Information Technology (Information Security Practices and Procedures for Protected System) Rules, 2018
X X X X Extracts X X X X
X X X X Extracts X X X X
....formation Security Practices and Procedures for Protected System) Rules, 2018. (2) They shall come into force on the date of their publication in the Official Gazette. 2. Definitions. (1) In these rules, unless the context otherwise requires - (a) "Act" means the Information Technology Act, 2000 (21 of 2000); (b) "Chief Information Security Officer" means the designated employee of Senior management, directly reporting to Managing Director /Chief Executive Officer/Secretary of the organisation, having knowledge of information security and related issues, responsible for cyber security efforts and initiatives including planning, developing, maintaining, reviewing and implementation of Information Security Policies;....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ontrols; (g) "Information Security Steering Committee" means the committee comprising higher management officials of the organisation, responsible for continuously improving and strengthening the cyber security posture of the Protected System and also plan, develop, review remedial actions to mitigate and recover from malicious cyber incidents; (h) "IT Security Service Level Agreements" means the legally recognised Service Level Agreements between the service providers and officials related to the "Protected System" for securing information related to "Protected System"; (i) "National Critical Information Infrastructure Protection Centre" means the agency established under sub-section (1) of section 70A of the Act....
X X X X Extracts X X X X
X X X X Extracts X X X X
....epresentative of National Critical Information Infrastructure Protection Centre (NCIIPC); (v) Any other expert(s) to be nominated by the organisation. (2) The Information Security Steering Committee (ISSC) shall be the apex body with roles and responsibilities as follows: - (a) All the Information Security Policies of the "Protected System "shall be approved by Information Security Steering Committee. (b) Significant changes in network configuration impacting "Protected System" shall be approved by the Information Security Steering Committee. (c) Each significant change in application(s) of the "Protected System" shall be approved by Information Security Steering Committee. (d) A mechanism sha....
X X X X Extracts X X X X
X X X X Extracts X X X X
....Centre "Guidelines for Protection of Critical Information Infrastructure". Any changes to network architecture shall be documented; (d) plan, develop, maintain the documentation of authorised personnel having access to "Protected System" and the same shall be reviewed at least once a year, or whenever required, or according to the Information Security Management System(ISMS) as suggested in clause(b); (e) plan, develop, maintain and review the documents of inventory of hardware and software related to "Protected System"; (f) ensure that Vulnerability/Threat/Risk (V/T/R) Analysis for the cyber security architecture of "Protected System" shall be carried out at least once a year. Further, Vulnerability/Threat/Risk (....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ivity, if any, shall be documented; (k) establish a Network Operation Center (NOC) using tools and techniques to manage control and monitor the network(s) of "Protected System" for ensuring continuous network availability and performance; (l) plan, develop, maintain and review the process of taking regular backup of logs of networking devices, perimeter devices, communication devices, servers, systems and services supporting "Protected System" and the logs shall be handled as per the Information Security Management System(ISMS) as suggested in clause (b). 4. Roles and Responsibilities of "Protected System(s)" towards National Critical Information Infrastructure Protection Centre :- (1) The Chief Information Security ....
X X X X Extracts X X X X
X X X X Extracts X X X X
....rotected System". (j) IT Security Service Level Agreements (SLAs) of "Protected System". (3) (a) The Chief Information Security Officer (CISO) shall establish a process, in consultation with the National Critical Information Infrastructure Protection Centre (NCIIPC), for sharing of logs of "Protected System" with National Critical Information Infrastructure Protection Centre (NCIIPC) to help detect anomalies and generate threat intelligence on real time basis. (b) The Chief Information Security Officer shall also establish a process of sharing documented records of Cyber Security Operation Center (related to unauthorised access, unusual and malicious activity) of "Protected System" with National Critical Information Infrastru....
TaxTMI