formally reviewed and documented after the fact, not left unrecorded.

Compliance does not stop at the organization’s own walls

Two final requirements round out the document. First, the organization has to keep an up to date record of every law, regulation, standard, and contractual obligation that applies to it, and have an independent internal audit function that checks compliance, tracks findings, and reports results to management. Second, that same scrutiny extends to vendors and third parties: the organization has to assess and audit suppliers, check their security compliance, and verify that any legal authorisations and controls they claim actually hold up.

Why this is a bigger ask than it looks

On paper, 27 controls across seven short sections does not look like much. In practice, this is asking many government offices to restructure how they work. A department where the same two or three people currently handle IT and security together will need a real reporting line change, a formally notified committee, a documented RACI matrix, and a budget line that may never have existed before. That is not paperwork you finish in an afternoon.

The honest test of this document will not be how well it reads. It will be whether provincial departments and smaller autonomous bodies actually get the staff and budget to make the separation between IT and security real, or whether Governance becomes the one PISF requirement that gets signed off without changing anything on the ground.

Full Sources List:
Pakistan Information Security Framework (PISF) 2026, “Essential Governance Controls,” published by the National Cyber Emergency Response Team, Government of Pakistan.
PKCERT official PDF Document

Get notified when we publish

No spam, unsubscribe anytime.

Read our privacy policy for more info.

Leave a Comment

Your email address will not be published. Required fields are marked *