The
government of India has put its cyber security initiative on fast
track after years of neglect and looming threat of cyber-attacks.
Going a step further from the announcement of the Cyber Security
Policy a few days ago, on Friday, the ‘Guidelines for Protection
of National Critical Information Infrastructure,’ were placed in
the public domain.
The
detailed document was prepared by the National Critical Information
Infrastructure Protection Centre (NCIIPC) which is to function as a
specialised unit under the National Technical Research Organisation
(NTRO).
Across
the world, critical information infrastructure is broadly defined
as including those networks which are interrelated, interconnected
and interdependent. In India, the guidelines would initially
include information and communications, transportation, energy,
finance, technology, law enforcement, security and law enforcement,
government, space and sensitive organizations.
India’s
new guidelines are an extension of a legislative recognition under
the IT Act 2000, which defines critical information infrastructure
as “those computer resource and incapacitation or description of
which, shall have debilitating impact on national security,
economy, public health or safety”.
These
guidelines go beyond the statement of intent expressed in the
recently announced cyber security policy and have been formulated
through a multi-stakeholder Joint Working Group (JWG) consisting of
representatives from the government, academia and private sector.
The JWG held wide consultations with sector experts and regulators
across the key sectors before finalising the guidelines.
The
cyber-security initiative is unique since given the vast ownership
of the private sector of networks, infrastructure and consumers in
telecom, Internet, banking, civil aviation, energy and transport
sectors, they will now need to actively collaborate with the
NCIIPC, as well as participate to ensure effective implementation
of the guidelines.
Telecom
service providers which provide a vast majority of the underlying
national network are not only the first line of defence to any
cyber-attack on the critical information infrastructure but in fact
interconnect several other networks, such as aviation, energy and
transport to each other and to the nearly 700 million Indians who
have access to telephony and to a smaller degree to Internet and
social media.
Members
of the JWG agreed that this was only the first version of the
guidelines which would need to continuously evolve, given the speed
at which technology is changing, services evolving and citizens
adapting to the same. The JWG also recognised that threats to the
critical information infrastructure, unlike traditional national
security, can arise from within the country, enemy States and
non-state actors from outside India.