Showing posts with label CYBER SECURITY IN INDIA. Show all posts
Showing posts with label CYBER SECURITY IN INDIA. Show all posts

Friday, 23 December 2011

Data Security, Cyber Security And Privacy In Indian Banking Industry

Banking industry of India is passing through a transformation age. From technological upgradations to enacting new regulatory norms, banking sector of India is all set for a big change. However, this change is also very demanding and challenging in terms of legal obligations and technological knowledge. Banks in India are finding it difficult to cope with both.

For instance, banks in India are required to not only ensure cyber due diligence in India but also cyber security due diligence in India. Reserve Bank of India (RBI) has very categorically told Indian banks to ensure effective cyber security in their day to day affairs and banking transactions. However, banks in India are not complying with RBI’s cyber security due diligence requirements due to lack of awareness and technical expertise.

Further, on the compliances front as well, banks in India are not doing the needful. For instance, as per RBI’s recommendations, all banks should create a position of chief information officers (CIOs) as well as steering committees on information security at the board level at the earliest. Till now banks in India have not fulfilled these requirements.

Similarly on the front of cyber security Indian banks have not performed well. Cyber security for banking and financial sectors of India is not up to the mark. Internet banking risks in India are in abundance and we have no cyber security of Internet banking in India. Even cyber due diligence for banks in India is not taken seriously by Indian banks. Cyber security of online banking systems in India is by and large below average and many cases of banking financial frauds and cyber crimes have been reported in India.

Even the mobile banking in India is risky as the present banking and other technology related legal frameworks are not conducive for mobile banking in India. We have no dedicated Internet banking laws in India or mobile banking laws in India. Mobile banking transactions in India are risky and untrusting in the absence of mobile cyber security in India. We are still not ready for mobile governance in India as m-governance in India is not going to be successful in the absence of a sound mobile governance policy of India.

Data security and privacy in Indian banking industry is another area that requires special attention of Indian banks. Banks in India must ensure privacy protection and data protection of its customers.

The corporate and banking laws in India are in the process of being streamlined. An Integrated modern banking law in India is also in pipeline. RBI has also prescribed an enhanced due diligence measures by banks of India for higher risks customers. Overall, the emphasis is upon ensuring data security, cyber security and privacy protection by banks operating in India.

Thursday, 7 April 2011

National Cyber Security Policy Of India

Cyber law of India is weak and so is cyber security of India. In fact, cyber security of India is in poor state. We have no cyber security strategy of India and this is resulting in a weak and vulnerable cyber security of India. India is facing serious cyber threats and its cyberspace is not at all secure. Cyber terrorism against India is now a well known fact and cyber espionage against India is even admitted by Indian government. Even defence forces of India need to upgrade their cyber security capabilities. We also have negligible cyber forensics capabilities in India and cyber skills development in India is the need of the hour.

Cyber terrorism in India, cyber crimes and cyber attacks against India are increasing because we have no national security policy of India. Further, we also have no national security an ICT policy of India. Obviously national cyber security in India is not upto the mark in the absence of networks security in India.

National Security Policy of India is urgently required and Cyber Security Policy of India must be an essential part of the same, says Praveen Dalal, managing partner of New Delhi based Law Firm Perry4Law and leading techno legal expert of India. Increasing Cyber Security Readiness with Adaptive Threat Management is need of the hour, suggests Dalal. Further, Measurement of ICT Resilience and Robustness on regular basis is also required, suggests Dalal.

Even cyber security research and development in India is lacking. We have a single and exclusive techno legal cyber security research, training and education institution of India. The same is managed by Perry4Law and Perry4Law Techno Legal Base (PTLB). It is managing issues like cyber law, cyber security, cyber war, cyber espionage, cyber forensics, etc.

In order to ensure strong cyber security, Indian cyber security policy must be formulated as soon as possible. Critical infrastructure protection in India and Critical ICT infrastructure protection in India must be an integral part of the same. Further, national ICT crisis management plan of India must also be formulated. Indian crisis management plan for cyber attacks and cyber terrorism is still not ready and the same must formulated immediately.

Further, Cyber law policy of India and cyber crime policy of India must also be formulated. Data security and cyber security laws in India are also required. Presently, we have no data security, data protection, privacy protection and cyber security laws in India. Cyber terrorism preparedness in India must also be made part of the homeland security of India. In short, cyber security policy is needed in India and it cannot be postponed any more. The sooner it is formulated the better it would for the national interest of India.

Wednesday, 6 April 2011

Cyber Forensics Courses In India

Cyber forensics in India has been increasingly seen as a career option. With increasing use of information and communication technology (ICT) in India and increasing cyber crimes, demand for cyber forensics experts in India is going to increase.

For instance, it took central bureau of investigation (CBI) and Indian computer emergency response team (CERT-In) more than four months to trace even the basic level information like Internet protocol address. CBI and CERT-In were investigating the website defacement of CBI claimed to be done by cyber army of Pakistan.

The chances of catching the culprits are very dim, claims Praveen Dalal, managing partner of New Delhi base techno legal firm Perry4Law and leading techno legal expert of India. This is because of two reasons. Firstly, it has been more than Four Months since the attack took place. Till now most of the Logs would have been either deleted, tampered with or modified, informs Dalal. Secondly, there are great chances that Insecure Wireless Connection must have been used for committing this attack, informs Dalal. This makes it next to impossible to detect the true identity of the attacker after this long delay, claims Dalal.

This shows India is not ready for the growing demands of cyberspace that is under constant cyber attacks. India is under constant cyber threats and cyber terrorism attacks. Further, cyber security of India is also not upto the mark. Even there are no standards for measurement of ICT resilience and robustness in India.

While the cyber attacks are increasing in India yet the professionals to tackle the same are missing. At this stage the importance of techno legal research, training and educational centre of Perry4Law Techno Legal Base (PTLB) assumes significance. PTLB is managing the exclusive techno legal cyber forensics training and education centre of India.

PTLB and its cyber forensics centre are providing techno legal cyber forensics courses in India. Further, they are also providing domain specific cyber forensics training in India. This is done through the online platform of PTLB.

If you wish to be a successful cyber forensics professional world wide, joining of the courses of PTLB is a must. Since seats are limited, early registration is beneficial.

Sunday, 27 March 2011

Cyber Crimes And Network Security In India

Cyber crimes are increasing in India at an alarming speed. With a poor track record of cyber crime convictions, the situation is even more worrisome. The law enforcement officials in India are not well versed with cyber law related issues. The cyber crime cells operating in India lacks expertise to nab cyber criminals.

If this is not enough, the information technology act 2000 has made almost all the cyber crimes bailable in India. Cyber criminals can commit these bailable cyber crimes and roam free on bail as a matter of right.

While cyber criminals have almost no need to fear from the Cyber Law of India, yet Companies, Organisations and Intermediaries must observe Cyber Due Diligence in India, informs Praveen Dalal, managing partner of New Delhi based law firm Perry4Law.

If you are a Bank operating in India, you must also meet the mandatory requirements to create a position of Chief Information Officers (CIOs) as well as establish Steering Committees on Information Security at the Board Level at the earliest, informs Dalal. This is required to ensure effective cyber security for banks and financial institutions operating in India.

Further, system administrators must also observe due diligence regarding Indian cyber law and cyber security requirements. By showing a lax attitude towards cyber security, these system administrators may find themselves booked under the laws of India.

As cyber crimes increase in India and due diligence requirements becomes more stringent, it would be a sound practice to adopt effective cyber crime policy for an organisation. Further, organisations and individuals must also pay enough attention to the cyber security requirements of their networks.

These days, network security has become very important for business entities. Almost all the organisations are connected with cyberspace and this makes their networks vulnerable to cyber attacks. Network security must be an integral part of the security policy of all organisations. An increasing awareness about network security in India has been seen and this is a good step in the right direction.

Friday, 25 March 2011

Information Security Policy Of India

Information security in India is a very crucial part of homeland security of India. However, despite information security being a crucial field, it is in poor state of condition in India.

There are many factors for this poor information security in India. Two chief reasons for the same are lack of information security policy of India and absence of information security laws in India.

The importance of having an Information Security Policy is not only now being acknowledged even by top management of organisations but has also been recently made mandatory by the Reserve Bank of India (RBI) for banks operating in India, informs Praveen Dalal, managing partner of new Delhi based law firm Perry4Law and leading techno legal expert of India.

In fact, recently the RBI has released its Information Technology Vision Document 2011-17 that endorses the requirements for having strong information security for online banking and offline banking transactions. The document also mandates that all banks would have to create a position of chief information officers (CIOs) as well as steering committees on information security at the board level at the earliest, informs Dalal.

Lack of information security policy of India is also casting doubts whether India is capable of tackling the cyber terrorism attacks against it. Further, cases of cyber espionage and cyber attacks are also increasing in India.

On top of it, we have a weak cyber law of India that gives a free hand to cyber criminals’ world wide. If India wishes to secure its cyberspace, it must formulate a robust and effective information security policy of India. This policy must be supplemented by stringent cyber laws of India. Till these steps are taken, Indian cyberspace would remain vulnerable to cyber attacks, cyber terrorism and cyber espionage.

Wednesday, 23 March 2011

Cyber Security Laws In India

Cyber security is a very crucial part of homeland security of India. Indian cyberspace and crucial governmental computer systems have been systematically breached from time to time.

In April 2008, Indian intelligence agencies detected Chinese hackers breaking into the computer network of the Ministry of External Affairs. Similarly, for almost 3 months the e-mail communications from Prime Minister’s Office (PMO) got affected as the e-mail system was infected by a malware.

Despite the importance of this field, very little ahs been done in this regard in India, Firstly, the cyber law of India is extremely weak to tackle the growing cases of cyber crimes and cyber attacks. Secondly, there are no cyber security laws in India. However, the most glaring example of indifference towards cyber security in India is the absence of a cyber security policy of India.

According to Praveen Dalal, managing partner of Perry4Law and leading techno legal expert of India, India has to pay attention towards securing its Critical Infrastructures and Protected Systems. The present attitude of India in this regard is far from satisfactory, says Dalal.

It is clear that issues like cyber security, critical infrastructure protection, cyber warfare capabilities, anti terrorism and anti cyber terrorism measures, etc have still not got the attention of Indian government. Till these issues are raised at national level and adopted as the national policies, not much can be expected from Indian cyber security, opines Dalal.

India needs to formulate stringent cyber laws and effective cyber security legislations. The entire exercise must be undertaken after formulating effective and robust cyber security policy. The sooner it is done the better it would be for the national interest of India.

Monday, 21 March 2011

National Cyber Security In India

Cyber security of India is ailing from various drawbacks. As a result India has not been able to fully capatilise the benefits of cyber security. There is no doubt about the proposition that cyber security in India must be improved urgently.

Although everybody talks about improving cyber security in India yet none provides the formula to do so. The safest and surest formula to strengthen Indian cyber security is to formulate an effective and robust cyber security strategy and policy of India.

India has another very compelling reason to ensure robust and resilient cyber security. The critical national infrastructure of India cannot be safeguarded from cyber attacks if India has a weak cyber security infrastructure, inform Praveen Dalal, managing partner of Perry4Law. With more and more public services now delivered though Internet, e-governance and computer systems, it is pertinent to ensure their integrity and security, suggests Dalal.

In fact, Indian government has released the draft electronic delivery of services bill 2011 that would ensure effective electronic delivery of services in India once it becomes an applicable law. However, the proposed mandatory delivery of electronic services would face many problems including cyber security problems.

If the essential public services are made electronic without ensuring robust cyber security, it would be a nightmare for India, warns Dalal. The government must ensure a strong cyber security for the infrastructure providing electronic delivery of services to Indian citizens, suggests Dalal.

National cyber security of India has to cover a long distance before we can call ourselves a reasonably cyber safe nation. India must increase cyber security readiness with adaptive threat management. Further, India must also ensure cyber due diligence compliances and cyber security audits, incidence response and threat analysis, first responder’s utilisation and other similar practices to ensure efficient cyber security practices.