Information Technology (Certifying Authorities) Rules, 2000.
X X X X Extracts X X X X
X X X X Extracts X X X X
....Certifying Authority; (d) "Controller" means Controller of Certifying Authorities appointed under sub-section (1) of Section 17 of the Act; (e) "Digital Signature Certificate" means Digital Signature Certificate issued under sub-section (4) of section 35 of the Act; (f) "information asset" means all information resources utilized in the course of any organisation's business and includes all information, applications (software developed or purchased), and technology (hardware, system software and networks); (g) "licence" means a licence granted to Certifying Authorities for the issue of Digital Signature Certificates under these rules; (h) "licensed Certifying Authority" means Certifying Authority who has been granted a licence to issue Digital Signature Certificates; (i) "person" shall include an individual; or a company or association or body of individuals; whether incorporated or not; or Central Government or a State Government or any of the Ministries or Departments, Agencies or Authorities of such Governments; (i) "Schedule" means a schedule annexed to these rules; (k) "subscriber identity verification....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ure.- The verification of a Digital Signature shall be accomplished by computing a new hash result of the original electronic record by means of the hash function used to create a Digital Signature and by using the public key and the new hash result, the verifier shall check- (i) if the Digital Signature was created using the corresponding private key; and (ii) if the newly computed hash result matches the original result which was transformed into Digital Signature during the signing process. The verification software will confirm the Digital Signature as verified if :- (a) the signer's private key was used to digitally sign the electronic record, which is known to be the case if the signer's public key was used to verify the signature because the signer's public key will verify only a Digital Signature created with the signer's private key; and (b) the electronic record was unaltered, which is known to be the case if the hash result computed by the verifier is identical to the hash result extracted from the Digital Signature during the verification. process. 6. Standards.- The Information Technology (IT) architecture for Cert....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... paid up capital of not less than five crores of rupees; and (ii) net worth of not less than fifty crores of rupees: Provided that no company in which the equity share capital held in aggregate by the Non-resident Indians, Foreign Institutional Investors, or foreign companies, exceeds forty-nine per cent of its capital, shall be eligible for grant of licence: Provided further that in a case where the company has been registered under the Companies Act, 1956 (1 of 1956) during the preceding financial year or in the financial year during which it applies for grant of licence under the Act and whose main object is to act as Certifying Authority, the net worth referred to in sub-clause (ii) of this clause shall be the aggregate net worth of its majority shareholders holding at least 51% of paid equity capital, being the Hindu Undivided Family, firm or company: Provided also that the majority shareholders referred to in the second proviso shall not include Non-resident Indian, foreign national, Foreign Institutional Investor and foreign company: Provided also that the majority shareholders of a company referred to in the second proviso whose ....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... shall have the meaning assigned to it in clause (ga) of sub-section (1) of section 3 of the Sick Industrial Companies (Special Provisions) Act, 1985 (1 of 1986); (v) "Non-resident" shall have the meaning assigned to it as in clause 26 of section 2 of the Income-tax Act, 1961 (43 of 1961). (2) The applicant being an individual, or a company, or a firm under sub-rule (1), shall submit a performance bond or furnish a banker's guarantee from a scheduled bank in favour of the Controller in such form and in such manner as may be approved by the Controller for an amount of not less than five crores of rupees and the performance bond or banker's guarantee shall remain valid for a period of six years from the date of its submission: Provided that the company and firm referred to in the second proviso to clause (b) and the second proviso to clause (c) of sub-rule (1) shall submit a performance bond or furnish a banker's guarantee for ten crores of rupees: Provided further that nothing in the first proviso shall apply to the company or firm after it has acquired or has its net worth of fifty crores of rupees. (3) Without prejudice to any penalty which may be ....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... will comply with the requirements of its Certification Practice Statement; (g) an undertaking that the Certifying Authority's operation would not commence until its operation and facilities associated with the functions of generation, issue and management of Digital Signature Certificate are audited by the auditors and approved by the Controller in accordance with rule 20: (h) an undertaking to submit a performance bond or banker's guarantee in accordance with sub-rule (2) of rule 8 within one month of Controller indicating his approval for the grant of licence to operate as a Certifying Authority; (i) any other information required by the Controller. 11. Fee.- (1) The application for the grant of a licence shall be accompanied by a non-refundable fee of twenty-five thousand rupees payable by a bank draft or by a pay order drawn in the name of the Controller. (2) The application submitted to the Controller for renewal of Certifying Authority's licence shall be accompanied by a non-refundable fee of five thousand rupees payable by a bank draft or by a pay order drawn in the name of the Controller. (3) Fee or any part thereof shall not....
X X X X Extracts X X X X
X X X X Extracts X X X X
....as he may deem fit, grant or renew the licence or reject the application: Provided that in exceptional circumstances and for reasons to be recorded in writing, the period of four weeks may be extended to such period, not exceeding eight weeks in all as the Controller may deem fit. (2) If the application for licensed Certifying Authority is approved, the applicant shall - (a) submit a performance bond or furnish a banker's guarantee within one month from the date of such approval to the Controller in accordance with sub-rule (2) of rule 8; and (b) execute an agreement with the Controller binding himself to comply with the terms and conditions of the licence and the provisions of the Act and the rules made thereunder. 17. Refusal of Licence.- The Controller may refuse to grant or renew a licence if- (i) the applicant has not provided the Controller with such information relating to its business, and to any circumstances likely to affect its method of conducting business, as the Controller may require; or (ii) the applicant is in the course of being wound up or liquidated; or (iii) a receiver has, or a receiver and manager have....
X X X X Extracts X X X X
X X X X Extracts X X X X
....t has confirmed to the Controller the adoption of Certification Practice Statement; (b) it has generated its key pair, namely, private and corresponding public key, and submitted the public key to the Controller; (c) the installed facilities and infrastructure associated with all functions of generation, issue and management of Digital Signature Certificate have been audited by the accredited auditor in accordance with the provisions of rule 31; and (d) it has submitted the arrangement for cross certification with other licensed Certifying Authorities within India to the Controller. 21. Requirements Prior to Cessation as Certifying Authority.- Before ceasing to act as a Certifying Authority, a Certifying Authority shall, - (a) give notice to the Controller of its intention to cease acting as a Certifying Authority: Provided that the notice shall be made ninety days before ceasing to act as a Certifying Authority or ninety days before the date of expiry of licence, (b) advertise sixty days before the expiry of licence or ceasing to act as Certifying Authority, as the case may be, the intention in such daily newspaper or newspa....
X X X X Extracts X X X X
X X X X Extracts X X X X
....cognized foreign Certifying Authority to digitally sign Digital Signature Certificate; (c) current and past versions of Certification Practice Statement of Certifying Authority; (d) time stamps indicating the date and time of - (i) grant of licence; (ii) confirmation of adoption of Certification Practice Statement and its earlier versions by Certifying Authority; (iii) commencement of commercial operations of generation and issue of Digital Signature Certificate by the Certifying Authority; (iv) revocation or suspension of licence of Certifying Authority; (v) commencement of operation of Cross Certifying Authority; (vi) issue of recognition of foreign Certifying Authority; (vii) revocation or suspension of recognition of foreign Certifying Authority. 23. Digital Signature Certificate.- The Certifying Authority shall, for issuing the Digital Signature Certificates, while complying with the provisions of section 35 of the Act, also comply with the following, namely :- (a) the Digital Signature Certificate shall be issued only after a Digital Signature Certificate application in the form provi....
X X X X Extracts X X X X
X X X X Extracts X X X X
....l Signature Certificate, it shall notify the same to the subscriber immediately; (j) all Digital Signature' Certificates shall be issued with a designated expiry date. 24. Generation of Digital Signature Certificate.- The generation of the Digital Signature Certificate shall involve: (a) receipt of an approved and verified Digital Signature Certificate request; (b) creating a new Digital Signature Certificate; (c) binding the key pair associated with the Digital Signature Certificate to a Digital Signature Certificate owner; (d) issuing the Digital Signature Certificate and the associated public key for operational use; (e) a distinguished name associated with the Digital Signature Certificate owner; and (f) a recognized and relevant policy as defined in Certification Practice Statement. 25. Issue of Digital Signature Certificate.- Before the issue of the Digital Signature Certificate, the Certifying Authority shall :- (i) confirm that the user's name does not appear in its list of compromised users; (ii) comply with the procedure as defined in his Certification Practice Statement includi....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ficate shall be revoked and become invalid for any trusted use, where - (a) there is a compromise of the Digital Signature Certificate owner's private key; (b) there is a misuse of the Digital Signature Certificate; (c) there is a misrepresentation or errors in the Digital Signature Certificate; (d) the Digital Signature Certificate is no longer required. (2) The revoked Digital Signature Certificate shall be added to the Certificate Revocation List (CRL). 30. Fees for issue of Digital Signature Certificate.- (1) The Certifying Authority shall charge such fee for the issue of Digital Signature Certificate as may be prescribed by the Central Government under sub-section (2) of section 35 of the Act. (2) Fee may be payable in respect of access to Certifying Authority's X.500 directory for certificate downloading. Where fees are payable, Certifying Authority shall provide an up-to-date fee schedule to all its subscribers and users, this may be done by publishing fee schedule on a nominated website. (3) Fees may be payable in respect of access to Certifying Authority's X.500 directory service for certificate revocation or stat....
X X X X Extracts X X X X
X X X X Extracts X X X X
....nt. 34. Access to Confidential Information.- (1) Access to confidential information by Certifying Authority's operational staff shall be on a "need-to-know" and "need-to- use" basis. (2) Paper based records, documentation and backup data containing all confidential information as prescribed in rule 33 shall be kept in secure and locked container or filing system, separately from all other records. (3) The confidential information shall not be taken out of the country except in a case where a properly constitutional warrant or other legally enforceable document is produced to the Controller and he permits to do so. SCHEDULE-1 [See rule 10] Form for Application for grant of Licence to be a Certifying Authority For Individual 1. Full Name* Last Name/Surname______________________________ First Name_______________________________ Middle Name___________________ 2. Have you ever been known by any other name? If Yes, Last Name/Surname_________________ First Name________________ Middle Name__________________ 3. Address A. Residential Address * Flat/Door/Block No.______________________________________ Name of Premises/Building/Vill....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... Address, if any______________________________________ Your User Name at ISP, if any______________________________________ 16. Personal Web page URL address, if any______________________________________ 17. Capital in the business or profession * Rs. ______________________________________ (Attach documentary proof) For Company /Firm/Body of Individuals/Association of Persons/ Local Authority 18. Registration Number *______________________________________ 19. Date of Incorporation/Agreement/Partnership * -- / -- / ---- 20. Particulars of Business, if any: * Head Office______________________________________ Name of Office______________________________________ Flat/Door/Block No. ______________________________________ Name of Premises/Business/Village______________________________________ Road/Street/Lane/Post office______________________________________ Area/Locality/Taluka/Sub-Division______________________________________ Town/City/District____________________ Pin___________________ State/Union Territory______________________________________ Telephone No. ______________________________________ Fax________________________________....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... 27. Authorised Representative * Name______________________________________ Flat/Door/Block No. ______________________________________ Name of Premises/Building/Village______________________________________ Road/Street/Lane/Post Office______________________________________ Area/Locality/Taluka/Sub-Division______________________________________ Town/District/City_________________________ Pin________________ State/Union Territory______________________________________ Telephone No. ______________________________________ Fax______________________________________ Nature of Business______________________________________ For Government Ministry/Department/Agency/Authority 28. Particulars of Organisation: * Name of Organisation______________________________________ Administrative Ministry/Department______________________________________ Under State/Central Government______________________________________ Flat/Door/Block No. ______________________________________ Name of Premises/Building/Village______________________________________ Road/Street/Lane/Post Office______________________________________ Area/Locality/Taluka/Sub-Divisio....
X X X X Extracts X X X X
X X X X Extracts X X X X
....bsp; ______________________________________ Date Signature of the Applicant Instructions:- 1. Columns marked with * are mandatory. 2. For the columns marked with #, details for at least one is mandatory 3. Column No. 1 to 17 are to be filled up by individual applicant. 4. Column No. 18 to 27 are to be filled up if applicant is a Company/ Firm/ Body of Individuals/ Association of Persons/ Local Authority. 5. Column No. 28 is to be filled up if applicant is a Government organisation 6. Column No, 29, 30, 31 and 34 are to be filled up by all applicants 7. Column No. 32 is applicable only for application for renewal of licence 8. Column No. 33 is not applicable if the applicant is a Government organisation SCHEDULE-II [See rule 19(2)] Information Technology (IT) Security Guidelines Index ....
X X X X Extracts X X X X
X X X X Extracts X X X X
............................................41 8.1 Job Scheduling..........................................................41 8.2 System Operations Procedure. ..........................................................41 8.3 Media Management ..........................................................42 8.4 Media Movement..........................................................42 9. Data Backup and Off-site Retention..........................................................43 10. Audit Trails and Verification ..........................................................44 11. Measures to Handle Computer Virus..........................................................45 12. Relocation of Hardware and Software. ..........................................................46 13. Hardware and Software Maintenance..........................................................46 14. Purchase and Licensing of Hardware and Software.....................................47 15. System Software..........................................................48 16. Documentation Security..........................................................49 17. Network....
X X X X Extracts X X X X
X X X X Extracts X X X X
....deline is determined by the organisation's requirement. 2. Implementation of an Information Security Programme Successful implementation of a meaningful Information Security Programme rests with the support of the top management. Until and unless the senior managers of the organization understand and concur with the objectives of the information security programme its ultimate success is in question The Information Security Programme should be broken down into specific stages as follows: (a) Adoption of a security policy; (b) Security risk analysis; (c) Development and implementation of a information classification system; (d) Development and implementation of the security standards manual; (e) Implementation of the management security self-assessment process; (f) On-going security programme maintenance and enforcement; and (g) Training. The principal task of the security implementation is to define the responsibilities of persons within the organization. The implementation should be based on the general principle that the person who is generating the information is also responsible for its security. How....
X X X X Extracts X X X X
X X X X Extracts X X X X
....fied is that classification of information that requires no protection against disclosure e.g. published annual reports, periodicals. While the above classifications are appropriate for a general organization view point, the following classifications may be considered : Top Secret: It shall be applied to information unauthorized disclosure of which could be expected to cause exceptionally grave damage to the national security or national interest. This category is reserved for Nation's closest secrets and to be used with great reserve. Secret: This shall be applied to information unauthorized disclosure of which could be expected to cause serious damage to the national security or national interest or cause serious embarrassment in its functioning This classification should be used for highly important information and is the highest classification normally used. Confidentiality: This shall be applied to information unauthorized disclosure cf which could be expected to cause damage to the security of the organisation or could be prejudicial to the interest of the organisation, or could affect the organisation in its functioning. Most information will on proper @alysi....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... meters of the operational site. (2) Automatic fire detection, fire suppression systems and audible alarms as prescribed by the Fire Brigade or any other agency of the Central or State Government shall be installed at the operational site. (3) Fire extinguishers shall be installed at the operational site and their locations clearly marked with appropriate signs. (4) Periodic testing, inspection and maintenance of the fire equipment and fire suppression systems shall be carried out. (5) Procedures for the safe evacuation of personnel in an emergency shall be visibly pasted/displayed at prominent places at the operational site. Periodic training and fire drills shall be conducted. (6) There shall be no eating, drinking or smoking in the operational site. The work areas shall be kept clean at all times. 4.3 Environmental Protection (1) Water detectors shall be installed under the raised floors throughout the operational site and shall be connected to audible alarms. (2) The temperature and humidity condition in the operational site shall be monitored and controlled periodically. (3) Personnel at the operational site shall be trained to monitor and control th....
X X X X Extracts X X X X
X X X X Extracts X X X X
....sponsibility to create, classify, retrieve, modify, delete or archive information must rest only with the System Administrator. (4) Any password used for the system administration and operation of trusted services must not be written down (in paper or electronic form) or shared with any one. A system for password management should be put in place to cover the eventualities such as forgotten password or changeover to another person in case of System Administrator (or System Security Administrator) leaving the organization. Every instance of usage of administrator's passwords must be documented. (5) Periodic review of the access rights of all users must be performed. (6) The System Administrator must promptly disable access to a user's account if the user is identified as having left the Data Centre, changed assignments, or is no longer requiring system access. Reactivation of the user's account must be authorized in writing by the System Administrator (Digitally signed e-mail may be acceptable). (7) The System Administrator must take steps to safeguards classified information as prescribed by its owner. (8) The System Administrator must authorize privilege....
X X X X Extracts X X X X
X X X X Extracts X X X X
....re removable media and should be in an encrypted format to avoid compromise by unauthorized persons. (2) Highly sensitive information shall be classified in accordance with para 3. (3) Sensitive information and data, which are stored on the fixed disk of a computer shared by more than one person, must be protected by access control software (e.g., password). Security packages must be installed which partition or provide authorization to segregated directories/files. (4) Removable electronic storage media must be removed from the computer and properly secured at the end of the work session or workday. (5) Removable electronic storage media containing sensitive information and data must be clearly labeled and secured. (6) Hard disks containing sensitive information and data must be securely erased prior to giving the computer system to another internal or external department or for maintenance. 5.4 Third Party Access (1) Access to the computer systems by other organisations shall be subjected to a similar level of security protection and controls as in these Information Technology security guidelines. (2) In case the Data Centre uses the facilities of external....
X X X X Extracts X X X X
X X X X Extracts X X X X
....t unauthorised access to data. (2) Any system software or resource of the computer system should only be accessible after being authenticated by access control system. 6.2 System Access Control (1) Access control software and system software security features shall be implemented to protect resources. Management approval is required to authorise issuance of user identification (ID) and resource privileges. (2) Access to information system resources like memory, storage devices etc., sensitive utilities and data resources and programme files shall be controlled and restricted based on a "need-to-use" basis with proper segregation of duties. (3) The access control software or operating system of the computer system shall provide features to restrict access to the system and data resources. The use of common passwords such as "administrator" or "president" or "game" etc. to protect access to the system and data resources represent a security exposure and shall be avoided. All passwords used must be resistant to dictionary attacks. (4) Appropriate approval for the request to access system resources shall be obtained from the System Administrator. Guidelines and proced....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ferent from the existing password and the two previous ones; (iii) Shall be changed at least once every ninety days; for sensitive system, password shall be changed at least once every thirty days; and (iv) Shall not be shared, displayed or printed. (2) Password retries shall be limited to a maximum of three attempted logons after which the user ID shall then be revoked; for sensitive systems. the number of password retries should be limited to a maximum of two. (3) Passwords which are easy-to-guess (e.g. user name, birth date, month. standard words etc.) should be avoided. (4) Initial or reset passwords must be changed by the user upon first use. (5) Passwords shall always be encrypted in storage to prevent unauthorized disclosure. (6) All passwords used must be resistant to dictionary attacks and all known password cracking algorithms. 6.4 Privileged User's Management (1) System privileges shall be granted to users only on a need-to-use basis. (2) Login privileges for highly privileged accounts should be available only from Console and terminals situated within Console room. (3) An audit trail of activities conducted by highly priv....
X X X X Extracts X X X X
X X X X Extracts X X X X
....rmation assets shall be assigned an "owner" responsible for the integrity of that data/resource. Custodians shall be assigned and shall be jointly responsible for information assets by providing computer controls to assist owners. (2) The operating system or security system of the computer system shall: (i) Define user authority and enforce access control to data within the computer system; (ii) Be capable of specifying, for each named individual, a list of named data objects (e.g. file, programme) or groups of named objects, and the type of access allowed. (3) For networked or shared computer systems, system users shall be limited to a profile of data objects required to perform their needed tasks. (4) Access controls for any data and/or resources shall be determined as part of the systems analysis and design process. (5) Application Programmer shall not be allowed to access the production system. 7. Sensitive Systems Protection (1) Security tokens/smart cards/bio-metric technologies such as Iris recognition, finger print verification technologies etc. shall be used to complement the usage of passwords to access the computer system. (2) For c....
X X X X Extracts X X X X
X X X X Extracts X X X X
....vailable. (9) Procedures shall be in place to ensure that only authorised addition/removal of media from the library is allowed. (10) Media retention periods shall be established and approved by management in accordance with legal/regulatory and user requirements. 8.4 Media Movement (1) Proper records of all movements of computer tapes/disks between on-site and off-site media library must be maintained. (2) There shall be procedures to ensure the authorized and secure transfer to media to/from external parties and the off-site location. A means to authenticate the receipt shall be in place. (3) Computer media that are being transported to off-site data backup locations should be stored in locked carrying cases that provide magnetic field protection and protection from impact while loading and unloading and during transportation. 9. Data Backup and Off-site Retention (1) Back-up procedures shall be documented, scheduled and monitored. (2) Up-to-date backups of all critical items shall be maintained to ensure the continued provision of the minimum essential level of service. These items include: (i) Data files (ii) Utilities programmes ....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... relative to time, volume, frequency, type of information asset, and redundancy. Other areas of analysis include: (i) Significant computer system events (e.g. configuration updates. system crashes) (ii) Security profile changes (iii) Actions taken by computer operations, system administrators, system programmers, and/or security administrators (4) The real time clock of the computer system shall be set accurately to ensure the accuracy of audit logs, which may be required for investigations or as evidence in legal or disciplinary cases. (5) The real time clock of the computer or communications device shall be set to Indian Standard Time (IST). Further there shall be a procedure that checks and corrects drift in the real time clock. (6) Computer system access records shall be kept for a minimum of two years, in either hard copy or electronic form. Records, which are of legal nature and necessary for any legal or regulation requirement or investigation of criminal behaviour, shall be retained as per laws of the land. (7) Computer records of applications transactions and significant events must be retained for a minimum period of two years or lon....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ion Technology equipment to reduce the effects of interference due to electromagnetic emanations. (2) Maintenance of an inventory and configuration chart of hardware. (3) Identification and use of security features implemented within hardware. (4) Authorization, documentation, and control of change made to the hardware. (5) Identification of support facilities including power and air conditioning. (6) Provision of an uninterruptible power supply. (7) Maintenance of equipment and services. (8) Organisation must make proper arrangements for maintenance of computer hardware, software (both system and application) and firmware installed and used by them. It shall be the responsibility of the officer in charge of the operational site to ensure that contract for annual maintenance of hardware is always in place. (9) Organisation must enter into maintenance agreements, if necessary, with the supplier of computer and communication hardware, software (both system and application) and firmware. (10) Maintenance personnel will sign non-disclosure agreements. (11) The identities of all hardware and software vendor maintenance staff should be verified before allowi....
X X X X Extracts X X X X
X X X X Extracts X X X X
....System Software (1) All system software options and parameters shall be reviewed and approved by the management. (2) System software shall be comprehensively tested and its security functionality validated prior to implementation. (3) All vendor supplied default user IDs shall be deleted or password changed before allowing users to access the computer system. (4) Versions of system software installed on the computer system and communication devices shall be regularly updated. (5) All changes proposed in the system software must be appropriately justified and approved by an authorised party. (6) A log of all changes to system software shall be maintained, completely documented and tested to ensure the desired results. (7) Procedures to control changes initiated by vendors shall be in accordance with para 21 pertaining to "Change Management ". (8) There shall be no standing "Write" access to the system libraries. All "Write" access shall be logged and reviewed by the System Administrator for dubious activities. (9) System Programmers shall not be allowed to have access to the application system's data and programme files in the production environment. ....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... network systems shall be controlled and restricted to authorized individuals only in accordance with para 6.2 - System Access Control. (6) As far as possible, transmission medium within the Certifying Authority's operational site should be secured against electro magnetic transmission. In this regard, use of Optical Fibre Cable and armoured cable may be preferred as transmission media as the case may be. (7) Network diagnostic tools, e.g., spectrum analyzer, protocol analyzer should be used on a need basis. 18. Firewalls (1) Intelligent devices generally known as "Firewalls" shall be used to isolate organisation's data network with the external network. Firewall device should also be used to limit network connectivity for unauthorized use. (2) Networks that operate at varying security levels shall be isolated from each other by appropriate firewalls. The internal network of the organization shall be physically and logically isolated from the Internet and any other external connection by a firewall. (3) All firewalls shall be subjected to thorough test for vulnerability prior to being put to use and at least half-yearly thereafter. (4) All web servers f....
X X X X Extracts X X X X
X X X X Extracts X X X X
....roduction system shall be established. Organisational responsibilities for the change management process shall be defined and assigned. (2) A risk and impact analysis, classification and prioritisation process shall be established. (3) No changes to a production system shall be implemented until such changes have been formally authorised. Authorisation procedures for change control shall be defined and documented. (4) Owners/Users shall be notified of all changes made to production system which may affect the processing of information on the said production system. (5) Fall-back procedures in the event of a failure in the implementation of the change process shall be established and documented. (6) Procedures to protect, control access and changes to production source code, data, execution statements and relevant system documentation shall be documented and implemented. (7) Version changes of application software and all system software installed on the computer systems and all communication devices shall be documented. Different versions of application software and system software must be kept in safe custody. 21.2 Testing Of Changes To Production System (1....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ness continuity plan shall be developed which inter alia include the procedures for emergency ordering of the equipment and availability of the services. (3) The need for backup hardware and other peripherals should be evaluated in accordance to business needs. 25. Security Incident Reporting and Response (1) All security related incidents must be reported to a central coordinator, appointed by the management to coordinate and handle security related incidents. This central coordinator shall be the single point of contact at the organization. (2) All incidents reported, actions taken, follow-up actions, and other related information shall be documented. (3) Procedures shall be defined for dealing with all security related incidents, including malicious software, break-ins from networks, software bugs which compromised the security of the system. 26. Disaster Recovery/Management (1) Disaster recovery plan shall be developed. properly documented, tested and maintained to ensure that in the event of a failure of the information system or destruction of the facility, essential level of service will be provided. The disaster recovery framework should include: ....
X X X X Extracts X X X X
X X X X Extracts X X X X
...............................57 3. Physical controls - site location, construction and physical access........................57 4. Media Storage..........................................60 5. Waste Disposal..........................................60 6. Off-site Backup..........................................60 7. Change and Configuration Management..........................................60 8. Network and Communications Security..........................................61 9. System Security Audit Procedures..........................................61 9.1 Types of event recorded..........................................61 9.2 Frequency of Audit Log Monitoring..........................................63 9.3 Retention Period for Audit Log..........................................63 9.4 Protection of Audit Log..........................................63 9.5 Audit Log Backup Procedure....
X X X X Extracts X X X X
X X X X Extracts X X X X
....; Key Compromise..........................................70 22. Confidentiality of Subscriber's Information............................................. 70 Security Guidelines for Certifying Authorities 1. Introduction This document prescribes security guidelines for the management and operation of Certifying Authorities (CAs) and is aimed at protecting the integrity, confidentiality and availability of their services, data and systems. These guidelines apply to Certifying Authorities that perform all the functions associated with generation, issue and management of Digital Signature Certificate such as: (1) Verification of registration, suspension and revocation request; (2) Generation, issuance, suspension and revocation of Digital Signature Certificates; and (3) Publication and archival of Digital Signature Certificates, suspension and revocation of information. 2. Security Management The Certifying Authority shall define Information Technology security policies for its operation on the lines defined in Schedule-Il and Schedule-III. The ....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... access mechanism must be installed at the Certifying Authority's operational site. The facility should have clearly laid out security zones within its facility with well-defined access rights to each security zone. Each security zone must be separated from the other by floor to ceiling concrete reinforced walls. Alarm and intrusion detection system must be installed at every stage with adequate power backup capable of continuing operation even in the event of loss of main power. Electrical/Electronic circuits to external security alarm monitoring service (if used) must be supervised. No single person must have complete access to PKI Server, root keys or any computer system or network device on his/her own. (5) Entrance to the main building where the Certifying Authority's facilities such as Data Centre, PKI Server and Network devices are housed and entrance to each security zone must be video recorded round the clock. The recording should be carefully scrutinized and maintained for at least one year. (6) A Certifying Authority site must be manually or electronically monitored for unauthorised intrusion at all times in accordance with the Information Technology Securi....
X X X X Extracts X X X X
X X X X Extracts X X X X
....opriate action plan shall be developed to manage the risks identified for each component. (2) The application software, system software and hardware, which are procured from questionable sources, shall not be installed and used for any function associated with generation and management of Digital Signature Certificate. (3) Software updates and patches shall be reviewed for security implications before being implemented on Certifying Authority's system. (4) Software updates and patches to rectify security vulnerability in critical systems used for Certifying Authority's operation shall be promptly reviewed and implemented. (5) Information on the software updates and patches and their implementation on Certifying Authority's system shall be clearly and properly documented. 8. Network and Communications Security (1) Certifying Authority's systems shall be protected to ensure network access control to critical systems and services from other systems in accordance with para 17, para 18, para 19 and para 20 of the Information Technology Security Guidelines given at Schedule-II. (2) Network connections from the Certifying Authority's system to exte....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ys; (x) Creation and revocation of Digital Signature Certificates; (xi) Attempts to initialize remove, enable, and disable subscribers, and update and recover their keys; (xii) Failed read-and-write operations on the Digital Signature Certificate and Certificate Revocation List (CRL) directory. (2) Monitoring and Audit Logs (i) A Certifying Authority should consider the use of automated security management and monitoring tools providing an integrated view of the security situation at any point in time. Records of the following application transactions shall be maintained: (a) Registration; (b) Certification; (c) Publication; (d) Suspension; and (e) Revocation. (ii) Records and log files shall be reviewed regularly for the following activities: (a) Misuse; (b) Errors; (c) Security violations; (d) Execution of privileged functions; (e) Change in access control lists; (f) Change in system configuration. (3) All logs, whether maintained through electronic or manual means, should contain the date and time of the event, and the identity of ....
X X X X Extracts X X X X
X X X X Extracts X X X X
....not include the backup of private signature keys. (2) Audit information as detailed in para 9, subscriber agreements, verification, identification and authentication information in respect of subscriber shall be retained for at least seven years. (3) A second copy of all information retained or backed up must be stored at three locations within the country including the Certifying Authority site and must be protected either by physical security alone, or a combination of physical and cryptographic protection. These secondary sites must provide adequate protection from environmental threats such as temperature, humidity and magnetism. The secondary site should be reachable in few hours. (4) All information pertaining to Certifying Authority's operation, Subscriber's application, verification, identification, authentication and Subscriber agreement shall be stored within the country. This information shall be taken out of the country only with the permission of Controller and where a properly constitutional warrant or such other legally enforceable document is produced. (5) The Certifying Authority should verify the integrity of the backups at least once every six....
X X X X Extracts X X X X
X X X X Extracts X X X X
....s to the Digital Signature Certificate server and the computer server maintaining all information associated with generation, issue and management of Digital Signature Certificate and private keys of the Certifying Authority. Minimum two individuals, preferably using a split-knowledge technique, such as twin passwords, must perform any operation associated with generation, issue and management of Digital Signature Certificate and application of private key of the Certifying Authority. 13. Identification and Authentication for Each Role All Certifying Authority personnel must have their identity and authorization verified before they are: (i) included in the access list for the Certifying Authority's site; (ii) included in the access list for physical access to the Certifying Authority's system; (iii) given a certificate for the performance of their Certifying Authority role; (iv) given an account on the PKI system. Each of these certificates and accounts (with the exception of Certifying Authority's signing certificates) must: (i) be directly attributable to an individual; (ii) not be shared; ....
X X X X Extracts X X X X
X X X X Extracts X X X X
....on system in the presence of the subscriber. (2) The key generation process shall generate statistically random key values that are resistant to known attacks. 18.1 Distribution of Keys Keys shall be transferred from the key generation system to the storage device (if the keys are not stored on the key generation system) using a secure mechanism that ensures confidentiality and integrity. 18.2 Storage (1) Certifying Authority's keys shall be stored in tamper-resistant devices and can only be activated under split-control by parties who are not involved in the set-up and maintenance of the systems and operations of the Certifying Authority. The key of the Certifying Authority may be stored in a tamper-resistant cryptographic module or split into sub-keys stored in tamper-resistant devices under the custody of the key custodians. (2) The Certifying Authority's key custodians shall ensure that the Certifying Authority's key component or the activation code is always under his sole custody. Change of key custodians shall be approved by the Certifying Authority's management and documented. 18.3 Usage (1) A system and software integrity check shall....
X X X X Extracts X X X X
X X X X Extracts X X X X
....e years. Use of particular key lengths should be determined in accordance with departmental Threat-Risk Assessments. 21.2 Destruction Upon termination of use of a Certifying Authority signature private key, all components of the private key and all its backup copies shall be securely destroyed. 21.3 Key Compromise (1) A procedure shall be pre-established to handle cases where a compromise of the Certifying Authority's Digital Signature private key has occurred. In such case, the Certifying Authority shall immediately revoke all affected Subscriber Digital Signature Certificates. (2) The Certifying Authority should immediately revoke the affected keys and Digital Signature Certificates in the case of Subscriber private key compromise. (3) The Certifying Authority's public keys shall be archived permanently to facilitate audit or investigation requirements. (4) Archives of Certifying Authority's public keys shall be protected from unauthorised modification. 22. Confidentiality of Subscriber's Information (1) Procedures and security controls to protect the privacy and confidentiality of the subscribers' data under the Certifying Author....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... Office_______________________________ Area/Locality/Taluka/Sub-Division_______________________________ Town/City/District_______________________________ State/Union Territory___________________ Pin : _____________ Telephone No. _______________________________ Fax_______________________________ 4 Address for Communication *. Tick √ as applicable A or B 5. Father's Name * Last Name/Surname_______________________________ First Name_______________________________ Middle Name_______________________________ 6. Sex * (For Individual Applicant only) Tick √ as applicable : Male / Female 7. Date of Birth (dd/mm/yyyy) * -- / -- / ---- 8. Nationality *_______________________________ 9. In case of foreign national, visa details_______________________________ _______________________________ 10. Credit Card Details Credit Card Type_______________________________ Credit Card No. _______________________________ Issued By_______________________________ 11. E-mail Address_______________________________ 12. Web URL address_______________________________ 13. Passport Details #_________....
X X X X Extracts X X X X
X X X X Extracts X X X X
....llage_______________________________ Road/Street/Lane/Post Office_______________________________ Area/Locality/Taluka/Sub-Division_______________________________ Town/City/District_______________________________ State/Union Territory Pin_______________________________ Fax No. _______________________________ Nationality_______________________________ In case of foreign national, Visa details_______________________________ Passport Details # Passport No. _______________________________ Passport issuing authority_______________________________ Passport expiry date_______________________________ Voter's Identity Card No. #_______________________________ Income Tax PAN no. #_______________________________ E-mail Address_______________________________ Personal Web page URL, if any_______________________________ For Government Organisations/Agencies 24 Particulars of Organisation/Agency : * Name of Organisation_______________________________ Administrative Ministry/Department_______________________________ Under State/Central Government_______________________________ Fl....
X X X X Extracts X X X X
X X X X Extracts X X X X
....articular information system, professional or other employee or contractor, Cr organization is approved to perform certain duties and to operate in a specific security mode. using a prescribed set of safeguards AUTHORITY REVOCATION LIST (ARL) A list of revoked Certifying Authority certificates An ARL is a CRL for Certifying Ausonty cross-certificates ADDRESSEE A person who is intended by the originator to receive the electronic record bul ones hot include any intermediary AFFILIATED CERTIFICATE A certificate issued to an affiliated individual (See also AFFILIATE L'INDIVIDU AT ) AFFIRM / AFFIRMATION To state or indicate by conduct that data is correct or information is true AFFIXING DIGITAL SIGNATURE With its grammatical variations and cognate expressions means adoption of any methodology or procedure by a person for the purpose of authenticating an electronic record by means of uigrial signature. ALIAS A pseudonym APPLICANT (See CA APPLICANT. CERTIFICATE APPLICANT) APPLICATION SOFTWARE A software that is specific to the solution of an application problem It is the software coded by or for an end user that performs a service or relat....
X X X X Extracts X X X X
X X X X Extracts X X X X
....s AVAILABILITY The extent to which information or processes are reasonably accessible and usable upon demand, by an authorized entity, allowing authorized access to resources and timely performance of time-critical operations. BACKUP The process of copying critical information, data and software for the purpose of recovering essential processing back to the time the backup was taken BINDING An affirmation by a Certifying Authority of the relationship between a named entity and its public key CERTIFICATE A Digital Signature Certificate issued by Certifying Authority CERTIFICATE CHAIN An ordered list of certificates containing an end-user subscriber certificate and Certifying Authority certificates (See VALID CERTIFICATE) CERTIFICATE EXPIRATION The time and date specified in the Digital Signature Certificate when the operational period ends, without regard to any earlier suspension or revocation CERTIFICATE EXTENSION An extension field to a Digital Signature Certificate which may convey additional information about the public key being certified, the certified subscriber, the Digital Signature Certificate issuer. and/or the certification proc....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ATE SERIAL NUMBER A value that unambiguously identifies a Digital Signature Certificate generated by a Certifyiny Authority CERTIFICATE SIGNING REQUEST (CSR) A machine-readable form of a Digital Signature Certificate application CERTIFICATE SUSPENSION (SEE SUSPEND A CERTIFICATE) CERTIFICATION / CERTIFY The process of issuing a Digital Signature Certificate by a Certifying Authority CERTIFYING AUTHORITY (CA) A person who has been granted a licence to issue a Digital Signature Certificate under section 24 of Information Technology Act. 2000 CERTIFYING AUTHORITY SOFTWARE The cryptographic software required to manage the keys of end entities CERTIFYING AUTHORITY SYSTEM All the hardware and software system (e g. Computer. PKi servers network devices ntc used by the Certifying Authority for generation, production, issue and management of Drutal Signature Certificate CERTIFICATION PRACTICE STATEMENT (CPS) A statement issued by a Certifying Authority to specify the practices that the Certif, no Authority employs in issuing Digital Signature Certificates CERTIFIER (See ISSUING AUTHORITY) CHALLENGE PHRASE A set of numbers and/or letters that....
X X X X Extracts X X X X
X X X X Extracts X X X X
....the use of satellite microwave. terrestrial line or other communication media, and (h) temunals or a complex consisting of two or more interconnected computers whether or not the interconnection is continuously maintained COMPUTER PERIPHERAL Means equipment that works in conjunction with a computer but is not a part of the main computer itself, such as printer, magnetic tape reader, etc COMPUTER RESOURCE Means computer, computer system, computer network, data, computer database or software COMPUTER SYSTEM A device or collection of devices, including input and output support devices and excluding calculators which are not programmable and capable of being used in conjunction with external files, which contain computer programmes, electronic instructions, input data and output data, that performs logic arithmetic, data storage and retrieval, communication control and other functions COMPUTER VIRUS (See VIRUS) CONFIDENTIALITY The condition in which sensitive data is kept secret and disclosed only to authorized parties à¤à¤¾à¤°à¤¤ का राजपतà¥à¤° : असाधारण [à¤....
X X X X Extracts X X X X
X X X X Extracts X X X X
....e by any means DATA Means a representation of information knowledge, facts concepts or instructions which are being prepared or have been prepared in a formalised manner, and is intended to be processed is being processed or has been processed in a computer system or computer network, and may be in any form (including computer printouts magnetic or optical storage media, punched cards. punched tapes) or stored internally in the memory of the computer. DATA BASE (See COMPUTER DATABASE) DATA CENTRE (as also COMPUTER CENTRE) The facility covering the computer room, media library, network area server area, programming and administration areas, other storage and support areas used to carry out the computer processing functions Usually refers to the computer room and media library DATA CONFIDENTIALITY (See CONFIDENTIALITY) ¡PART II -SEC 3(1)1 DATA INTEGRITY A condition in which data has not been altered or destroyed in an unauthorized manner (See also THREAT, COMPROMISE) DATA SECURITY The practice of protecting data from accidental or malicious modification, destruction, or disclosure DEMO CERTIFICATE A Digital Signature Certificate issued by a C....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ligent devices (such as routers or gateways, used to isolate networks. Firewalls make it difficult for attackers to jump from network to network A double firewall is two firewalls connected together Double firewalls are used to minimise risk if one firewall gets compromised or provide address translation functions. FILE TRANSFER PROTOCOL (FTP) The application protocol that offers file system access from the Internet suite of protocols FUNCTION In relation to a computer. includes logic, control arithmetical process deleher storage and retrieval and communication or telecommunication from or within a computer GATEWAY Hardware or software that is used to translate protocols between two or more systems GENERATE A KEY PAIR A trustworthy process of creating private keys during Digital Signature Certificate application whose corresponding public keys are submitted to the applicable Certifying Authority during Digital Signature Certificate application in a manner that demonstrates the applicants capacity to use the private key HARD COPY A copy of computer output that is printed on paper in a visually readable form 39 punted reports, listing, and documents H....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ation of a cryptographic transformation ie g encipherment, decipherment, cryptographic check function computation, signature generation or signature verification). KEY GENERATION The trustworthy process of creating a private key/public key pair KEY MANAGEMENT The administration and use of the generation, registration, certification, deregistration distribution, installation, storage, archiving, revocation, derivation and destruction of keying material in accordance with a security policy KEY PAIR In an asymmetnc crypto system, means a private key and its mathematically related public key. which are so related that the public key can verify a digital signature created by the private key LICENCE Means a licence granted to a Certifying Authority LOCAL AREA NE Ã…RK (LAN) A geographically small network of computers and supporting components used by a group or department to share related software and hardware resources LOW-SENSITIVE Applies to information that, if compromised, could reasonably be expected to cause injury outside the national interest, for example, disclosure of an exact salary figure. MANAGEMENT OF DIGITAL SIGNATURE CERTIFICATE [....
X X X X Extracts X X X X
X X X X Extracts X X X X
....ception Zone OPERATIONAL CERTIFICATE A Digital Signature Certificate which is within its operational period at the present date and time or at a different specified date and time, depending on the context OPERATIONAL MANAGEMENT Refers to all business/service unit management (I.e. the user management) as well as Information Technology management. OPERATIONAL PERIOD The period starting with the date and time a Digital Signature Certificate is issued (or on a later date and time certain if stated in the Digital Signature Certificate) and ending with the date and time on which the Digital Signature Certificate expires or is earlier suspended or revoked. ORGANIZATION An entity with which a user is affiliated An organization may also be a user. ORIGINATOR A person who sends, generates, stores or transmits any electronic message or causes any electronic message to be sent, generated, stored or transmitted to any other person but does not include an intermediary. PASSWORD (PASS PHRASE; PIN NUMBER) Confidential authentication information usually composed of a string of characters used to provide access to a computer resource. PARTICULARLY SENSITIVE ....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... It intercepts all requests to the real server to see if it can fulfill the request itself. If not, it forwards the request to the real server. PUBLIC ACCESS ZONE Generally surrounds or forms part of a government facility. Examples include the grounds surrounding a building, and public corridors and elevator lobbies in multiple-occupancy buildings. Boundary designators such as signs and direct or remote surveillance may be used to discourage unauthorized activity. PUBLIC KEY The key of a key pair used to verify a digital signature and listed in the Digital Signature Certificate. PUBLIC KEY CERTIFICATE (See CERTIFICATE) PUBLIC KEY CRYPTOGRAPHY (See CRYPTOGRAPHY) A type of cryptography that uses a key pair of mathematically related cryptographic keys. The public key can be made available to anyone who wishes to use it and can encrypt information or verify a digital signature; the private key is kept secret by its holder and can decrypt information or generate a digital signature. à¤à¤¾à¤°à¤¤ का राजपतà¥à¤° : असाधारण [ à¤à¤¾à¤— II-खणà¥à¤¡ 3....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... of the occurrence of those events. RISK MANAGEMENT The total process of identifying, controlling, and eliminating or minimizing uncertain events that may affect Information Technology system resources. RSA A public key cryptographic system invented by Rivest, Shamir & Adelman. [PART II-SEC. 3(i)] SECRET SHARE A portion of a cryptographic secret split among a number of physical tokens SECRET SHARE HOLDER An authorized holder of a physical token containing a secret share. SECURE CHANNEL A cryptographically enhanced communications path that protects messages against perceived security threats. SECURE SYSTEM Means computer hardware, software, and procedure that- (a) are reasonably secure from unauthorised access and misuse. (b) provide a reasonable level of reliability and correct operation, (c) are reasonably suited to performing the intended functions, and (d) adhere to generally accepted security procedures SECURITY PROCEDURE Means the security procedure prescribed under section 16 of the Information Technology Act, 2000 SECURITY The quality or state of being protected from unauthorized access or uncontrolled losses or ....
X X X X Extracts X X X X
X X X X Extracts X X X X
.... and to the individual person, if any. who controls that equipment or device A subject is assigned an unambiguous name, which is bound to the public key contained in the subject's Digital Signature Certificate SUBJECT NAME The unambiguous value in the subject name field of a Digital Signature Certificate which Is bound to the public key SUBSCRIBER A person in whose name the Digital Signature Certificate is issued SUBSCRIBER AGREEMENT The agreement executed between a subscriber and a Certifying Authority for the provision of designated public certification services in accordance with this Certification Practice Statement SUBSCRIBER INFORMATION Information supplied to a certification authority as part of a Digital Signature Certificate application (See also CERTIFICATE APPLICATION) SUSPEND A CERTIFICATE A temporary "hold" placed on the effectiveness of the operational period of a Digital Signature Certificate without permanently revoking the Digital Signature Certificate A Digital Signature Certificate suspension is invoked by, e.g., a CRL entry with a reason code (See also REVOKE A CERTIFICATE) SYSTEM ADMINISTRATOR The person at a computer in....
X X X X Extracts X X X X
X X X X Extracts X X X X
....arty that contributes to the ultimate security and trustworthiness of computer-based information transfers. A trusted third party does not connote the existence of a trustor-trustee or other fiduciary relationship. (Cf., TRUST) TRUSTWORTHY SYSTEM Computer hardware, software, and procedures that are reasonably secure from intrusion and misuse; provide a reasonable level of availability, reliability, and correct operation, are reasonably suited to performing their intended functions; and enforce the applicable security policy A trustworthy system is not necessarily a "trusted system" as recognized in classified government nomenclature TYPE (OF CERTIFICATE) The defining properties of a Digital Signature Certificate, which limit its intended purpose to a class of applications uniquely, associated with that type. UNAMBIGUOUS NAME (See DISTINGUISHED NAME) UNIFORM RESOURCE LOCATOR (URL) A standardized device for identifying and locating certain records and other resources located on the World Wide Web. USER An authorized entity that uses a certificate as applicant, subscriber, recipient or relying party, but not including the Certifying Authority issuing the Digita....
TaxTMI