Just a moment...

Top
Help
×

By creating an account you can:

Logo TaxTMI
>
Call Us / Help / Feedback

Contact Us At :

E-mail: [email protected]

Call / WhatsApp at: +91 99117 96707

For more information, Check Contact Us

FAQs :

To know Frequently Asked Questions, Check FAQs

Most Asked Video Tutorials :

For more tutorials, Check Video Tutorials

Submit Feedback/Suggestion :

Email :
Please provide your email address so we can follow up on your feedback.
Category :
Description :
Min 15 characters0/2000
TMI Blog
Home / RSS

Issued updated Security Manual for Licensed Defence Industries (SMLDI), 2025

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... Dated : 23-07-2025 ============= Document 1 सत्यमेव जयते Government of India Ministry of Defence Department of Defence Production SECURITY MANUAL FOR LICENSED DEFENCE INDUSTRIES (SMLDI) (Revised in June, 2025) 0 INDEX S. No. Topic Page No. 1 List of Abbreviations used 7 2 Foreword 9 3 Executive Summary 10 Category-A 12 4 Chapter 1- General Provisions, Requirements and Responsibilities 13 1.1 Scope 1.2 Authority 1.3 Responsibility of the Management and Employees 5 Chapter 2- Security Organisation and Personnel Security 15 2.1 Company Chief Security Officer (CCSO) 2.2 Cyber Information Security Officer (CISO) 2.3 Security Staff 2.4 Responsibilities and duties of CCSO 2.5 Reporting procedure 2.6 Personnel Security 6 Chapter 3- Security of Premises and Physical Security Measures 22 3.1 General 3.2 Physical Security Measures 3.3 Layout of Premises 3.4 Reception Office and Visitors 3.5 Material Gate 3.6 Watch Tower 3.7 Setting up of Plant Security Council 3.8 Identity Badges, Entry Passes for personnel /vehicle and Parki....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....ssified area / zone 7.10 Cyber Posture Enhancement via integration with Defence CSOC 11 Chapter 8- Subcontracting 71 8.1 General 8.2 Terms and conditions related to classified information 8.3 Engagement of Consultants/Advisers 2 8.4 Audit Recommendations 12 Chapter 9- International Security 72 9.1 Imports of Equipment/Materials 9.2 Warning to Consignees 9.3 Handing and Taking Over 9.4 NDA for transfer of classified information between two countries 9.5 Movement 13 Chapter 10- Visits and Meetings 74 10.1 Visit of foreign nationals 10.2 Meetings 10.3 Nomination of employees from ILDC to attend Classified Meetings 14 Chapter 11- Training 77 11.1 General 11.2 Security briefing 11.3 Training 11.4 Refresher Training 11.5 Security training of Vendors/Contractors and Casual Labourers 11.6 Training of project work Trainees 11.7 Training on Cyber Security 15 Chapter 12- Miscellaneous 79 12.1 General 12.2 Publicity and Photography 12.3 Trials / Demonstration 12.4 Rejects and Salvage 12.5 Disaster Management 12.6 Internal Security Audit 12.7 Action on Completion of Audit 12.8 External Securit....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....st of Documents, Checks and Annual accounting 5.6 Care and Custody of Classified Documents and Equipment / Responsibility of Holders 5.7 Notebooks of PAs 5.8 Segregation and Care of SECRET Section 5.9 Security Arrangements for SECRET Section 5.10 Guarding - Provision for Lighting 5.11 Duplicating Work. 5.12 Reprographic Equipment. 5.13 Opening and Diarizing of Classified Documents. 5.14 Transmission of Classified Documents 5.15 Emergency Procedures 5.16 Disclosure 5.17 Down Grading, Disposal and Destruction of Classified Documents and Equipment 21 Chapter 6 - Communication Security 118 6.1 General 6.2 Telephones 6.3 Cell or Mobile Phones /Data Cards /Voice Modems 6.4 Fax Communications 22 Chapter 7 - Computer and Cyber Security (Information Systems 121 Security) 7.1 General 7.2 ISO 27001 7.3 Common Requirements 7.4 Enterprise Resource Planning (ERP) 7.5 Physical and software security 7.6 Acquisition of Computer hardware and software 7.7 Miscellaneous aspects 7.8 Guidelines for computer users or operators 7.9 Instructions for use of Internet within classified area / zone 7.10 Cyber Posture Enhance....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....ial Security Force A.11 CMD Chairman and Managing Director A.12 CONFD Confidential A.13 COTS Commercial of The Shelf A.14 CPMF Central Para Military Force A.15 CrPC Criminal Proceeding Code A.16 CSA Competent Security Authority A.17 CISO Cyber Information Security Officer A.18 DDoS Distributed Denial of Service A.19 DDP Department of Defence Production A.20 DFMD Door Framed Metal Detector A.21 DGR Director General of Resettlement A.22 DKIM Doman Keys Identified Mall A.23 DMARC Domain-based Message Authentication, Reporting, and Conformance A.24 DoC Department of Commerce A.25 DoS Denial of Service A.26 DPIIT Department for Promotion of Industry & Internal Trade A.27 DPSU Defence Public Sector Undertaking A.28 DSA Designated Security Agency A.29 DSC Defence Security Corps A.30 GSM Global System Monitoring A.31 HQ Head Quarters A.32 IAM Identity and Access Management A.33 ID Identification Card A.34 I(D&R) Industries Development & Regulations Act A.35 ILDC Indian Licensed Defense Company A.36 IoT Internet of Things 7 A.37 IPC Indian Penal Code A.38 IPS Internet Protocol Security A.39 IR&D In-hou....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....be put in place by the licensee. The licensee shall follow the detailed instructions issued by the concerned licensing authorities and Department of Defence Production, Ministry of Defence from time to time for strict compliance. This Security Manual therefore, is issued for compliance by licensed defence companies in the private sector as a part of the licensing conditions prescribed in the Industrial License. In the context of this Manual, License means Manufacturing license/Industrial License/Defence License issued by the licensing authorities. Further, the term ILDCs denotes all the private companies which have been issued Defence Industrial License and DPSUs of Ministry of Defence. 3. This Security Manual prescribes minimum standards of security and other safeguards required to be put in place by the licensee in the interest of national safety and security. The contracting agencies such as Service Headquarters/DRDO/DPSUs etc may specify higher degree of cyber security requirements over and above the baseline requirements mentioned in this manual for specific projects based on risk assessment undertaken by them. Specific attention in this regard is also drawn to the Official....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....tructions or if the areas of operation/ manufacturing are not possible to be segregated, the security instructions applicable to the higher level of security would be applied. Categorisation of the companies/products will be as per orders issued by the MoD from time to time. Presently, the items classified into Category A and Category B broadly includes below mention attributes :- Category- A: Products that are highly classified and sensitive from the security angle and the manufacturing of these items would require the highest level of security. The illustrative examples of products under this category are arms, ammunitions, explosives, propellants, propulsion, aircrafts, warships, battle tanks, radars, weapons, software and various types of charges. Category- B: Semi-finished products, sub-assemblies, sub-systems of main weapons/ equipment/ platforms and some finished products of lesser degree of sensitivity. The illustrative examples of products under this category are wing assemblies/ structural assemblies/ barrel assemblies/ turret/ avionics etc. 2. The level of security will depend upon the category of the product that the company intends to manufacture. Under all ci....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....rity - Procedure for Import of equipment, movement of equipment; Handing and Taking Over procedures. X. Visits and Meetings - Guidelines on visits of foreign national(s),procedure to be adopted for processing security clearance XI. Training- Describes responsibility of ILDCs to provide Security training and briefing of employees. XII. Miscellaneous - Guidelines on Internal Security Audit, Waste Management, Disaster Management and Compliance Statement. The provisions of the Security Manual are applicable to CEO/Head of the organisation, CCSO, CISO, Management tier including all the employees of the ILDCs alongwith the contractors, sub-contractors, dealing with the affairs of the company. In the event of non-adherence of security guidelines by ILDC, action shall be taken against the ILDC and/or individual person(s) as per relevant Government regulations/provisions in various Acts, such as IPC, CrPC, I(D&R) Act, Arms Act, OSA 1923 etc. 11 CATEGORY A 12 CHAPTER - 1 - General Provisions, Requirements and Responsibilities 1.1 Scope: 1.1.1 The Manual is applicable to all Licensee companies engaged in the production of defence products and issued Industrial Li....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....urity regulations by any member of the staff working under him or in that 13 department, or of any misconduct, of such a nature as would give rise to doubts about the staff member's integrity/ reliability from the security point of view. The CCSO will maintain the data of all such reported instances along with the Action Taken which will be made available to the external security audit team. 1.3.4 Whenever a new employee joins the company and/or the department, the superior officer of the employee will ensure that the new incumbent has read and understood the contents of the manual and shall take an undertaking in writing to this effect. 14 CHAPTER - 2 - Security Organisation and Personnel Security 2.1 Company Chief Security Officer (CCSO): Each ILDC or its multi-location units shall appoint an Indian Citizen as the CCSO, the CCSO should be an ex-Army/ ex-Air Force/ ex-Navy/CPMF/Police Officer who would ensure that security measures necessary for implementing applicable provisions of this Manual are in place and the manual is being implemented in the true spirit of the intention. Persons of Indian Origin and Non- Resident Indians shall be excluded from such app....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... 2.2.1.1 Duties of Management Tier 15 The Management Tier, headed by the CEO/MD, assisted by CISO, shall have the following roles and responsibilities: - a) Responsible for taking executive decisions pertaining to ICT infrastructure for Organisation. b) Decision making body for overall policy matters. c) To take strategic decisions and evaluate opportunities in the field of Cyber Security and Cyber Defence, and countering cyber threats. d) To ensure maintenance and enhancement of the overall cyber posture of the organisation. 2.2.1.2 Duties of Cyber Information Security Officer- a) Ensuring cyber security posture of the Organisation b) Implementation of cyber security controls over entire network. c) Cyber security and incident response. d) Maintain awareness of emerging threats and vulnerabilities. e) Implementation of Cyber Crisis Management plan. f) Internal Information security audit of IT systems and controls g) Maintaining and updating the threat landscape for the Organisation. h) Ensuring review of the Cyber Security Policy by the designated expert agency to check for the adequacy and effectiveness of the existing policy in for....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....y Audits of the Organisation. b) Function as operations support and emergency response provider in case of Cyber Security incidents with the Organisation. c) Handling cyber threats, vulnerability detection/ mitigation etc. d) Advise IT division of the organisation for effective patch management of ICT infrastructure. Issue guidelines for timely dissemination of patches/Hot fixes/Service packs/Updates for IT assets. e) Formulate and disseminate Cyber Security advisory on latest cyber security threats and trends. f) Issue security advisories and instructions. g) Ensure the cyber hygiene and compliance to Cyber Security policies of the Organisation's IT assets. h) Carry out risk analysis and suggest mitigation measures/ enhancing security of the organisation. i) Support in formulating Cyber Security policy and carrying out periodic review in consultation with ISO & CISO. j) Organise periodic training and awareness campaigns for personnel on Cyber Security. k) Organise seminar/conference on cyber security to brainstorm/assess the current challenges/requirements of the Organisation. l) Ensuring furnishing of all reports mandated by Security Manual to MHA....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....on. d) To prevent recurrence and suggest remedial measures. e) To report Cyber Attack/Data Breach to CISO. 18 2.4.2 If classified information or materials have been compromised/ lost/ found in wrong place, it is to be reported by concerned employee immediately in writing to the CCSO who shall take necessary action. 2.4.3 As and when cases of security violations are detected by the Security Staff, the same is to be reported to the CCSO on occurrence. These will be followed immediately by formal violation reports addressed to the head of the department who will thoroughly investigate the matter and furnish an action report within a week. 2.4.4 Enquires to have a tentative time frame by which it will be completed, in addition, progress report shall be submitted to the office of the Company Chief Security Officer till the case is finalized. 2.5 Reporting Procedure: 2.5.1 The ILDC shall, at the earliest, report in writing to the nearest Police Station, local office of agencies of MHA and the Nodal Office, DDP regarding any information or materials in regard to actual, possible or probable espionage, sabotage, terrorism, subversive activities or adverse informatio....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....pport activities of NCIIP / CERT-In/ Nodal Office, DDP /other agencies of MHA and MoD. 2.6.2 To ensure that there is no leakage of information it is necessary to observe the precautions given below: - a) Character and antecedent verification through police, reference checks, previous employment verification has to be carried out for all persons before joining the ILDC. b) In case any adverse police report is received against an individual dealing with classified matters, on re-verification, generally after every three years, he or she shall be transferred out immediately. Persons employed on TOP SECRET work shall be subjected to prior positive vetting by Nodal Office, DDP, and also every two years thereafter. In case adverse police report pertains to national security, an enquiry shall be initiated by Plant Security Council(defined in para 3.7) under relevant law/act/internal guidelines, the individual shall not only be suspended but also barred from office access during the course of enquiry. 20 c) Only permanent employees shall be posted in TOP SECRET and in SECRET sections to deal with classified documents. d) Police Verification shall be conducted i.r.o. all c....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....tion cameras along with manned controlled room may be put into place for perimeter security. 3.3.3 There should be lighting arrangement all along the perimeter wall to allow clear observation during hours of darkness. 3.3.4 To reinforce manual observation and to have data available for investigation, the perimeter should be covered by CCTV with recording facility for 90 days. The Guidelines issued by Ministry of Electronics and Information Technology (MeitY) on CCTVs from time to time shall be strictly adhere to. 3.3.5 If required, electric fence may be deployed along the perimeter wall. Further, Tunnelling and culvert protection measures shall be undertaken for perimeter security. 3.3.6 If possible the patrolling track should be on either side of perimeter wall so that security personnel manning the watchtowers have clear view of the perimeter wall; besides, they can quickly move to the spot for the problem, if situation so arises. 3.3.7 There should be no construction close to the wall and a distance of minimum 05 mtrs be maintained inside the wall. Wherever possible, no construction zone of 50ft from the compound wall may be maintained. Vegetation near the perimet....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....nescorted. The visitor shall not be allowed to leave the reception office without an escort. 23 3.4.5 Official visitors from Ministry of Defence, Government of India, MHA in possession of valid ID cards will also be issued with the visitors ID card at the reception office; however, such visitors need not be escorted inside the classified area/zone/office. 3.4.6 No visitor shall be entertained after working hours. In exceptional circumstances where a visitor has to stay beyond the specified time, clearance of designated officer as decided by CCSO should be taken and security should be kept informed of the same. 3.4.7 Security Control room shall be situated near the factory main gate. 3.4.8 Medics: First Aid Room to be set up. 3.5 Material Gate: Entry & exit of all material, raw, processes, garbage and scrap must take place only through the designated gate, which, as far as possible, should be divested from the employees. Provision of Weigh Bridge be made at the material gate 3.5.1 Communication: Gates are required to be connected to the security control room besides the office and residence of the security officer through a communication network that is depen....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....rrangements and take corrective actions. In case of Multi Facility Organisation, Headquarters security representative will also be included as a member in the quarterly reviews. The Record of the proceedings shall be maintained by the company. The council may also bring to the notice of Local Police/Nodal Office of DDP any cases pertaining to security violation, theft/pilferage, espionage, sabotage, terrorism, subversion activities or adverse information about any employee. 3.8 Identity Badges, Entry Passes for personnel /vehicle and Parking of Vehicles: Entry into Classified zone/area/offices would be regulated on the basis of photo Identity cards issued by the CCSO. The Identity Badge should have following details: a) Company logo b) Name and photograph of the employee c) Staff Number and pass number d) Signature of issuing authority e) Blood group f) Date of issue and validity g) Signature of employee h) Address of Unit 3.8.1 These ID cards are to be returned to CCSO on the date of expiry of their validity or when no longer required. The identity badges should be reissued once in 5 years so that latest photo is reflected on the badge. The Secu....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... 3.8.3 Vehicle Stickers: Vehicle stickers would be issued by the CCSO to employees who are on permanent basis and who have a valid photo ID card issued by the CCSO for parking in designated area outside the installation. 3.8.4 Loss of Identity Cards: Loss of ID card should be reported immediately to the CCSO along with an investigation report from the concerned section/office. CCSO may thereafter take further necessary action as per the policy of the company/office/organization. A database of stolen/lost ID cards will also be maintained with proper and regular Cyber audit of the computers used in the issuance of ID cards. 26 3.8.5 All sections shall maintain a list showing name, designation, identity card number, local resident address and permanent home address contact number of the employees working in area/zone/office handling classified information. 3.8.6 The ID card, vehicle sticker and any other documents issued to an employee would be withdrawn and submitted to the CCSO prior to dismissal, suspension or transfer of the employee. 3.9 Keys of the Organization: 3.9.1 Keys to the offices rooms/areas/zones holding classified information should be kept in a se....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....ng beer, wine and all alcoholic drinks) would be strictly prohibited inside the plant. 27 3.14 Security Measures for Sensitive / Secure / Storage Areas for Classified Equipment: The storage area may be declared as Vital Point with the following safeguards: - a) Additional Boundary Wall and Power Fence to prevent any intrusion, if required. b) Access control for authorised personnel through photo identity and/or proximity/smart/biometric card based systems. Biometric Access Control System must be installed at vital/sensitive points. Further, facilities shall devise second level access authorization for entering the operational area/server room. c) Frisking and Baggage screening of employees of persons moving in/ out of the Vital Point shall be enforced. d) Banning electronic gadgets, cameras, storage devices inside the Vital Points shall be enforced. Carrying of Smart phones high-end mobiles with cameras and other features also to be banned. e) Patrolling in and around the Vital Points including night patrolling by Guards and Dog squads if required shall be carried out. Night patrolling should be mandatorily provisioned at staggered intervals covering the ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....Such authority should be restricted to a few officers only and their specimen signatures should be available at the gate for easy and quick identification. Computerized Material Management System (CMMS) for returnable/non-returnable goods shall be installed for generating gate pass and data backup. 4.2 Inward Material Register: Entry will be made in the register in respect of all materials that come into the plant, either brought by the contractors as sample, or brought by the stores officers as supplies/samples, for which inward materials gate pass has been issued by the security gate officers. Samples and such other materials taken back should be crossed out after the party has returned the inward materials gate pass. 4.3 Material Gate Pass Register: This register shows materials that went out of the factory under an authorized gate pass. The time and nature of materials sent out and brought back be recorded by the gate staff. The time of return however should be noted. A specimen signature book showing the signature of the officer authorized to sign passes should also be maintained. 4.4 Material Gate Pass: A model material gate pass procedure is given below. Th....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....All abnormal delays will be documented with specific reasons. 4.10 Issue of Gate Passes: Gate pass should be issued to all materials including stationary items taken out of the gate. 4.11 Transfer of Classified information: When drawing in CDs/any electronic form are exchanged with subcontractors/ vendors in case outsourcing activity involving technology transfer of classified projects or indigenous classified projects for manufacturing components, it should be sent in sealed cover with material gate pass signed by authorized personnel. The CCSO will authorise a person for supervising the movement of such information. 31 Sealing & dispatch should be done appropriate to the classification of projects. The subcontractor/vendor who has been given any classified project or information would also be bound by the provisions under "Official Secrets Act, 1923". 4.12 Items brought by customers/suppliers as samples or for demonstration: Items brought by customers/suppliers as samples or for demonstration/try out/rectification/repairs etc. should be allowed 'INWARD GATE PASS' by 'Security in-charge' at gates. The materials will be allowed to be taken out on the same ga....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....of explosive and classified materials. Consignor as well as consignee would keep the Superintendent of Police of the district falling on way between the place of consigner and the place of consignee informed. g) When classified Equipment is sent by road in India, the vehicles will, as far as possible, be harboured during the night in Military unit en-route. The information for such an arrangement has to be forwarded to MoD well in advance of the planned movement, to arrange for the necessary security clearance with the military authorities concerned. In absence of Military units, they will harbour within civil police station. Where neither of the two courses is possible, the dispatching authority will approach the civil authorities through their higher formation, for affording security protection and other assistance to the convoy en- route. The superintendent of police of the district falling on the way between the place of consignor and the place of consignees should to be informed. GPS tracking devices on the equipment / vehicles to continuously monitor the movement of classified materials / equipment may be installed. 33 CHAPTER - 5 - Handling of Documents and Equipmen....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....yone except for official purpose. e) UNCLASSIFIED: The designation UNCLASSIFIED is used to identify information and equipment that does not require a security classification. 34 Note: Documents or equipment not covered by any of the above categories shall be regarded as unclassified. 5.2 Guidelines on Classification: 5.2.1 A document should be given a classification which it really deserves. Over classification or under classification can be detrimental. 5.2.2 If a document or equipment bearing higher security classification is added to a file, document or material, the file/document/ material itself will be upgraded to that classification. 5.2.3 The document or equipment as a whole shall bear the highest security grading that any particular part of it may deserve. The grading of a file or of a group of physically connected documents or materials must be that of the higher graded document/ material therein. 5.2.4 Officers authorized to classify: The originator of the document will be authorized to classify the document / upgrade / downgrade the same. It is the responsibility of the originator that care is taken of such documents so that the same do not fall ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....ttached to the original information or material released. 5.4 Accounting of Classified Documents and Equipment: 5.4.1 Reference Number: Classified documents and equipment shall be given code or other reference number, which will be used in correspondence to avoid reference to their titles and subject matter. 5.4.2 Copy numbers or Receipts or making of Spare Copies. The following important aspects shall be kept in view in this regard: - (a) When more than one copy of TOP SECRET document is made, they shall be given copy numbers and each page shall be serially numbered. (b) The transmission of TOP SECRET and SECRET documents shall be covered by a receipt system. The sender shall enclose a receipt for completion and return to the sender by the addressee. (c) If the receipt for a classified document does not reach the issuing authority within seven days, the issuing authority shall ascertain whether the document has in fact been received, if not the same to be reported to CCSO. (d) Letters or documents including appendices, if any, shall have continuous page numbers. The total number of pages of a TOP SECRET or SECRET letter or document will be indicated in word....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....h designated entry/exit points. 5.6.1 All categories of classified documents and equipment will be regarded as under the personal charge of the individual to whom the same is issued as recorded and by whom a receipt has been given. 5.6.2 Other Classified Documents and Equipment will be regarded as under the charge of the person to whom the custody of these documents and materials has been entrusted by the Head of the office concerned. 5.6.3 Individuals in charge of Classified Documents and Materials are responsible for their safe custody and their disclosure is limited to only those required to know. The concept of need to know to be followed. 37 5.6.4 Proper handing /taking over of all documents to be carried out whenever an individual is transferred or superannuating. 5.6.5 In case any employee transferred from one classified section to other section, an undertaking should be obtained from the employee that "No information regarding the functional aspects of the section, cases or reference of any cases will be discussed / disclosed by him / her. 5.6.6 The holders of classified documents will carry out periodic checks. 5.6.7 Classified documents will not be....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....he highest category of document contained in the safe. f) The company security staff must check employees / staff carrying briefcase, purses at exit/entry to see that no official takes out/in any classified paper without written authority from the Competent Authority. g All almirahs containing classified documents will have a cross marking on it and it shall be written as "to be removed first in case of fire". 5.7 Notebooks of PAs: 5.7.1 Note-books after utilization of PAs should be returned to the officer under whom he works who will keep it in his personal custody and destroy it after the expiry of three months from the date of the last entry in the note book. 5.7.2 The Short-hand note books should remain in the custody of the officer. After typing out the dictation, the PA should return it to the officer. In no case will it be kept in the locker provided to the PA for storing stationery etc. 5.7.3 Any notebook, disc, tape, film, cassette laptop, PCs etc. which has been used to record classified material, should be treated as a classified document and should be kept in the custody of the officer. Classified work done on Laptops, PCs will not be stored in the har....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....by the CEO/ Head of the Company. 5.12 Reprographic Equipment: The reprographic equipment shall be under the personal custody of an officer. It shall be located in his room and he shall be personally responsible for the custody, operation and accounting of the documents reproduced. Any change of the officer or change of location of equipment should immediately be reported to the CCSO, whose personnel shall make periodic checks to verify the system of the accounting. The machine should always be kept under lock, while not in use. 5.13 Opening and Diarizing of Classified Documents: (a) Opening (i) On receipt of TOP SECRET documents the inner cover will be handed over by the opening personnel to the Officers. All TOP SECRET covers will be opened by the addressee or in his absence by the officer officiating for him. (ii)SECRET or CONFIDENTIAL documents will be opened either by the addressee or a person so authorised by him. (b) Diarizing (i) The diarizing of all TOP SECRET documents shall be carried out either by the officer to whom it is addressed or by his personal staff so authorised by him. The diarizing of SCERET documents may be entrusted to the lower level at....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....t seal bearing a number issued by the CCSO. The closing and sealing of SECRET and CONFIDENTIAL inner covers shall be carried out by or under the supervision of Section Officer or Personal Assistant or equivalent. iii. All departmental seals issued to different branches/groups/ units must be numbered and a list must be maintained by the issuing authority showing person to whom it has been issued. All such persons will be responsible for the security of these seals. iv. In case of any loss of such seal, matter should immediately be reported to the CCSO and authority concern for necessary action on their parts. Besides, other seals of the same series should be treated as compromised. Later, a new series of seal with different shape and design should be issued as early as possible. (c) Movement of Classified Documents i. For movement of classified paper within office, a box, may be of steel or of thick leather / Rexene/ canvas provided it has a proper locking arrangement and cannot be easily cut/pierced/ opened/ tampered, need to be used. Under no circumstances should classified documents be carried loose in the hands of the messengers/ orderlies. ii. A messenger carryin....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....equipment. (d) Carrying Classified Documents or Equipment to Residence or Outside Office. Carrying of classified documents and equipment to residence of officers is prohibited. All Top Secret papers should be dealt with in office only. i. Officers are generally prohibited to carry any Top Secret paper to their residence. When it is necessary to send a Top Secret paper to CEO/ authorized senior officer at his residence after office hours, the dispatching officer should obtain his specific instructions that it may be sent to his residence and that he would be ready to receive the document at his residence. 42 ii. The dispatching officer must ensure that the box in which Top Secret document is sent, is locked and fastened to the vehicle in which the messenger is carrying it. iii. When an officer having authority to do so carries any Top secret document to his residence, he must take the documents only in securely locked bag/box, the key of which must be in his possession. The bag/box must be kept all along in his personal custody till he reaches his residence where also this must be placed in a secure place to which no outsider may have access. iv. Whenever an office....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....papers/documents for the meeting. These documents will not be carried to residence except where permitted. 5.15 Emergency Procedures: ILDCs shall develop procedures for safeguarding classified equipment in emergency situations. The procedures shall be as simple and practical as possible and should be adaptable to any type of emergency that may reasonably arise. ILDCs shall promptly report to the designated agency any emergency situation that renders the facility incapable of safeguarding classified equipment. 5.16 Disclosure: 5.16.1 General: ILDCs shall ensure that classified information is disclosed only to authorized persons. 5.16.2 Disclosure to Employees: ILDCs are authorized to disclose classified information to their authorized employees as necessary for the performance of tasks or services essential to the fulfilment of a classified contract or subcontract. 5.16.3 Disclosure to Subcontractors/ other persons/other ILDCs: ILDCs are authorized to disclose classified information to a subcontractor when access is necessary for the performance of tasks or services essential to the fulfilment of a prime contractor a subcontract. Prior authorization shall be obtained ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....l have no authority to downgrade / upgrade the security classification of a document received from other department without the concurrence of the originator. 5.17.3. Upgrading Action: When a notice is received to upgrade equipment to a higher level, the new markings shall be immediately entered on the equipment according to the notice to upgrade, and all the superseded markings shall be obliterated. The authority for and the date of the upgrading action shall be entered on the equipment. 5.17.4 Disposal: Classified documents will be examined from time to time with a view to reducing the number of such documents held. Accountable documents, if no longer required by holder, will be returned to the issuing authorities. 5.17.5 Destruction: TOP SECRET, SECRET or accountable CONFIDENTIAL documents will be shredded to small size without being able to be reconstituted and shall be destroyed by burning and a proper record be maintained under the supervision of authorised officer. Documents other than classified may be destroyed at the discretion of the head of the office concerned. 5.17.6 Other points on destruction: a) Record of daily destruction of classified waste, indica....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....tion w.r.t Social Media Usage, Cyber best practices and handling calls/manning Exchange. (d) Any attempt by the caller/ adversary to impersonate as government official seeking sensitive information should be blocked and officials should be wary of such calls from calls. Specifically, to prevent leaking of information through such calls, following procedure should be followed: - (i) Do not provide any information without establishing the identity of the caller. (ii) Take down the caller's contact number and seek time to revert back. (iii) If any suspicion arises during the call, cancel the call. (iv) Do not disclose any sensitive information over phone to anyone. (v) Don't be tricked into giving away confidential information. (vi) If any email is received from an operative of unfriendly countries, forward that email to CERT-IN for further necessary action. (vii) If the email attachment is opened by the user, immediately disconnect that PC from network and scan the network for the presence of malware. (viii) Any such calls or email shall be report to the CISO immediately (e) To prevent misuse, telephones should be kept locked when the officer is away fro....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....eing worked upon. On special cases permission to carry mobile phones by critical staff, in these areas shall be recommended by the Head of department and granted by CCSO. Mobile phones are not permitted inside conference halls, operations rooms, at official briefings and at sensitive places even in off mode. This instruction is applicable to even those who have been permitted. Mobile phone with camera and other technical advance features including internet, GSM, etc. should not be allowed irrespective of ranks inside the office premises. No visitors will be permitted to carry mobiles inside the facility, the mobiles of visitors are to be deposited at the reception. 48 6.4 FAX communications: FAX communications are also vulnerable to interception or leakage, e.g. a cross- connection. It is, therefore, necessary to identify the end party before transmitting a message. Papers which are not of classified or sensitive nature may be transmitted with the help of FAX in emergent cases. Under no circumstances such an option is exercised for transmitting classified documents. No classified message should be passed or received on Fax on auto mode. 6.4.1 While using Fax machines a ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....romising data /information by remote access. (c) Susceptibility to Ransomware and Denial of Service Attacks (d) Susceptibility to Phishing, Smishing and Vishing Attacks (e) Accidental/Intentional cross connection between the Organization Local Area Network and Internet. (f) Spoofing by intruders. (g) Defacing of various Websites by anonymous Hackers. 7.1.6 In addition to above, any advisory issued by the Government from time to time shall be strictly complied with. 50 7.2 ISO 27001: 7.2.1 The companies shall follow guidelines under ISO 27001. Appropriate controls shall be implemented to accommodate the guidelines given in this manual. 7.2.2 This International Standard has been prepared to provide a model for establishing, implementing, operating, monitoring, reviewing, maintaining and improving an Information Security Management System (ISMS). 7.2.3 This International Standard adopts a process approach for establishing, operating, monitoring, reviewing, maintaining and improving an organization's ISMS. 7.2.4 The process approach for information security management presented in this International Standard encourages its users to emphasize the impo....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....nd restoration mechanisms. These must be tested on a regular basis. (f) Configuration rules of Firewall, IDS/IPS, UTM, EDR/UEBA, SIEM/SOAR (g) Industry 4.0 policy for safety of Cyber Physical and SCADA/ICS Systems. (h) Disaster Recovery policy with focus on data security while assuring business continuity. (i) (a) Restrict privileged accounts on the system to only those organisation- identities personnel who require this access compulsorily to carry out their allotted tasks which require access to controlled defence information (b) Require that users (or roles) with privileged accounts use non-privileged accounts when accessing functions or information not related to allotted tasks which require access to controlled defence information (j) (a) Prevent non-privileged users from executing privileged functions. (b) Log the execution of privileges functions. (k) Unsuccessful Logon Attempts Limit the number of consecutive invalid logon attempts to an organisation- defined number and an organisation-defence time period. (l) System use notification Display a system use notification message with privacy and security notices consistent with applicable contro....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....e use of any centralised IS resource. e) To maintain the CIA, control and audit logging mechanism along with monitoring system should be in place, for changes to data includes deterring, detecting and reporting of successful and unsuccessful attempts to change etc.Such monitoring system can be implemented by deploying solutions like Security incident and Event Management (SIEM), Security Orchestration Automation and Response (SOAR) and User and Entity Behaviour Analytics (UEBA). f) Use of next generation technologies like Zero Trust Architecture will help in attack surface reduction. Also for granular level control Identity and Access Management (IAM) solutions are recommended. g) Control and audit logs should be available in centralised systems/applications for Successive Logon Attempts, Multiple Logon Control, Session termination and User Inactivity etc. The logs retention period must be for a period of minimum 180 days. h) Security should be ensured for inter connectivity of multiple LANs, when organisation has multiple Units/Offices across the geographical location, where interconnectivity may be WAN (Wide Area Network) using public networks. 53 i) When Pub....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....dents mandatorily to be reported to CERT- In: (i) Targeted scanning/ probing of critical networks/systems. (ii) Compromise of critical systems/ information. (iii) Unauthorised access of IT systems/ data 54 (iv) Defacement of website or intrusion into a website and unauthorised changes such as inserting malicious code, links to external websites etc. (v) Malicious code attacks such as spreading of Virus/Worm/Trojan/Bots/Spyware/Ransomware/Cryptominers. (vi) Attack on servers such as Database, Mail, DNS and Network devicessuch as Routers. (vii) Identity theft, spoofing and phishing attacks. (viii) Denial of Service (DoS) and Distributed Denial of Service (DDoS)attacks. (ix) Attacks on Critical infrastructure, SCADA and operational technologysystems and Wireless networks. (x) Attacks on Application such as E-Governance, E-Commerce etc. Data Breach. (xi) (xii) Data Leak. (xiii) Attacks on Internet of Things (loT) devices and associated systems,networks, software, servers. (xiv) Attacks or incident affecting Digital Payment systems. (xv) Attacks through Malicious Mobile Apps. (xvi) Fake mobile Apps (xvii) Unauthorised access to socia....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....ndling capability for incidents that is consistent with the incident response plan and includes preparation, detection and analysis, containment, eradication and recovery processes and procedures. (ii) (iii) Update the incident response plan to address system and organisational changes or problems encountered during plan implementation, execution or testing phases. (VIII) Incident Monitoring, Reporting and Response Assistance (i) Track and document system security incidents. (ii) Report suspected incidents to the organisational incident response capability within an organisation-defined time period. (iii) Report incident information to CERT-In/NCIIPC as per timelines promulgated by these entities from time to time. (iv) Provide an incident response support resource that offers advice and assistance to users of the systems for the handling and reporting of incidents. 56 (IX) Incident Response Testing Test the effectiveness of the incident response capability periodically. (X) Incident Response Testing (i) Provide incident response training to system users consistent with assigned roles and responsibilities: a) Within an organisation-defined ti....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....ves etc). (ii) Shredding or secure disposal of console logs or printouts, used printer ribbons & carbons, damaged tapes and hard disks etc. (iii) Protection of Switches/Routers and other connectivity devices. 7.5.3 Network racks should be situated away from easily accessible public spaces like the pantry, cafeteria, restrooms, waiting rooms, hallways etc. Also these devices should be properly locked and must be under continuous surveillance using cameras. 7.5.4 Adequate protection is required both for the operating system software and application software. In order to prevent unauthorized access to the data, passwords should be assigned at multiple levels i.e. first at the time of making the system operational, second at the time of logging with the authorized user's name, third at the time of running application software and so on, depending upon the type of data being handled. It is very essential that there should be a provision of 'Audit Trail' features to know which user had logged in and at what time. a) Develop, approve and maintain a list of individuals with authorisation access to the physical location where the system resides. b) Issue authorisation cred....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....ommunication at the external managed interfaces to the system and at key internal managed interfaces within the system. b) Implement subnet works for publicly accessible system components that are physically or logically separated from internal networks. c) Connect to external systems only through managed interfaces consisting of boundary protection devices arranged in accordance with organizational security architecture. 7.6 Acquisition of Computer hardware and Software: 7.6.1 Computer hardware, which is proposed to be procured, should be of an open system or architecture and the user should be free to go in for 'Annual Maintenance Contract' with any party. The systems being procured should be the latest ones which can be upgraded at a later date. 59 7.6.2 If development of software application is outsourced, antecedents of the personnel/company developing the software should be verified. Where necessary, Non-Disclosure Agreements (NDA's) must be signed by the Contractor / sub-contractors. Further, for critical applications the vendor should be asked to provide source code for the application developed by him. Whenever feasible, dummy data should be used for test....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....pects: 7.7.1 Each ILDC shall formulate a clearly defined Cyber Security Policy, based on which a third party cyber security audit shall be conducted. This auditor shall be selected by the ILDC from the list of certified Cyber Security Auditors as published by Computer Emergency Response Team - India) CERT-In, on their web site. (i) The risk to secrecy of data due to the human factor should also not be underestimated. The following measures should be adopted in this regard :- a) Adequate separation of duties and restriction of access in every office so that no single person can individually compromise the entire system or data. b) Triennial character and antecedent verification of critically placed functionaries of the computer system handling sensitive information by CCSO through civil police. c) Cyber Awareness and Evaluation Module should be an integral component of employee induction training. Also on a periodic basis, recurring cyber security awareness training and evaluation sessions must be conducted to keep all employees informed and vigilant regarding cyber security matters. d) In-house sensitization and periodical briefing of concerned personnel of variou....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....ging supply risks associated with the research, development, design, manufacturing, acquisition, delivery, integration, operations, maintenance and disposal of the system, system components or system devices which are related to or store or harness-controlled defence information. Review and update the supply chain risk management plan periodically. Protect the supply chain risk management plan for unauthorised disclosure. t) Acquisition Strategies, Tools and Methods. Develop and implement acquisition strategies, contract, tools and procurement methods to identify, protect against and mitigate supply chain risks. u) The Software must be developed and build in secure environments. Those environments must be secured by the following actions, at a minimum - Separating and protecting each environment involved in developing and building software. Regularly logging, monitoring and auditing trust relationships used for authorisation and access to any software development and build environments among components within each environment. v) Enforcing multi-factor authentication and conditional access across the environments relevant to developing and building software in a manner tha....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... powers to the Unit Head for issuing written approvals. However, the responsibility and accountability of the same shall still rest with the CEO. All instructions relating to classified documents contained in this Manual are equally applicable to External / Portable Hard Drives. Carriage of External / Portable Hard Drive inside/outside the office premises is not permitted. Secondary storage Devices register will be maintained by the respective sections/departments. Internal physical check will be carried out within the concerned sections/departments every week and result indicated in 63 the register. Sections/departments will render a quarterly certificate to the CCSO regarding safe custody of the pen drives in their sections/departments. No visitor/employee will be permitted to use or carry personal pen drive / External / Portable Hard Drives within the classified area/zone. Loss of External / Portable Hard Drive will be reported to CCSO immediately, and investigations carried out simultaneously by the sections/departments, to ascertain the extent of loss of classified information and to pinpoint responsibility for the loss for initiating suitable action against the defau....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... : a) Damaged and unusable Cartridge Tapes/ CDs/ DVDs/ Pen Drives and other CSM should be broken and destroyed by burning or as applicable to the weeding out paper based files and an entry to this effect be made in the register. CCTV recordings should be password protected. b) Bad / condemned hard disk should not be released even after it has been replaced by a new one. Such hard disks will be destroyed by following procedures as applicable to weeding out of classified files. c) Destructions should be carried out by application of corrosive Chemicals (acid or abrasive substances, emery wheel or disk sander) to the recording surface, and by shredding, incineration, disintegration, pulverization and smelting etc. 7.7.8 Cyber Security Audit: a) The CISO must supervise all computer security measures within his offices/ branches/section. The CISO shall not be a foreign citizen, or a Personof Indian Origin who is a Non-Resident Indian. b) Cyber Security Audit must be carried out under the strict supervision of Cyber Information Security Officer (CISO). c) Periodic security audit of the IT is liable to be carried out by designated Govt Agencies, from time to time, to ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....ged and appropriate audit trails be maintained on the system in electronic form. (vii) Before deleting the sensitive files, overwrite the files with some junk data to prevent restoration of the sensitive data by any means. Keep the backup of operating system software and application software under safe custody. One backup copy should be kept in different location as a precaution against fire hazards. (viii) Backup data should be periodically updated. Keep the software maintenance tool in your own custody. The periodic checking of backup inventory and testing of the ability to restore information validates that the overall backup process is working. This may be given to the engineer called to attend to the faults in the system as and when required. (ix) External CD writers will be under the custody of officer only. CD writer will be used only in minimum and unavoidable files and data. (x) Ensure safe custody of the Computer Storage Media such as cartridge tapes, Pen Drives, CDs etc. (xi) Every new incoming storage media or software should be tested for Virus. Always use original software purchased from the authorised vendors. (xii) (xiii) Copying of data, deleti....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....ignificant risks associated with individuals are discovered. (xxx) Notify organisational personnel or roles when - a) Accounts are no longer required. b) Users are terminated or transferred c) System usage or need to know changes for an individual (xxxi) Information in Shared System Resources. Prevented unauthorised and unintended information transfer via shared system resources. (b)DON'Ts. (i) Don't let any unauthorized persons use your computer system. (ii) Don't share your password with anyone, not even your colleagues. 67 (iii) Don't reveal the root password to any unauthorized person, particularly an outsider. (iv) Don't connect the computer directly to the mains. Also, no heavy electric load drawing machines like plain paper copier, shredding machines, coolers etc. should be connected to the source of constant voltage supply to the computer. (v) Do not connect your computer system storing classified data to internet. (vi) Don't allow staff members to bring their own storage medias or software to run on the computer system of the department. (vii) Don't use pirated or gifted copies of software as these may contain viruses and even faci....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... PC will be kept isolated from all other systems, especially LAN/Intranet. Connection of any other system with Internet line for any purpose, whatsoever, is strictly prohibited. No official or personal files will be stored on the hard disk of Internet PC. Personal media will never be used on Internet PC. No sensitive/ classified office work will be done in Internet computers. 7.9.1 All official work will be carried out on a system belonging to Air Gapped Network. Air Gapped Network will be isolated from the Internet at the physical layer. The air-gapped network's devices should meet following criteria: (i) Must have a separate networking equipment, including switches and routers, accompanied by cables of a different colour to easily differentiate them from internet-related cables. (ii) Specially designated desktop computer (referred as Entry-Exit system) must be used for moving data into/out of Air-gapped network. (iii) Only officially recognised Thumb Drive/Pen Drive can be used on Entry-Exit system for data exchange. This Pen Drive will always remain in safe custody of CISO or any other officer designated by CISO. Every issue of Thumb Drive/ Pen Drive will be recorded....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....arred from using private email addresses (like Gmail, hotmail, yahoo, rediffmail etc.) for any form of official communications and emails from suppliers/contractors through private emails addressees should be barred, as far as possible. However, the employees should be discouraged to use official email id for registering into various non-official platforms like banking, insurance etc. (vii) Social media usage policy should be defined and enforced on all employees. Unless specifically required for discharge of their duties, employees must be prohibited from accessing social media sites from their official systems. Employees should be discouraged from publishing information related to their work. (viii) Server room/network room should have biometric access control systems with CCTV coverage in place (ix) Enforce approved authorisations for controlling the flow of controlled defence information within the system and between connected systems. 7.10 Cyber Posture Enhancement via integration with Defence CSOC: Industry entrusted with procurement orders/technologies developed by any Government agency of any such entity, privy to Defence related designs, plans, materials, do....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....he ILDCs shall make note of recommendations and take action as warranted as soon as possible but in any case not later than the timeline. 71 CHAPTER - 9 - International Security 9.1 Imports of Equipment/ Materials: (i) Where Sensitive Equipment/ Materials is bought or otherwise acquired by the ILDC, it should be ensured the equipment is securely packed and sealed and transported. The packages will not have any markings to indicate that the Equipment is Top secret / Secret. (ii) Top Secret and Secret Equipment/ Materials will not be shipped in Vessels / Flights which unload cargo in other countries or call at ports of unfriendly countries en-route. (iii) Bills of lading or other documents will not indicate the classification of the Equipment. Separate bills of lading may be made out for small consignments which are delivered to the Master of the Ship for personal custody during transit. These documents will indicate the equipment in general terms, e.g. Instrument, PCB and so on, but will not give precise details. (iv) Where possible, intimation will be sent to the consignee through official channels of the company. If time does not permit, intimation may be give....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....ng. Top Secret and Secret Equipment will be Handed/ Taken over under the direct supervision of authorized senior officer only. 9.4 NDA for transfer of classified information between two countries: The names of the Government Authority of each of the two countries empowered to authorise the release and to co-ordinate the safeguarding of Classified Information related to the Contract and the channels to be used for the transfer of the Classified Information between the Participants National Security Authority (NSA)/ Designated Security Authority (DSA)/ Competent Security Authority (CSA) and/or Contractors involved shall be governed by non-disclosure agreement. 9.5 Movement: (i) Consignors of Top Secret and Secret Equipment will warn the consignee of the dispatch of equipment so that the latter is in a position to make adequate security arrangements to receive it. All such equipment will be suitably shrouded and accompanied by an escort to ensure that no unauthorized person gains an access to them surreptitiously. (ii) When only portion of equipment is Top Secret or Secret and it is possible to conceal that portion, it is not necessary for the entire equipment to be cov....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....reigners, well in advance, giving the following particulars: - i. Full name of the visitor. ii. Nationality of the visitor. iii. Date of birth. iv. Parentage of the visitor. V. Permanent and Present address of the visitor. vi. Passport No with date and place of issue. vii. Validity of Passport. 74 viii. Visa details (types, data & place of issue and duration of visa) ix. Occupation and Name of the Firm / organization which the visitor is representing. X. Specific purpose of the visit. xi. If the foreigner has visited the establishment earlier, full details of the same is to be furnished. xii. Details of escort being provided for conducting the tour of the Foreign National(s). xiii. Address of Hotel/accommodation where the foreign visitor staying in India during the visit. xiv. The address of the Indian company with which the foreigner is having partnership/alliance etc. XV. Date & Time of visit xvi. Area to be visited xvii. Certificate that no classified document shall be shared with the foreign visitors. b) The particulars of the foreigners will be filled in a proper format and processed through CEO/Head of ILDC as the case ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....ion of employees from ILDC to attend Classified Meetings: The CEO may authorize its nominated employee(s) to attend certain classified meetings pertaining to classified information / sensitive information. It is the responsibility of CEO for non-leakage of information. 76 CHAPTER - 11 - Training 11.1 General: It shall be the responsibility of the ILDC to provide all employees with security training and briefing, commensurate with their roles and responsibilities while dealing with classified information. Towards this, the ILDC may obtain defensive security, threat awareness and other educational and training information from the nominated agency of Government of India, Ministry of Defence. 11.2 Security Briefing: All employees should be briefed on security do's/don'ts on joining as a part of induction programme.The induction programme must include Cyber Awareness Capsule. Prior to being granted access to classified information, an employee shall receive an initial security briefing that includes the following: a. A threat awareness briefing. b. A defensive security briefing. c. An overview of the security classification system. d. Employee report....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... respective College / University. 11.7 Training on Cyber Security: IT Division shall ensure that all personnel be appropriately trained on the Organization's Information Security policies commensurate with their roles and responsibilities and be kept up-to-date on any additions or changes to the policies. 78 CHAPTER - 12 - Miscellaneous 12.1 General: MoD will be the nodal agency for preparation, review and implementation of the manual. However, conducting inspection and audit would be the responsibility of MHA /MoD.MHA &MoD may take the assistance of other organizations like Agencies of MHA and MoD, DPSUs, NTRO etc. in the inspection or audit. 12.2 Publicity and Photography: No photography would be permitted inside the Classified Zone/Area pertaining to MoD projects without the approval of MoD. Photography, when permitted for official purposes, will be done under proper supervision and both the photos, soft copy of photograph and their negatives shall be appropriately classified. In the case of Top Secret and Secret Equipment, permission for photography or publicity will be granted by General Manager / Chief Executive of the manufacturing Division / Unit or ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... The disaster management plan should focus on data security while assuring business continuity. The BCP/DR backup sites (also referred as Secondary sites) should not be a source of data breach. Disaster Management Plan should be in line with the guidelines/instructions issued by the National Disaster Management Authority/State Disaster Management Authority. 12.6 Internal Security Audit: The ILDC shall carry out internal security audit to ensure verification of compliance of security instructions contained in this manual. The Security Audits are required to be conducted to ascertain the level of compliance of security instruction and procedures specified in the security manual. The audit shall be done at least on a yearly basis. If ILDC is Multi Facility Organisation (MFO), audit shall be done annually in each facility: - (a) Check compliance by all the establishments to realize the designed security objectives as enumerated in the security manual. (b) Verify the effective implementation of the instructions and identify lapses, if any. (c) Verify the efficacy of the existing Security & Fire Control System. (d) To check that adequate safeguards exist against espiona....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... and materials in its possession to the rightful owner or Ministry of Defence as the case may be, within 24 hours of such cancellation of the licence. 12.9.2 In case of breach, violation, non-adherence to the provisions of Security Manual, penal provision including financial penalties and denial of various RFPs/technical details/ToTs other contracts by the Government agencies including Service Headquarters, DRDO, DPSUs, etc may be imposed. 12.9.3 For an entity holding license under Arms Act, 1959 (Arms Act) strict adherence to the terms and conditions of the license is mandatory. Any violation of these terms and conditions may lead to cancellation of license and prosecution under the Arms Act, 1959. The provisions of the Explosive Substances Act, 1908 will also be applicable in cases involving in the manufacture, possession, storage or transport of explosives. 12.10 Alternate Power Source: An alternate power source is required to ensure that the system availability is maintained in the event of loss of primary power due to various reasons, including sabotage/subversion. 12.11 Investigations of compromising emanations: Compromising emanations are unintentional inte....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....t to environment, waste management, electronics waste disposal. The guidelines must include explicit procedures for the destruction of electronic devices at the end of their life cycle, especially emphasizing the secure wiping of sensitive data from storage devices to prevent potential data breaches. 12.14.1 Waste Management from health perspective: - Classification of waste will be done as chemical, hazardous, toxic and recyclable collection, transport, processing or disposal, managing and monitoring of waste materials. The term usually relates to materials produced by industrial activity, and the process is generally undertaken to reduce their effect on health, the environment or aesthetics. Waste management is a distinct practice from resource recovery which focuses on delaying the rate of consumption of natural resources. All wastes materials, whether they are solid, liquid, gaseous or radioactive fall within the ambit of waste management. 82 12.14.2 E-Waste :- Once the electronic device reaches its end of its life cycle, the data on the device must be destroyed by techniques like erasing, wing, and degaussing. Storage devices such as hard disks and flash drives should....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....mes into possession in any other way. 1.3.2 It is the duty of each employee of the company to immediately bring to the notice of his superior officer or the Company Chief Security Officer (CCSO), any breach of security regulations in general and/or in particular, any compromise on classified information or materials, either deliberately or inadvertently. 1.3.3 Every employee in the supervisory level is required to ensure, by frequent surprise checks, visits to office rooms and other places where his subordinates work or which they frequent and by all other means in his power, that the instructions laid down for the conduct of business and maintenance of security in company are fully understood and complied with by all of them. It will also be his duty to bring immediately to the notice of his superior officer, or to the officers responsible for security in his department, any instance of breach of security regulations by any member of the staff working under him or in that 85 department, or of any misconduct, of such a nature as would give rise to doubts about the staff member's integrity/ reliability from the security point of view. The CCSO will maintain the data of a....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

..... He shall also be responsible for incident management, identification of the organizations Critical Information Infrastructure assets and interaction with NCIIPC/CERT- In/Nodal Office, DDP and other agencies of MHA and MoD, as the case may be. The CISO must be of sufficient seniority to report directly to senior most management of the organization to ensure functional independence. The CISO may be assisted by additional staff as per the requirement of ILDC. It is the responsibility of the CISO to ensure that the organizational cyber security policy is adequately framed, implemented and audited to ensure necessary and sufficient protection from cyber threats. The CISO shall also clearly identify residual risk subsequent to implementation of requisite cyber security mechanisms. 2.2.1 Following organizational structure for Cyber Security shall be followed in ILDCs :- 2.2.1.1 Duties of Management Tier: The Management Tier, headed by the CEO/MD, assisted by CISO and CIOs, shall have the following roles and responsibilities :- 87 a) Responsible for taking executive decisions pertaining to ICT infrastructure for Organisation. b) Decision making body for overall policy m....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....et along with the custodian/ user. g) Ensure that the changes in the ownership are logged in the IT Asset file. The format for collating the details of IT Assets. h) Ensure that the IT Assets are not moved out of the respective division for which they were initially allocated without approval of the CISO. However, the same shall be properly documented. i) Ensure that the policies as laid down in this Cyber Security Policy are disseminated across to all personnel within the division. j) Ensure strict compliance with the laid down policies with respect to physical security of IT Assets. k) Comply with the instructions/ guidelines laid down as a part of the Cyber Security Policy. l) Act as the Nodal Officer for his/ her particular Wing/ Division/ Section as applicable for matters related to Cyber Security. 2.2.1.4 Duties of Cyber Security Division: a) Cyber Security Audits of the Organisation. b) Function as operations support and emergency response provider in case of Cyber Security incidents with the Organisation. c) Handling cyber threats, vulnerability detection/ mitigation etc. d) Advise IT division of the organisation for effective patch manageme....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....ndicating lapses noticed by him as and when it occurs. i) To arrange regular programs to apprise the employees on security matters. j) To maintain constant liaison with law enforcing agencies and nodal offices in Ministries. k) To carry out improvement in the security system for the premises under his charge, as required, over and above the security manual. l) To arrange Internal & External Security Audits m) To carry out a comprehensive personnel risk assessment, short listing of suspects and keeping them on watch list in coordination with HR and Vigilance Department. 2.4.1 When breach of security occurs, the main objectives shall be: - (a) To swiftly find out what has happened and modus operandi of the breach committed. (b) To minimise the damage done. (c) To investigate/ trace the culprit and report to CEO/ head of the company by fastest mode of communication. (d) To prevent recurrence and suggest remedial measures. (e) To report Cyber Attack/Data Breach to CISO. 2.4.2 If classified information or materials have been compromised/ lost/ found in wrong place, it is to be reported by concerned employee immediately in writing to the CCSO who shall....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....arest police station and Nodal Office, DDP immediately on occurrence, over and above, the same will be reflected in quarterly report. 2.6 Personnel Security: 2.6.1 Every ILDC shall ensure that no security leakage occurs through any personnel due to any reason, including, but not limited to, the following: - a) For personal gain. b) For political affiliations. c) Carelessness in talk and in handling documents. d) In correspondence. e) In communication. f) Transmission of classified documents. g) Conversations. h) In case of any breach in the cyber security infrastructure of the ILDC, (National Critical Information Infrastructure Protection) NCIIP (Computer Emergency Response Team- India) CERT-In/ shall be notified at earliest with a copy to Nodal Office, DDP. The ILDC shall ensure that all requisite information / assistance is provided by its personnel to support activities of NCIIP / CERT-In/Nodal Office, DDP /other agencies of MHA and MoD. 2.6.2 To ensure that there is no leakage of information it is necessary to observe the precautions given below: - a) Character and antecedent verification through police, reference checks, previous employment ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....ard to this effect shall be installed in trilingual at the main gate and around, also contemplating 'trespassers shall be prosecuted'. 3.2 Physical Security Measures: Physical security means security in the form of safeguarding the installation which would comprise of providing adequate safeguards against an intruder coming from outside to damage the installation. This includes securing the perimeter walls, gates, lighting, access control system of entry, protection of vital stores and designating restricted areas. 3.3 Layout of Premises: The installation must have perimeter as under 3.3.1 A 8 Ft wall with barbed wire fence / concertina coil. 3.3.2 Spot lights with Day & Night CCTV Cameras. 3.3.3 There should be lighting arrangement all along the perimeter wall to allow clear observation during hours of darkness. 3.3.4 To reinforce manual observation and to have data available for investigation, the perimeter should be covered by CCTV with recording facility for 90 days. The Guidelines issued by Ministry of Electronics and Information Technology (MeitY) on CCTVs from time to time shall be strictly adhere to. 3.3.5 There should be minimum number of gates. ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....ed with the visitor's ID card at the reception office; however, such visitors need not be escorted inside the classified area/zone/office. 3.4.6 No visitor shall be entertained after working hours. In exceptional circumstances where a visitor has to stay beyond the specified time, clearance of designated officer as decided by CCSO should be taken and security should be kept informed of the same. 3.4.7 Security Control room shall be situated near the factory main gate. 3.4.8 Medics: First Aid Room & Tie up with local Hospitals. 3.5 Material Gate: Entry & exit of all material, raw, processes, garbage and scrap must take place only through the designated gate, which, as far as possible, should be divested from the employees. Provision of Weigh Bridge be made at the material gate 3.5.1 Communication: Gates are required to be connected to the security control room besides the office and residence of the security officer through a communication network that is dependable and operational around the clock. 95 Also, alternate means of communication in the form of radio telephony should be available at the gates/ watch towers to ensure uninterrupted communication. ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....will also be included as a member in the quarterly reviews. The Record of the proceedings shall be maintained by the company. 96 The council may also bring to the notice of Local Police/Nodal Office, DDP any cases pertaining to security violation, theft/pilferage, espionage, sabotage, terrorism, subversion activities or adverse information about any employee. 3.8 Identity Badges, Entry Passes for personnel /vehicle and Parking of Vehicles: Entry into Classified zone/area/offices would be regulated on the basis of photo Identity cards issued by the CCSO. The Identity Badge should have following details: a) Company logo b) Name and photograph of the employee c) Staff Number and pass number d) Signature of issuing authority e) Blood group f) Date of issue and validity g) Signature of employee h) Address of Unit 3.8.1 These ID cards are to be returned to CCSO on the date of expiry of their validity or when no longer required. The identity badges should be reissued once in 5 years so that latest photo is reflected on the badge. The Security Department should keep relevant account of badges issued. All employees shall follow the following instructio....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....is and who have a valid photo ID card issued by the CCSO for parking in designated area outside the installation. 3.8.4 Loss of Identity Cards: Loss of ID card should be reported immediately to the CCSO along with an investigation report from the concerned section/office. CCSO may thereafter take further necessary action as per the policy of the company/office/organization. A database of stolen/lost ID cards will also be maintained with proper and regular Cyber audit of the computers used in the issuance of ID cards. 3.8.5 All sections shall maintain a list showing name, designation, identity card number, local resident address and permanent home address contact number of the employees working in area/zone/office handling classified information. 3.8.6 The ID card, vehicle sticker and any other documents issued to an employee would be withdrawn and submitted to the CCSO prior to dismissal, suspension or transfer of the employee. 3.9 Keys of the Organization: 3.9.1 Keys to the offices rooms/areas/zones holding classified information should be kept in a secured designated placed at the office of CCSO. The access to the secured designated place will be strictly limited. ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....es for Sensitive / Secure / Storage Areas for Classified Equipment: The storage area may be declared as Vital Point with the following safeguards :- (a) Additional Boundary Wall and Power Fence to prevent any intrusion, if required. (b) Access control for authorised personnel through photo identity and/or proximity/smart/biometric card based systems. (c) Frisking and Baggage screening of employees of persons moving in/ out of the Vital Point shall be enforced. (d) Banning electronic gadgets, cameras, storage devices inside the Vital Points shall be enforced. Carrying of Smart phones high-end mobileswith camerasand other features also to be banned. (e) Patrolling in and around the Vital Points including night patrolling by Guards and Dog squads if required shall be carried out. Night patrolling 99 should be mandatorily provisioned at staggered intervals covering the entire perimeter along with vital points. (f) CCTV surveillance must be provided at entry / exit of Vital Points and other sensitive locations inside the factory. Recording of all CCTV footage should be kept for 90 days. (g) A two key system may be used for stores holding sensitive hardware ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....4.2 Inward Material Register: Entry will be made in the register in respect of all materials that come into the plant, either brought by the contractors as sample, or brought by the stores officers as supplies/samples, for which inward materials gate pass has been issued by the security gate officers. Samples and such other materials taken back should be crossed out after the party has returned the inward materials gate pass. 4.3 Material Gate Pass Register: This register shows materials that went out of the factory under an authorized gate pass. The time and nature of materials sent out and brought back shall be recorded by the gate staff. The time and nature of materials sent out shall the gate staff showing that the item is brought back. The time of return however should be noted. A specimen signature book showing the signature of the officer authorized to sign passes should also be maintained. 4.4 Material Gate Pass: A model material gate pass procedure is given below. The ILDC should, as far as possible, evolve a proper gate pass procedure to suit the conditions prevailing in the respective divisions and get it issued under the signature of the competent authori....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....1 Transfer of classified information: When drawing in CDs/any electronic form are exchanged with subcontractors/ vendors in case outsourcing activity involving technology transfer of classified 102 projects or indigenous classified projects for manufacturing components, it should be sent in sealed cover with material gate pass signed by authorized personnel.The CCSO will authorise a person for supervising the movement of such information. Sealing & dispatch should be done appropriate to the classification of projects. The subcontractor/vendor who has been given any classified project or information would also be bound by the provisions under "Official Secrets Act, 1923". 4.12 Items brought by customers/suppliers as samples or for demonstration: Items brought by customers/suppliers as samples or for demonstration /tryout /rectification /repairs etc. should be allowed 'INWARD GATE PASS' by 'Security in-charge' at gates. The materials will be allowed to be taken out on the same gate pass after making proper entry in the office copy of the INWARD GATE PASS book. This procedure will be applicable to materials brought as samples. In case any electronic items(s) is/are brou....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... informed. g) When classified Equipment is sent by road in India, the vehicles will, as far as possible, be harboured during the night in Military unit en-route. The information for such an arrangement has to be forwarded to MoD well in advance of the planned movement, to arrange for the necessary security clearance with the military authorities concerned. In absence of Military units they will harbour within civil police station. Where neither of the two courses is possible, the dispatching authority will approach the civil authorities through their higher formation, for affording security protection and other assistance to the convoy en- route. The superintendent of police of the district falling on the way between the place of consignor and the place of consignees should to be informed. GPS tracking devices on the equipment / vehicles to continuously monitor the movement of classified materials / equipment may be installed. 104 CHAPTER - 5 - Handling of Documents and Equipment 5.1 Security Classification of Documents and Equipment: 5.1.1 Aims & objective of Document / equipment Security: To prevent a spy or an enemy agent from access to classified information/ equ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....r equipment not covered by any of the above categories shall be regarded as unclassified. 105 5.2 Guidelines on Classification 5.2.1 A document should be given a classification which it really deserves. Over classification or under classification can be detrimental. 5.2.2 If a document or equipment bearing higher security classification is added to a file, document or material, the file/document/ material itself will be upgraded to that classification. 5.2.3 The document or equipment as a whole shall bear the highest security grading that any particular part of it may deserve. The grading of a file or of a group of physically connected documents or materials must be that of the higher graded document/ material therein. 5.2.4 Officers authorized to classify: The originator of the document will be authorized to classify the document / upgrade / downgrade the same. It is the responsibility of the originator that care is taken of such documents so that the same do not fall in the wrong hands. The overall responsibility of safeguarding classified documents will be of the CEO/ head of the company who shall take all necessary precautions / audits / review mechanisms as d....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... or other reference number, which will be used in correspondence to avoid reference to their titles and subject matter. 5.4.2 Copy numbers or Receipts or making of Spare Copies. The following important aspects shall be kept in view in this regard: - a) When more than one copy of TOP SECRET document is made, they shall be given copy numbers and each page shall be serially numbered. b) The transmission of TOP SECRET and SECRET documents shall be covered by a receipt system. The sender shall enclose a receipt for completion and return to the sender by the addressee. c) If the receipt for a classified document does not reach the issuing authority within seven days, the issuing authority shall ascertain whether the document has in fact been received, if not the same to be reported to CCSO. d) Letters or documents including appendices, if any, shall have continuous page numbers. The total number of pages of a TOP SECRET or SECRET letter or document will be indicated in words below the security classification on the top centre of the front page. e) The Typist besides noting down his initials at the foot of each classified paper typed by him/her, should also note the numb....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... and by whom a receipt has been given. 5.6.2 Other Classified Documents and Equipment will be regarded as under the charge of the person to whom the custody of these documents and materials has been entrusted by the Head of the office concerned. 5.6.3 Individuals in charge of Classified Documents and Materials are responsible for their safe custody and their disclosure is limited to only those required to know. The concept of need to know to be followed. 5.6.4 Proper handing /taking over of all documents to be carried out whenever an individual is transferred or superannuating. 5.6.5 In case any employee transferred from one classified section to other section, an undertaking should be obtained from the employee that No information regarding the functional aspects of the section, cases or reference of any cases will be discussed / disclosed by him / her. 5.6.6 The holders of classified documents will carry out periodic checks. 108 5.6.7 Classified documents will not be studied in the presence of a person who is not entitled to see them or left exposed during the absence of the authorized holder. 5.6.8 When an individual is the sole occupant of a room and dur....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....s out/in any classified paper without written authority from the Competent Authority. 109 (g) All almirahs containing classified documents will have a cross marking on it and it shall be written as "to be removed first in case of fire". 5.7 Notebooks of PAs: 5.7.1 Note-books after utilization of PAs should be returned to the officer under whom he works who will keep it in his personal custody and destroy it after the expiry of three months from the date of the last entry in the note book. 5.7.2 The Short-hand note books should remain in the custody of the officer. After typing out the dictation, the PA should return it to the officer. In no case will it be kept in the locker provided to the PA for storing stationery etc. 5.7.3 Any notebook, disc, tape, film, cassette laptop, PCs etc. which has been used to record classified material, should be treated as a classified document and should be kept in the custody of the officer. Classified work done on Laptops, PCs will not be stored in the hard disk or CDs and zip drives etc. If used, these will be handled as per the security classification of data contained therein. 5.8 Segregation and Care of SECRET Section: Any....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....nd he shall be personally responsible for the custody, operation and accounting of the documents reproduced. Any change of the officer or change of location of equipment should immediately be reported to the CCSO, whose personnel shall make periodic checks to verify the system of the accounting. The machine should always be kept under lock, while not in use. 5.13 Opening and Diarizing of Classified Documents: (a)Opening (i) On receipt of TOP SECRET documents the inner cover will be handed over by the opening personnel to the Officers. All TOP SECRET covers will be opened by the addressee or in his absence by the officer officiating for him. (ii) SECRET or CONFIDENTIAL documents will be opened either by the addressee or a person so authorised by him. (b) Diarizing (i) The diarizing of all TOP SECRET documents shall be carried out either by the officer to whom it is addressed or by his personal staff so authorised by him. The diarizing of SCERET documents may be entrusted to the lower level at the discretion of the concerned officer. The responsibility of the safe custody of the documents will, however, rest with the officer concerned (ii) The diarizing of CONFID....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... Officer or Personal Assistant or equivalent. (iii) All departmental seals issued to different branches/groups/ units must be numbered and a list must be maintained by the issuing authority showing person to whom it has been issued. All such persons will be responsible for the security of these seals. (iv) In case of any loss of such seal, matter should immediately be reported to the CCSO and authority concern for necessary action on their parts. Besides, other seals of the same series should be treated as compromised. Later, a new series of seal with different shape and design should be issued as early as possible. (c)Movement of Classified Documents (i) For movement of classified paper within office, a box, may be of steel or of thick leather / Rexene/ canvas provided it has a proper locking arrangement and cannot be easily cut/pierced/ opened/ tampered, need to be used. Under no circumstances should classified documents be carried loose in the hands of the messengers/ orderlies. (ii) A messenger carrying secret covers should not leave them unattended at any time till they are delivered. (iii) Within the Same Block or Building: TOP SECRET files or documents shal....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... of officers is prohibited. All Top Secret papers should be dealt with in office only. (i) Officers are generally prohibited to carry any Top Secret paper to their residence. When it is necessary to send a Top Secret paper to CEO/ authorized senior officer at his residence after office hours, the dispatching officer should obtain his specific instructions that it may be sent to his residence and that he would be ready to receive the document at his residence. (ii) The dispatching officer must ensure that the box in which Top Secret document is sent, is locked and fastened to the vehicle in which the messenger is carrying it. (iii) When an officer having authority to do so carries any Top secret document to his residence, he must take the documents only in securely locked bag/box, the key of which must be in his possession. The bag/box must be kept all along in his personal custody till he reaches his residence where 113 also this must be placed in a secure place to which no outsider may have access. (iv) Whenever an officer requires a Top Secret document for meetings /discussions, etc. either at the place of his posting or at a place other than the place of postin....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....s: ILDCs shall develop procedures for safeguarding classified equipment in emergency situations. The procedures shall be as simple and practical as possible and should be adaptable to any type of emergency that may reasonably arise. ILDCs shall promptly report to the designated agency any emergency situation that renders the facility incapable of safeguarding classified equipment. 5.16 Disclosure: 5.16.1 General: ILDCs shall ensure that classified information is disclosed only to authorized persons. 5.16.2 Disclosure to Employees: ILDCs are authorized to disclose classified information to their authorized employees as necessary for the performance of tasks or services essential to the fulfilment of a classified contract or subcontract. 5.16.3 Disclosure to Subcontractors/ other persons/other ILDCs: ILDCs are authorized to disclose classified information to a subcontractor when access is necessary for the performance of tasks or services essential to the fulfilment of a prime contract or a subcontract. Prior authorization shall be obtained by the ILDC in writing from the Government Agency having classification jurisdiction over the information involved for this purpose. ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....ence of the originator. 5.17.3. Upgrading Action: When a notice is received to upgrade equipment to a higher level, the new markings shall be immediately entered on the equipment according to the notice to upgrade, and all the superseded markings shall be obliterated. The authority for and the date of the upgrading action shall be entered on the equipment. 5.17.4 Disposal: Classified documents will be examined from time to time with a view to reducing the number of such documents held. Accountable documents, if no longer required by holder, will be returned to the issuing authorities. 5.17.5 Destruction: TOP SECRET, SECRET or accountable CONFIDENTIAL documents will be shredded to small size without being able to be reconstituted and shall be destroyed by burning and a proper record be maintained under the supervision of authorised officer. Documents other than classified may be destroyed at the discretion of the head of the office concerned. 5.17.6 Other points on destruction: a) Record of daily destruction of classified waste, indicating individual detailed for supervision and the time and place shall be maintained by the Sections, in order to pin point the responsi....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....o impersonate as government official seeking sensitive information should be blocked and officials should be wary of such calls from calls. Specifically, to prevent leaking of information through such calls, following procedure should be followed: - (i) Do not provide any information without establishing the identity of the caller. (ii) Take down the caller's contact number and seek time to revert back. If any suspicion arises during the call, cancel the call. (iii) (iv) Do not disclose any sensitive information over phone to anyone. (v) Don't be tricked into giving away confidential information. (vi) If any email is received from an operative of unfriendly countries, forward that email to CERT-IN for further necessary action. (vii) If the email attachment is opened by the user, immediately disconnect that PC from network and scan the network for the presence of malware. (viii) Any such calls or email shall be report to the CISO immediately (e) To prevent misuse, telephones should be kept locked when the officer is away from his office. (f) Cordless phones will not be used. (g) If it comes to notice that an intruder has come on the line and some inf....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....ead of department and granted by CCSO. Mobile phones are not permitted inside conference halls, operations rooms, at official briefings and at sensitive places even in off mode. This instruction is applicable to even those who have been permitted. Mobile phone with camera and other technical advance features including internet, GSM, etc should not be allowed irrespective of ranks inside the office premises. No visitors will be permitted to carry mobiles inside the facility, the mobiles of visitors is to be deposited at the reception. 119 6.4 FAX communications: FAX communications are also vulnerable to interception or leakage, e.g. a cross-connection. It is, therefore, necessary to identify the end party before transmitting a message. Papers which are not of classified or sensitive nature may be transmitted with the help of FAX in emergent cases. Under no circumstances such an option is exercised for transmitting classified documents. No classified message should be passed or received on Fax on auto mode. 6.4.1 While using Fax machines a record of the documents or papers faxed or received will be kept in a register. The record will include the following details: - a)....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....hing, Smishing and Vishing Attacks (e) Accidental/Intentional cross connection between the Organization Local Area Network and Internet. (f) Spoofing by intruders. (g) Defacing of various Websites by anonymous Hackers. 7.1.6 In addition to above, any advisory issued by the Government from time to time shall be strictly complied with. 121 7.2 ISO 27001: 7.2.1 The companies shall follow guidelines under ISO 27001. Appropriate controls shall be implemented to accommodate the guidelines given in this manual. 7.2.2 This International Standard has been prepared to provide a model for establishing, implementing, operating, monitoring, reviewing, maintaining and improving an Information Security Management System (ISMS). 7.2.3 This International Standard adopts a process approach for establishing, operating, monitoring, reviewing, maintaining and improving an organization's ISMS. 7.2.4 The process approach for information security management presented in this International Standard encourages its users to emphasize the importance of: (i) Understanding an organization's information security requirements and the need to establish policy and objectives for inf....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....wall, IDS/IPS, UTM, EDR/UEBA, SIEM/SOAR (g) Industry 4.0 policy for safety of Cyber Physical and SCADA/ICS Systems. (h) Disaster Recovery policy with focus on data security while assuring business continuity. (i) (a) Restrict privileged accounts on the system to only those organisation- identities personnel who require this access compulsorily to carry out their allotted tasks which require access to controlled defence information (b) Require that users (or roles) with privileged accounts use non- privileged accounts when accessing functions or information not related to allotted tasks which require access to controlled defence information (j) (a) Prevent non-privileged users from executing privileged functions. (b) Log the execution of privileges functions. (k) Unsuccessful Logon Attempts: Limit the number of consecutive invalid logon attempts to an organisation- defined number and an organisation-defence time period. (l) System use notification: Display a system use notification message with privacy and security notices consistent with applicable controlled defence information handling and processing rules before granting access to the system. (m)....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....echanism along with monitoring system should be in place, for changes to data includes deterring, detecting and reporting of successful and unsuccessful attempts to change etc.Such monitoring system can be implemented by deploying solutions like Security incident and Event Management (SIEM), Security Orchestration Automation and Response (SOAR) and User and Entity Behaviours Analytics (UEBA). f) Use of next generation technologies like Zero Trust Architecture will help in attack surface reduction. Also for granular level control Identity and Access Management (IAM) solutions are recommended. g) Control and audit logs should be available in centralised systems/applications for Successive Logon Attempts, Multiple Logon Control, Session termination and User Inactivity etc. The logs retention period must be for a period of minimum 180 days. 124 h) Security should be ensured for inter connectivity of multiple LANs, when organisation has multiple Units/Offices across the geographical location, where interconnectivity may be WAN (Wide Area Network) using public networks. i) When Public networks are used proven, secured WAN technologies should be used along with appropriate ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....tical networks/systems. (ii) Compromise of critical systems/ information. (iii) Unauthorised access of IT systems/ data (iv) Defacement of website or intrusion into a website and unauthorised changes such as inserting malicious code, links to external websites etc. (v) Malicious code attacks such as spreading of Virus/Worm/Trojan/Bots/Spyware/Ransomware/Cryptominers. Attack on servers such as Database, Mail, DNS and Network devices such as Routers. (vi) (vii) Identity theft, spoofing and phishing attacks. (viii) Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks. (ix) Attacks on Critical infrastructure, SCADA and operational technology systems and Wireless networks. (x) Attacks on Application such as E-Governance, E-Commerce etc. (xi) Data Breach. (xii) Data Leak. (xiii) Attacks on Internet of Things (loT) devices and associated systems, networks, software, servers. (xiv) Attacks or incident affecting Digital Payment systems. (xv) Attacks through Malicious mobile Apps. (xvi) Fake mobile Apps (xvii) Unauthorised access to social media accounts. (xviii) Attacks or malicious/ suspicious activities affecting Cl....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....and includes preparation, detection and analysis, containment, eradication and recovery processes and procedures. (c) Update the incident response plan to address system and organisational changes or problems encountered during plan implementation, execution or testing phases. (VIII) Incident Monitoring, Reporting and Response Assistance (a) Track and document system security incidents. (b) Report suspected incidents to the organisational incident response capability within an organisation-defined time period. (c) Report incident information to CERT-In/NCIIPC as per timelines promulgated by these entities from time to time. 127 (d) Provide an incident response support resource that offers advice and assistance to users of the systems for the handling and reporting of incidents. (IX) Incident Response Testing Test the effectiveness of the incident response capability periodically. (X) Incident Response Testing (a) Provide incident response training to system users consistent with assigned roles and responsibilities: (i) Within an organisation-defined time-period of assuming an incident response role or responsibility and following occurrence of or....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... & carbons, damaged tapes and hard disks etc. (iii) Protection of Switches/Routers and other connectivity devices. 7.5.3 Network racks should be situated away from easily accessible public spaces like the pantry, cafeteria, restrooms, waiting rooms, hallways etc. Also these devices should be properly locked and must be under continuous surveillance using cameras. 7.5.4 Adequate protection is required both for the operating system software and application software. In order to prevent unauthorized access to the data, passwords should be assigned at multiple levels i.e. first at the time of making the system operational, second at the time of logging with the authorized user's name, third at the time of running application software and so on, depending upon the type of data being handled. It is very essential that there should be a provision of 'Audit Trail' features to know which user had logged in and at what time. a) Develop, approve and maintain a list of individuals with authorisation access to the physical location where the system resides. b) Issue authorisation credentials for physical access. c) Review the physical access list periodically. 7.5.5 Review ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....interfaces within the system. b) Implement subnet works for publicly accessible system components that are physically or logically separated from internal networks. c) Connect to external systems only through managed interfaces consisting of boundary protection devices arranged in accordance with organizational security architecture. 130 7.6 Acquisition of Computer hardware and Software 7.6.1 Computer hardware, which is proposed to be procured, should be of an open system or architecture and the user should be free to go in for 'Annual Maintenance Contract' with any party. The systems being procured should be the latest ones which can be upgraded at a later date. 7.6.2 If development of software application is outsourced, antecedents of the personnel/company developing the software should be verified. Where necessary, Non-Disclosure Agreements (NDA's) must be signed by the Contractor / sub-contractors. Further, for critical applications the vendor should be asked to provide source code for the application developed by him. Whenever feasible, dummy data should be used for testing the applications. This would prevent the vendor from accessing sensitive information. ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... on which a third party cyber security audit shall be conducted. This auditor shall be selected by the ILDC from the list of certified Cyber Security Auditors as published by Computer Emergency Response Team - India) CERT-In, on their web site. i) The risk to secrecy of data due to the human factor should also not be underestimated. The following measures should be adopted in this regard: - a) Adequate separation of duties and restriction of access in every office so that no single person can individually compromise the entire system or data. b) Triennial character and antecedents verification of critically placed functionaries of the computer system handling sensitive information by CCSO through civil police. c) Cyber Awareness and Evaluation Module should be an integral component of employee induction training. Also on a periodic basis, recurring cyber security awareness training and evaluation sessions must be conducted to keep all employees informed and vigilant regarding cyber security matters. d) In-house sensitization and periodical briefing of concerned personnel of various departments regarding computer security. e) Inclusion of talks on computer security....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....isition, delivery, integration, operations, maintenance and disposal of the system, system components or system devices which are related to or store or harness- controlled defence information. Review and update the supply chain risk management plan periodically. Protect the supply chain risk management plan for unauthorised disclosure. Acquisition Strategies, Tools and Methods. t) Develop and implement acquisition strategies, contract, tools and procurement methods to identify, protect against and mitigate supply chain risks u) The Software must be developed and build in secure environments. Those environments must be secured by the following actions, at a minimum - Separating and protecting each environment involved in developing and building software. Regularly logging, monitoring and auditing trust relationships used for authorisation and access to any software development and build environments among components within each environment. 133 v) Enforcing multi-factor authentication and conditional access across the environments relevant to developing and building software in a manner that minimises security risk. w) Taking consistent and reasonable steps to doc....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....and accountability of the same shall still rest with the CEO. All instructions relating to classified documents contained in this Manual are equally applicable to External / Portable Hard Drives. Carriage of External / Portable Hard Drive inside/outside the office premises is not permitted. Secondary storage Devices register will be maintained by the respective sections/departments. Internal physical check will be carried out within the concerned sections/departments every week and result indicated in the register. 134 Sections/departments will render a quarterly certificate to the CCSO regarding safe custody of the pen drives in their sections/departments. No visitor/employee will be permitted to use or carry personal pen drive / External / Portable Hard Drives within the classified area/zone. Loss of External / Portable Hard Drive will be reported to CCSO immediately, and investigations carried out simultaneously by the sections/departments, to ascertain the extent of loss of classified information and to pinpoint responsibility for the loss for initiating suitable action against the defaulters. a) Prohibit the use of external systems in production environment unless ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....should be broken and destroyed by burning or as applicable to the weeding out paper based files and an entry to this effect be made in the register. CCTV recordings should be password protected. b) Bad / condemned hard disk should not be released even after it has been replaced by a new one. Such hard disks will be destroyed by following procedures as applicable to weeding out of classified files. c) Destructions should be carried out by application of corrosive Chemicals (acid or abrasive substances, emery wheel or disk sander) to the recording surface, and by shredding, incineration, disintegration, pulverization and smelting etc. 7.7.8 Cyber Security Audit: a) The CISO must supervise all computer security measures within his offices/ branches/section. The CISO shall not be a foreign citizen, or a Personof Indian Origin who is a Non-Resident Indian. b) Cyber Security Audit must be carried out under the strict supervision of Cyber Information Security Officer (CISO). c) Periodic security audit of the IT is liable to be carried out by designated Govt Agencies, from time to time, to ensure that the laid down guidelines are strictly followed. However, this does not ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... (vii) Before deleting the sensitive files, overwrite the files with some junk data to prevent restoration of the sensitive data by any means. Keep the backup of operating system software and application software under safe custody. One backup copy should be kept in different location as a precaution against fire hazards. (viii) Backup data should be periodically updated. Keep the software maintenance tool in your own custody. The periodic checking of backup inventory and testing of the ability to restore information validates that the overall backup process is working. This may be given to the engineer called to attend to the faults in the system as and when required. (ix) External CD writers will be under the custody of officer only. CD writer will be used only in minimum and unavoidable files and data. (x) Ensure safe custody of the Computer Storage Media such as cartridge tapes, Pen Drives, CDs etc. (xi) Every new incoming storage media or software should be tested for Virus. (xii) Always use original software purchased from the authorised vendors. (xiii) Copying of data, deletion, modification, etc. from the disk should be done under proper authorisation and....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....onal personnel or roles when - a) Accounts are no longer required. b) Users are terminated or transferred c) System usage or need to know changes for an individual (xxxi) Information in Shared System Resources. Prevented unauthorised and unintended information transfer via shared system resources. (b) DON'Ts. i. Don't let any unauthorized persons use your computer system. ii. Don't share your password with anyone, not even your colleagues. iii. Don't reveal the root password to any unauthorized person, particularly an outsider. 138 iv. Don't connect the computer directly to the mains. Also, no heavy electric load drawing machines like plain paper copier, shredding machines, coolers etc. should be connected to the source of constant voltage supply to the computer. V. Do not connect your computer system storing classified data to internet. vi. Don't allow staff members to bring their own storage medias or software to run on the computer system of the department. vii. Don't use pirated or gifted copies of software as these may contain viruses and even facilitate intrusions into the system. viii. Don't play computer games. These could be the....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... system with Internet line for any purpose, whatsoever, is strictly prohibited. No official or personal files will be stored on the hard disk of Internet PC. Personal media will never be used on Internet PC. No sensitive/ classified office work will be done in Internet computers. 7.9.1 All official work will be carried out on a system belonging to Air Gapped Network. Air Gapped Network will be isolated from the Internet at the physical layer. The air-gapped network's devices should meet following criteria: (i) Must have a separate networking equipment, including switches and routers, accompanied by cables of a different colour to easily differentiate them from internet-related cables. (ii) Specially designated desktop computer (referred as Entry-Exit system) must be used for moving data into/out of Air-gapped network. (iii) Only officially recognised Thumb Drive/Pen Drive can be used on Entry-Exit system for data exchange. This Pen Drive will always remain in safe custody of CISO or any other officer designated by CISO. Every issue of Thumb Drive/ Pen Drive will be recorded. (iv) Under no circumstances, the Entry-Exit system should be used for nefarious activities li....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....icial communications and emails from suppliers/contractors through private emails addressees should be barred, as far as possible. However, the employees should be discouraged to use official email id for registering into various non-official platforms like banking, insurance etc. vii. Social media usage policy should be defined and enforced on all employees. Unless specifically required for discharge of their duties, employees must be prohibited from accessing social media sites from their official systems. Employees should be discouraged from publishing information related to their work. viii. Server room/network room should have biometric access control systems with CCTV coverage in place ix. Enforce approved authorisations for controlling the flow of controlled defence information within the system and between connected systems. 7.10 Cyber Posture Enhancement via integration with Defence CSOC: Industry entrusted with procurement orders/technologies developed by any Government agency of any such entity, privy to Defence related designs, plans, materials, documents, products, software, etc shall ingest necessary logs only (non- content) to Defence Cyber Security Op....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....later than the timeline. 142 CHAPTER - 9 - International Security 9.1 Imports of Equipment/ Materials: a) Where Sensitive Equipment/ Materials is bought or otherwise acquired by the ILDC, it should be ensured the equipment is securely packed and sealed and transported. The packages will not have any markings to indicate that the Equipment is Top secret / Secret. b) Top Secret and Secret Equipment/ Materials will not be shipped in Vessels / Flights which unload cargo in other countries or call at ports of unfriendly countries en-route. c) Bills of lading or other documents will not indicate the classification of the Equipment. Separate bills of lading may be made out for small consignments which are delivered to the Master of the Ship for personal custody during transit. These documents will indicate the equipment in general terms, e.g. Instrument, PCB and so on, but will not give precise details. d) Where possible, intimation will be sent to the consignee through official channels of the company. If time does not permit, intimation may be given through a coded / encrypted signal etc., describing the equipment in general terms and indicting the security measures....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....ficer only. 9.4 NDA for transfer of classified information between two countries: The names of the Government Authority of each of the two countries empowered to authorise the release and to co-ordinate the safeguarding of Classified Information related to the Contract and the channels to be used for the transfer of the Classified Information between the Participants National Security Authority (NSA)/ Designated Security Authority (DSA)/ Competent Security Authority (CSA) and/or Contractors involved shall be governed by non-disclosure agreement. 9.5 Movement: a) Consignors of Top Secret and Secret Equipment will warn the consignee of the dispatch of equipment so that the latter is in a position to make adequate security arrangements to receive it. All such equipment will be suitably shrouded and accompanied by an escort to ensure that no unauthorized person gains an access to them surreptitiously. b) When only portion of equipment is Top Secret or Secret and it is possible to conceal that portion, it is not necessary for the entire equipment to be covered up. Only the Top Secret / Secret portion(s) of such equipment should be covered. c) If a portion of equipment ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....(iii) Date of birth. (iv) Parentage of the visitor. (v) Permanent and Present address of the visitor. (vi) Passport No with date and place of issue. (vii) Validity of Passport. 145 (viii) Visa details (types, data & place of issue and duration of visa) (ix) Occupation and Name of the Firm / organization which the visitor is representing. (x) Specific purpose of the visit. (xi) If the foreigner has visited the establishment earlier, full details of the same is to be furnished. (xii) Details of escort being provided for conducting the tour of the Foreign National(s). (xiii) Address of Hotel/accommodation where the foreign visitor staying in India during the visit. (xiv) The address of the Indian company with which the foreigner is having partnership/alliance etc. (xv) Date & Time of visit (xvi) Area to be visited (xvii) Certificate that no classified document shall be shared with the foreign visitors. (b) The particulars of the foreigners will be filled in a proper format and processed through CEO/Head of ILDC as the case may be for approval. Purpose of the visits also needs to be mentioned in the format prescribed for this purpose. The....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....nd certain classified meetings pertaining to classified information / sensitive information. It is the responsibility of CEO for non-leakage of information. 147 CHAPTER - 11 - Training 11.1 General: It shall be the responsibility of the ILDC to provide all employees with security training and briefing, commensurate with their roles and responsibilities while dealing with classified information. Towards this, the ILDC may obtain defensive security, threat awareness and other educational and training information from the nominated agency of Government of India, Ministry of Defence. 11.2 Security Briefing: All employees should be briefed on security do's/don'ts on joining as a part of induction programme. The induction programme must include Cyber Awareness Capsule Prior to being granted access to classified information, an employee shall receive an initial security briefing that includes the following: a. A threat awareness briefing. b. A defensive security briefing. c. An overview of the security classification system. d. Employee reporting obligations and requirements. e. Security procedures and duties applicable to the employee's job. 11.3 Tr....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....el be appropriately trained on the Organization's Information Security policies commensurate with their roles and responsibilities and be kept up-to-date on any additions or changes to the policies. 149 CHAPTER - 12 - Miscellaneous 12.1 General: MoD will be the nodal agency for preparation, review and implementation of the manual. However, conducting inspection and audit would be the responsibility of /MHA /MoD. MHA and MoDmay take the assistance of other organizations like DPSUs, NTRO etc. in the inspection or audit. 12.2 Publicity and Photography: No photography would be permitted inside the Classified Zone/Area pertaining to MoD projects without the approval of MoD. Photography, when permitted for official purposes, will be done under proper supervision and both the photos, soft copy of photograph and their negatives shall be appropriately classified. In the case of Top Secret and Secret Equipment, permission for photography or publicity will be granted by General Manager / Chief Executive of the manufacturing Division / Unit or Factory, however, it will be done under controlled conditions by the official photographer. As far as possible only official agencies ....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....red as Secondary sites) should not be a source of data breach. Disaster Management Plan should be in line with the guidelines/instructions issued by the National Disaster Management Authority/State Disaster Management Authority. 12.6 Internal Security Audit: The ILDC shall carry out internal security audit to ensure verification of compliance of security instructions contained in this manual. The Security Audits are required to be conducted to ascertain the level of compliance of security instruction and procedures specified in the security manual. The audit shall be done at least on a yearly basis. If ILDC is Multi Facility Organisation (MFO), audit shall be done annually in each facility: - a) Check compliance by all the establishments to realize the designed security objectives as enumerated in the security manual. b) Verify the effective implementation of the instructions and identify lapses, if any. c) Verify the efficacy of the existing Security & Fire Control System. d) To check that adequate safeguards exist against espionage, sabotage and subversion in a given environment where the installation is located. e) To check the general Security awareness amo....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

.... the licence. 12.9.2 In case of breach, violation, non-adherence to the provisions of Security Manual, penal provision including financial penalties and denial of various RFPs/technical details/ToTs other contracts by the Government agencies including Service Headquarters, DRDO, DPSUs, etc. may be imposed. 12.9.3 For an entity holding license under Arms Act, 1959 (Arms Act) strict adherence to the terms and conditions of the license is mandatory. Any violation of these terms and conditions may lead to cancellation of license and prosecution under the Arms Act, 1959. The provisions of the Explosive Substances Act, 1908 will also be applicable in cases involving in the manufacture, possession, storage or transport of explosives. 12.10 Alternate Power Source: An alternate power source is required to ensure that the system availability is maintained in the event of loss of primary power due to various reasons, including sabotage/subversion. 12.11 Investigations of compromising emanations: Compromising emanations are unintentional intelligence-bearing signals that, if intercepted and analyzed, will disclose classified information when it is transmitted, received, handl....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....truction of electronic devices at the end of their life cycle, especially emphasizing the secure wiping of sensitive data from storage devices to prevent potential data breaches. 12.14.1 Waste Management from health perspective its the classification of waste as chemical, hazardous, toxic and recyclable collection, transport, processing or disposal, managing and monitoring of waste materials. The term usually relates to materials produced by industrial activity, and the process is generally undertaken to reduce their effect on health, the environment or aesthetics. Waste management is a distinct practice from resource recovery which focuses on delaying the rate of consumption of natural resources. All wastes materials, whether they are solid, liquid, gaseous or radioactive fall within the ambit of waste management. 12.14.2 E-Waste: Once the electronic device reaches its end of its life cycle, the data on the device must be destroyed by techniques like erasing, wing, and 153 degaussing. Storage devices such as hard disks and flash drives should undergo destruction, and the CISO must issue a destruction certificate, co- signed by a board of officer, verifying the destruct....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....DDP 12 & 13 Report on incidents such as Fire, Theft, Sabotage, Espionage, Cyber Accidents, strike, terror activities, adverse information about employees unauthorized receipt of classified materials, report of loss or suspected compromise Immediately(with in 24 hours) and on quarterly basis Immediately 30th June 30th September 31st December 31st March Local Police,M HA, Nodal Office, DDP 14 Report to MHA on list of employees cleared from security angle Annually 30th June 30th September 31st December 31st March Nodal Office, DDP 15 Report of inflow of foreign investment Annually 30th June 30th September 31st December 31st March Nodal Office, DDP *Report to be submitted within 7 days of end of Quarter/Half year/Financial year ** In case, ILDC does not have any information to report, a Nil report shall be sent to concerned licensing authorities *** Licensing authorities are Ministry of Home Affairs (MHA), Department for Promotion of Industry & Internal Trade (DPIIT) and Department of Commerce (DoC) 156 Annexure - I 1. Name and Address of the Industrial Undertaking State State 2. Location of Factory 3. If any extension has been granted then (i)....

X X   X X   Extracts   X X   X X

Full Text of the Document

X X   X X   Extracts   X X   X X

....al for Licensed Defence Indsutries In regard to Industrial License No I issued to M/s hereby declare that our company is complying with the provisions mentioned in the Security Manual for Licensed Defence Industries prepared by Ministry of Defence, Department of Defence Production. Encl: If required Place: [Signature] Date: Name (Block Letters) (CEO/MD) 160 Annexure-V No. To, D(DIP) Section, Department of Defence Production, Ministry of Defence Subject: Self certification on compliance to Internal Security Audit. In regard to Industrial License No issued to M/s I hereby declare that the Internal Audit as mandated by the Security Manual for LDIs have been conducted and the observations/Recommendations have been complied with. Place: [Signature] Date: Name (Block Letters) (CEO/MD) 161 Annexure-VI Annual Cyber Security Audit in case of classified information, if any S.No Observations of Annual Cyber Security Audit Action Taken Stage of Progress Probable Date of completion Remarks, if any Annexure-VII Internal Inspection Reports of Manufacturing facilities S.No Observations of Internal Reports ....