Firstpost
  • Home
  • Video Shows
    Vantage Firstpost America Firstpost Africa First Sports
  • World
    US News
  • Explainers
  • News
    India Opinion Cricket Tech Entertainment Sports Health Photostories
  • Asia Cup 2025
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
Trending:
  • Nepal protests
  • Nepal Protests Live
  • Vice-presidential elections
  • iPhone 17
  • IND vs PAK cricket
  • Israel-Hamas war
fp-logo
Govt bans foreign firms from conducting IT security audits of critical sectors for fear of sensitive data being leaked
Whatsapp Facebook Twitter
Whatsapp Facebook Twitter
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
  • Home
  • India
  • Govt bans foreign firms from conducting IT security audits of critical sectors for fear of sensitive data being leaked

Govt bans foreign firms from conducting IT security audits of critical sectors for fear of sensitive data being leaked

Yatish Yadav • November 29, 2019, 14:57:33 IST
Whatsapp Facebook Twitter

In the wake of the cyber attack on Kudankulam Nuclear Power Plant, the government has directed the ministries and departments handling India’s critical infrastructure to avoid hiring foreign firms to conduct IT security audits of its systems and networks

Advertisement
Subscribe Join Us
Add as a preferred source on Google
Prefer
Firstpost
On
Google
Govt bans foreign firms from conducting IT security audits of critical sectors for fear of sensitive data being leaked

New Delhi: In the wake of the cyber attack on Kudankulam Nuclear Power Plant, the government has directed the ministries and departments handling India’s critical infrastructure to avoid hiring foreign firms to conduct IT security audits of its systems and networks. Even, Indian firms empanelled for auditing will require clearance from domestic spy agency, Intelligence Bureau (IB) to rule out any foreign links. Security audits in all the ministries and critical sectors are carried out to ensure that country’s information infrastructure is not vulnerable to attacks by hackers and that all the systems have a secure government firewall. According to the documents reviewed by Firstpost, Computer Emergency Response Team (CERT-IN) — under the purview of the Ministry of Electronics and Information Technology — has prepared a list of auditing firms in consultation with the IB. In case any government department is planning to hire firms outside of the list, security vetting by the IB has also been made mandatory. “Since engaging non-Indian firms for auditing requirements by the government organisations and critical sectors may involve exposing sensitive information to non-Indian persons/entities or having foreign links, the concerned government ministries and organisations should obtain no-objection certificates from IB/Ministry of Home Affairs before engaging any non-Indian firms,” the documents said. [caption id=“attachment_5397041” align=“alignleft” width=“380”]Representational image. Reuters. Representational image. Reuters.[/caption] It has been further observed that critical sectors are facing threats from multiple sources and increasing attacks on the systems are organised and targeted with the help of criminals and State actors to reap immense benefits out of information compromise or espionage. The cyber criminals may carry out fraud, conduct espionage to steal state and military secrets and disrupt critical infrastructures by exploiting the vulnerabilities in any system. Worse yet, hackers can cover their tracks so that they cannot be traced and in a post-attack situation, is extremely difficult to prove whether the cyber criminal is an individual, a gang or a group of State actors. “The public sector, although increasingly relying on information technology, has not fully awakened to the challenges of security. Economic stability depends on uninterrupted operations of banking, finance, critical infrastructure such as power generation and distribution, transport systems of rail, road, air and sea which are critically reliant on information technology. Even though the focus has been on improving systems and providing e-governance services by various institutions, the IT networks and business processes have not placed the desired emphasis on information security,” the government documents said. There are three other directives which have been issued for critical sectors for protective monitoring of sensitive data and threat emanating from terrorist groups or enemy State. First, these sectors need to have adequate measures for grouping, formation and arrangement of counter measures for security of information infrastructure. Second, efforts are to be made to integrate security measures with information technology architecture to address contemporary and changing threats to critical database stored on government computers. Third, there will be mandatory disclosure of all attacks to the IB, so that any data breach can be resolved in a timely manner. Employees handling sensitive servers will be required to disclose the mobile device they are carrying, its serial number, model number along with details like security capabilities and vulnerabilities. The critical sectors will reserve the right to control official data on the employee’s mobile, including the right to back up, retrieve, modify, determine access or delete the organisation’s data without prior notice. The government documents said since mobile devices possess network connection capabilities, they can be exploited to connect to the organisation’s internal networks and can become a point to breach security. Also, individuals or experts hired for security audits of government systems will have to sign a non-disclosure agreement to prevent leakage of sensitive data. “Every auditing firm and its auditors (trained personnel) engaged should sign non-disclosure agreements before being allowed to commence the cyber security auditing work. To the extent feasible, it may be ensured that any data collected during the auditing work and report prepared thereof is not allowed to be taken out of the government premises by such auditors/firms,” government documents further added.

Tags
NewsTracker Intelligence Bureau Cyber crime Information technology cyber security Kudankulam Nuclear Power plant CERT In critical infrastructure Ministry of Electronics and Information Technology
End of Article
Latest News
Find us on YouTube
Subscribe
End of Article

Impact Shorts

NDA's CP Radhakrishnan wins vice presidential election

NDA's CP Radhakrishnan wins vice presidential election

CP Radhakrishnan of BJP-led NDA won the vice presidential election with 452 votes, defeating INDIA bloc's B Sudershan Reddy who secured 300 votes. The majority mark was 377.

More Impact Shorts

Top Stories

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Who is CP Radhakrishnan, India's next vice-president?

Who is CP Radhakrishnan, India's next vice-president?

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Israel targets top Hamas leaders in Doha; Qatar, Iran condemn strike as violation of sovereignty

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Nepal: Oli to continue until new PM is sworn in, nation on edge as all branches of govt torched

Who is CP Radhakrishnan, India's next vice-president?

Who is CP Radhakrishnan, India's next vice-president?

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Israel informed US ahead of strikes on Hamas leaders in Doha, says White House

Top Shows

Vantage Firstpost America Firstpost Africa First Sports

QUICK LINKS

  • Mumbai Rains
Latest News About Firstpost
Most Searched Categories
  • Web Stories
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Tech/Auto
  • Entertainment
  • IPL 2025
NETWORK18 SITES
  • News18
  • Money Control
  • CNBC TV18
  • Forbes India
  • Advertise with us
  • Sitemap
Firstpost Logo

is on YouTube

Subscribe Now

Copyright @ 2024. Firstpost - All Rights Reserved

About Us Contact Us Privacy Policy Cookie Policy Terms Of Use
Home Video Shorts Live TV