Official Gazette Notification Text
Official Transcriptरजिस्ट्री स.ं डी.एल.- 33004/99 REGD. No. D. L.-33004/99 सी.जी.-डी.एल.-अ.-05082026-275218 xxxGIDHxxx CG-DL-E-05082026-275218 xxxGIDExxx असाधारण EXTRAORDINARY भाग III—खण् ड 4 PART III—Section 4 प्राजधकार स ेप्रकाजित PUBLISHED BY AUTHORITY स.ं 484] नई दिल्ली, िुििार, िुलाई 31, 2026/श्रािण 9, 1948 ष 22, 1947 No. 484] NEW DELHI, FRIDAY, JULY 31, 2026/SHRAVAN 9, 1948 s 1947 केन्द्रीय जिद्यतु...
रजिस्ट्री स.ं डी.एल.- 33004/99 REGD. No. D. L.-33004/99 सी.जी.-डी.एल.-अ.-05082026-275218 xxxGIDHxxx CG-DL-E-05082026-275218 xxxGIDExxx असाधारण EXTRAORDINARY भाग III—खण् ड 4 PART III—Section 4 प्राजधकार स ेप्रकाजित PUBLISHED BY AUTHORITY स.ं 484] नई दिल्ली, िुििार, िुलाई 31, 2026/श्रािण 9, 1948 ष 22, 1947 No. 484] NEW DELHI, FRIDAY, JULY 31, 2026/SHRAVAN 9, 1948 s 1947 केन्द्रीय जिद्यतु प्राजधकरण अजधसचू ना नई दिल्ली, 31 िुलाई, 2026 फा. स.ं सीईए-एचिाई-91-19/8/2024-साइबर सरु क्षा प्रभाग.- जिद्युत (पूिव प्रकािन की प्रदिया) जनयम, 2005 के जनयम 3 के उप जनयम (2) के साथ पठित जिद्युत अजधजनयम, 2003 (2003 का 36) की धारा 177 की उप धारा (3) के द्वारा यथाअपेजक्षत केंरीय जिद्युत प्राजधकरण (जिद्युत क्षेत्र में साइबर सुरक्षा) जिजनयम, 2025 के प्रारूप का जिज्ञापन करने िाली सािविजनक सूचनाएं छह िैजनक समाचार पत्रों में प्रकाजित की गईं थीं, तादक उनसे प्रभाजित होन े की संभािना िाले सभी व्यजियों से उि प्रारूप जिजनयमों की प्रजतयां िनता को उपलब्ध कराए िाने की तारीख स े तीस दिन की अिजध समाप्त होने से पहल ेआपजियां और सुझाि आमंजत्रत दकए िा सकें;
और सािविजनक सूचनाएं अंतर्िवष्ट करने िाले उि समाचार पत्रों की प्रजतयां और प्रारूप जिजनयम केन्द्रीय जिद्युत प्राजधकरण की िेबसाइट पर 07 अक्टूबर, 2025 को िनता के जलए उपलब्ध करा िी गई थीं; और उि प्रारूप जिजनयमों पर िनता से प्राप्त आपजियों और सझु ािों पर केन्द्रीय जिद्युत प्राजधकरण न े जिचार दकया था;
और इलेक्रॉजनकी और सूचना प्रौद्योजगकी मंत्रालय न े जिद्युत क्षेत्र के जलए साइबर सुरक्षा के संबंध म ें इन जिजनयमों को बनाने के जलए अपनी सहमजत ि ेिी ह।ै 5963 GI/2026 (1)2 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4] अतः, अब, केन्द्रीय जिद्युत प्राजधकरण जिद्युत अजधजनयम, 2003 (2003 का 36) की धारा 73 की खंड (ग) के साथ पठित धारा 177 की उप-धारा (1) द्वारा प्रिि िजियों का प्रयोग करत े हुए, जिद्युत संयंत्रों और जिद्युत लाइनों के सुरजक्षत संचालन और रखरखाि को सुजनजित करने के जलए जिद्युत क्षेत्र में साइबर सुरक्षा से संबंजधत जनम्नजलजखत जिजनयम बनाता ह,ै अथातव :- अध्याय I प्रारंजभक
1. सजं क्षप्त नाम और प्रारंभ - (1) इन जिजनयमों का संजक्षप्त नाम केंरीय जिद्युत प्राजधकरण (जिद्युत क्षेत्र में साइबर सुरक्षा) जिजनयम, 2026 ह।ै
(2) य ेजिजनयम 1 अप्रलै 2027 से प्रिृि होंग:े परंतु जिजनयम 5(9), 5(24), 5(33), 5(39), 6(2) और 6(7) उन तारीखों से प्रिृि होंगे, जिन्द्ह ें प्राजधकरण केंरीय सरकार के पूिव अनुमोिन से पथृ क आिेिों के माध्यम स ेजिजनर्िवष्ट करे।
2. लाग ूहोन ेकी पठरजध और जिस्ट्तार - (1) य ेजिजनयम इन जनम्नजलजखत को लाग ूहोंगे: - (क) सभी संस्थाए,ं अपन े जिद्यमान और आगामी अिसंरचना के लिए, जो आपस म ें जडु ी जिद्युत प्रणािी स े जडु े पररचािन प्रौद्योलगकी अिसंरचना और उनके सूचना प्रौद्योलगकी अिसंरचना, जो ऐस े पररचािन प्रौद्योलगकी अिसंरचना स े भौलिक या िार्किक रूप स े जुडी हुई ह,ैं का स्वालमत्व, संचािन या प्रबंधन करिी हैंःैं परंतु जबिली बनाने िाली कंपजनयों, कैजटटि जिद्युत संयंत्र और उिाव भण्डारण प्रणाली िाले संगिनों के मामल े म,ें य ेजिजनयम तभी लाग ूहोंगे िब उनकी संस्ट्थाजपत क्षमता 50 मेगािाट या उससे अजधक हो:
परंत ु यह और दक, जिन संस्ट्थाओं की संस्ट्थाजपत क्षमता 50 मेगािाट से कम ह,ै उन्द्ह ें ‘भारतीय कंटयूटर आपात मोचन िल' द्वारा िारी "सूक्ष्म, लघ ु और मध्यम उद्यम के जलए 15 बुजनयािी साइबर सुरक्षा कंरोल” म ें बताए गए न्द्यूनतम साइबर सुरक्षा उपायों को लाग ूकरन े के जलए प्रोत्साजहत दकया िाता ह;ै (ख) जिजनयम 6, 11 और 12 के जसिाय, जिद्युत जिजनयय एक्सचेंि और ओिर-ि-काउंटर टलटे फॉमव।
(2) िडें र इन जिजनयम के जिजनयम 11 और जिजनयम 12 का पालन करेगा, जैसा िाग ू हो।
3. पठरभाषाएँ - (1) इन जिजनयमों में, िब तक संिभ वसे अन्द्यथा अपेजक्षत न हो - (क) “अजधजनयम” स ेजिद्युत अजधजनयम, 2003 (2003 का 36) अजभप्रेत ह;ै (ख) “सामानों का जबल” से दकसी उत्पाि या प्रणाली म ें उपयोग दकए िाने िाले घटकों, उप-घटकों, सामग्री, पुस्ट्तकालयों, और मॉड्यूल की एक व्यापक सूची और संरजचत िस्ट्त ु सूची अजभप्रेत है, तादक ऐसे उत्पाि या प्रणाली की सरं चना म ेंव्यापक िश्ृ यता और पारिर्ितव ा को सुजिधािनक बनाया िा सके;
(ग) “कारबार जनरंतरता योिना” स े िस्ट्तािेजीकृत प्रदियाएं अजभप्रते ह ैं िो दकसी संगिन को जनरंतर संचालन के एक पठरभाजषत स्ट्तर को बनाए रखने म ेंमागवििवन करती ह;ैं (घ) “मख्ु य सचू ना सरु क्षा अजधकारी” से दकसी संस्ट्था के िठरष्ठ प्रबधं न स्ट्तर का नाजमत कमवचारी अजभप्रेत है, जिस े साइबर सुरक्षा और उससे िडु े मामलों की िानकारी हो, और िो साइबर सुरक्षा के प्रयासों और पहलों के जलए उिरिायी ह;ै (ङ) “मख्ु य सचू ना सरु क्षा अजधकारी- जिद्यतु मत्रं ालय" स े जिद्युत मंत्रालय का मख्ु य सूचना सरु क्षा अजधकारी अजभप्रेत ह;ै (च) “सचं ार प्रणाली” स े पथृ क-पृथक संचार नेटिकव, संचार मीजडया, ठरलेइंग स्ट्टेिन, ठरब्यूटरी स्ट्टेिन, टर्मवनल उपकरण का एक संग्रह अजभप्रते ह ै िो आमतौर पर जिद्युत क्षेत्र के जलए एक एकीकृत संचार बनाने के जलए अंतसंबंध और अतं र-प्रचालन म ेंसक्षम होत े ह;ैं[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 3 (छ) “कंटयटू र सरु क्षा घटना मोचन िल- जिद्यतु ” स े जिद्युत क्षेत्र म ें साइबर सुरक्षा घटनाओं का समायोिन करने, ठरपोटव करने और उनका मोचन करने के जलए जिद्युत मंत्रालय द्वारा भारतीय कंटयूटर आपात मोचन िल के एक जिस्ट्ताठरत िाखा के रूप म ेंस्ट्थाजपत एक सगं िन अजभप्रेत है;
(ि) “नािकु सचू ना प्रौद्योजगकी प्रणाली” स े दकसी सगं िन की सूचना प्रौद्योजगकी प्रणाली अजभप्रेत ह,ै जिनकी अनुपलब्धता या खराबी उसके कारबार प्रचालन पर प्रजतकूल प्रभाि डालगे ी; (झ) “नािकु पठरचालन प्रौद्योजगकी प्रणाली” स े दकसी संगिन की प्रचालन प्रौद्योजगकी प्रणाली अजभप्रेत ह,ै जिनकी अनुपलब्धता या खराबी उसके कारबार प्रचालन पर प्रजतकूल प्रभाि डालगे ी;
(ञ) “नािकु प्रणाली” स े नािुक प्रचालनात्मक प्रौद्योजगकी प्रणाली या नािुक सूचना प्रौद्योजगकी प्रणाली या िोनों अजभप्रेत ह,ै जिसमें लाग ूहोने पर, दकसी संस्ट्था की िठटल सूचना अिसंरचना िाजमल है; (ट) “नािकु सचू ना अिसरं चना” से िह िठटल सूचना अिसंरचना अजभप्रेत ह,ै जिसे सूचना प्रौद्योजगकी अजधजनयम, 2000 (2000 का 21) की धारा 70 की उप-धारा (1) के स्ट्पष्टीकरण में पठरभाजषत दकया गया ह;ै (ि) “साइबर आजस्ट्त” स े प्रोग्रामेबल इलेक्रॉजनक जडिाइस, जिसमें कंटयूटटंग क्षमताएं हों या न हों, अजभप्रते ह ै जिसमें उसका हाडविेयर, सॉफ्टिेयर, सब-कंपोनेंट और उसका डेटा िाजमल ह ैिो एक नेटिकव से िुडे होत े हैं;
(ड) “साइबर आजस्ट्तयों रजिस्ट्टर” स े एक ऐसा अजभलेख अजभप्रेत ह ै जिसमें सभी साइबर आजस्ट्तयों की सूची और उनका जििरण होता ह;ै (ढ) “साइबर सकं ट प्रबधं न योिना” से साइबर संकट प्रबंधन योिना अजभप्रेत ह,ै िैसा दक सचू ना प्रौद्योजगकी (संरजक्षत प्रणाली के जलए सूचना सुरक्षा अभ्यास और प्रदियाए)ं जनयम, 2018 के जनयम 2 के उप-जनयम (1) के खंड (घ) म ेंपठरभाजषत दकया गया ह;ै (ण) “साइबर समत्ु थान-िजि” स े साइबर आजस्ट्त पर खराब जस्ट्थजतयों, तनाि, आिमणों या समझौतों का अनुमान लगान,े उनका सामना करन,े उनसे उबरन े और उनके अनुरूप ढलन े की क्षमता अजभप्रेत है;
(त) “साइबर सरु क्षा सपं रीक्षा” स े भारतीय कंटयूटर आपातकालीन मोचन िल पनै ल म ें िाजमल संपरीक्षक या भारत सरकार के जिद्युत मंत्रालय द्वारा पृथक आििे से अजभजहत दकसी अन्द्य संपरीक्षक द्वारा साइबर सुरक्षा की जस्ट्थजत का जनधावरण करने के जलए की गई संपरीक्षा अजभप्रेत ह;ै (थ) “साइबर सरु क्षा उल्लघं न” से साइबर सुरक्षा उल्लंघन अजभप्रेत ह,ै िैसा दक सूचना प्रौद्योजगकी (भारतीय कंटयूटर आपातकालीन मोचन िल और कायों ि कतवव्यों के जनष्पािन की रीजत) जनयम, 2013 के जनयम के उप-जनयम (1) के खंड (झ) म ेंपठरभाजषत दकया गया ह;ै (ि) “साइबर सरु क्षा घटना” स े साइबर सुरक्षा घटना अजभप्रते ह,ै िैसा दक सूचना प्रौद्योजगकी (भारतीय कंटयूटर आपातकालीन मोचन िल और कायों ि कतवव्यों के जनष्पािन की रीजत) जनयम, 2013 के जनयम 2 के उपजनयम (1) के खंड (ि) में पठरभाजषत दकया गया ह;ै (ध) “साइबर सरु क्षा नीजत” से िानकारी, कंटयूटर संसाधनों, नेटिकव, जडिाइस, औद्योजगक जनयंत्रण प्रणाली और प्रचालन प्रौद्योजगकी संसाधन को सुरजक्षत रखन े और उनकी साइबर सुरक्षा जस्ट्थजत म ें सुधार करन े के जलए जनयम और प्रदियाऐं अजभप्रेत ह;ैं (न) “साइबर तोडफोड” स े जिद्वषे पणू व प्रयोिन से सूचना प्रणाली, नेटिकव, या उसम ें प्रोसेस दकए गए डेटा को बाजधत करन,े नुकसान पहुचं ाने या नष्ट करन े के जलए िानबूझकर की गई कारविाई अजभप्रेत है;
(प) “जितठरत उत्पािन ससं ाधन” स े एक ऐसा उत्पािन स्ट्टेिन अजभप्रेत ह ै िो 33 केिी से कम िोल्टेि स्ट्तर पर जिद्युत प्रणाली म ें जबिली फीड करता ह,ै और इसम ें जग्रड से िुड े रूफटॉप सोलर प्रणाली और ऊिा व भंडारण प्रणाली िाजमल ह;ैं (फ) “इलक्े रॉजनक सरु क्षा पठरजध”: स े सूचना प्रौद्योजगकी प्रणाली या पठरचालन तकनीक प्रणाली या िोनों के चारों4 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4] ओर की तार्कवक सीमा अजभप्रेत ह ै िो इलक्े रॉजनक रूप से िडु े हुए हैं, जिसके अंिर ऐसी प्रणाली की सुरक्षा के जलए एक्सेस की जनगरानी एिं जनयंत्रण दकया िाता ह;ै (ब) “सस्ट्ं था” म ें उत्पािन कंपजनयाँ, कैजटटि उत्पािन संयंत्र, ऊिाव भंडारण प्रणाली िाली सस्ट्ं थाएं; पारेषण लाइसेंसधारी; जितरण लाइसेंसधारी; राष्ट्रीय भार प्रषे ण केंर; क्षेत्रीय भार प्रेषण केंर; राज्य भार प्रेषण केंर, ऊिाव जिजनमय, ओिर ि काउंटर टलेटफॉम विाजमल ह;ैं (भ) “फैक्री स्ट्िीकृजत परीक्षण” स े िेंडर द्वारा, संस्ट्था के प्रजतजनजध की उपजस्ट्थजत में, प्रणाली या उपकरण या उसके मुख्य कंपोनेंट की कायावत्मक, प्रििवन, संजििात्मक और सरु क्षा अपेक्षाओं को सत्याजपत करने के जलए, प्रषे ण स े पहले की िाने िाली सरं जचत और प्रलेजखत परीक्षण प्रदिया अजभप्रेत ह;ै (म) “सचू ना प्रौद्योजगकी प्रणाली” स ेसूचना प्रौद्योजगकी प्रणाली अजभप्रेत ह ैजिसमें उपयोगकताव एडं पॉइंट्स, नेटिकव संसाधन, एटलीकेिन, सिवर और उसमें तनै ात दकए गए संचार घटक िाजमल ह ैं और जिसका प्रचालन प्रौद्योजगकी अिसंरचना के साथ भौजतक या तार्कवक सम्बन्द्ध ह;ै (य) “अप्रचजलत आजस्ट्त” से ऐसी आजस्ट्त अजभप्रेत ह ै जिसे मूल उपकरण जनमावता या मलू उपकरण आपूर्तवकताव न े पुराना घोजषत कर दिया है, जिसका उत्पािन और सेिाएं बंि कर िी गई ह,ैं और उसका सहयोग अब उपलब्ध नहीं ह,ै और िह आजस्ट्त तकनीकी तरक्की, प्रचालनात्मक बिलािों के कारण अपने आिजयत प्रयोिन के जलए उपयुि नहीं ह ैऔर इससे सुरक्षा या प्रचालनात्मक िोजखम हो सकता ह;ै (य क) “प्रचालनात्मक प्रौद्योजगकी” स े प्रोग्रामेबल हाडविेयर या प्रणाली अजभप्रेत ह ै िो दफजिकल जडिाइस, प्रदिया और इिेंट की सीधी जनगरानी या जनयंत्रण के माध्यम से बिलािों का पता लगाता ह ै या बिलाि करता ह;ै (य ख) “प्रोज़्यमू र” से एक ऐसा व्यजि अजभप्रेत ह,ै िो जग्रड से जबिली लेता ह ै और उसी आपूर्तव बबंि ु का उपयोग करके जितरण लाइसेंसधारी के जलए जग्रड म ेंजबिली डाल भी सकता ह;ै (य ग) “सरं जक्षत प्रणाली” स े ‘सूचना प्रौद्योजगकी (संरजक्षत प्रणाली के जलए सूचना सरु क्षा प्रथाएं और प्रदियाए)ं जनयम, 2018’ जनयम 2 के उप-जनयम (1) की धारा (ट) म ें बताई गई पठरभाषा के अनसु ार ‘संरजक्षत प्रणाली’;
(य घ) “ठरमोट एक्ससे ” से दकसी बाहरी नेटिकव के माध्यम से दकसी संगिन के दकसी भी साइबर आजस्ट्त तक पहुचं अजभप्रेत ह;ै (य ङ) “ठरमोट प्रचालन” से दकसी संस्ट्था की सूचना प्रौद्योजगकी या पठरचालन तकनीक प्रणाली का दिनप्रजतदिन का प्रचालन और जनयंत्रण अजभप्रेत ह,ै िो ऐसी प्रणाली से िरू दकसी िगह से दकया िाता ह;ै (य च) “स्ट्ि लखे ा परीक्षा ” स े दकसी संस्ट्था द्वारा एक जििीय िषव म ें इन जनयमों में जिजनर्िवष्ट सभी लाग ू जनयमों के पालन का आकलन करन े के जलए लेखा परीक्षा अजभप्रेत ह;ै (य छ) “सिं िे निील िानकारी” से िह डेटा या िानकारी अजभप्रेत ह ै जिसे अगर बताया िाए, बिला िाए, या नष्ट दकया िाए तो दकसी संगिन या व्यजि की जनिता, अखडं ता, सुरक्षा या कामकाि पर नकारात्मक प्रभाि पड सकता ह;ै (य ि) “साइट स्ट्िीकृजत परीक्षण” से स्ट्थापना पर कायावत्मक, प्रििनव , संजििात्मक और सुरक्षा अपेक्षाओं को सत्याजपत करन े के जलए दकया गया सरं जचत और िस्ट्तािेजित परीक्षण अजभप्रेत है, और यह सुजनजक्षत करना दक कोई प्रणाली या उपकरण और उसके मख्ु य घटक, प्रचालनारंभ/चालू करने स े पहले, अपने अंजतम प्रचालनात्मक माहौल म ेंिैसा आिजयत दकया गया ह;ै (य झ) “उप-क्षत्रे ीय कंटयटू र सरु क्षा घटना मोचन िल” से प्राजधकरण द्वारा नाजमत एक ऐसी संस्ट्था अजभप्रेत ह ै िो साइबर सुरक्षा से िडु े मामलों में कंटयूटर सुरक्षा घटना मोचन िल– जिद्युत की सहायता करे;[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 5 (य ञ) “तकनीकी मानिंड प्रमाण-पत्र” से दकसी संगिन को एक प्राजधकृत प्रमाणन जनकाय द्वारा िारी दकया गया प्रमाण-पत्र अजभप्रेत ह,ै िो केंरीय सरकार द्वारा जिजनर्िवष्ट साइबर सुरक्षा मानकों के अनुपालन को सुजनजित करने के जलए मान्द्यता प्राप्त हो;
(य ट) “खतरा” स े कोई भी पठरजस्ट्थजत या घटना अजभप्रेत ह ै जिसमें दकसी कमी का फायिा उिान े और दकसी साइबर आजस्ट्त या सूचना प्रौद्योजगकीप्रणाली या पठरचालन तकनीक प्रणाली की गोपनीयता, अखंडता या उपलब्धता पर नकारात्मक असर डालन े की क्षमता हो;
(य ि) “जिश्वसनीय स्रोत” से एक ऐसी मैकेजनिम अजभप्रेत ह ै जिसे खास सुरक्षा अपेक्षाओं, खासकर साइबर सरु क्षा आपूर्तव चेन िोजखमों को कम करने के जलए यह सुजनजित करके जडजाइन दकया गया है, दक जिद्युत क्षेत्र स े िुडे उपकरण, जनमावता, सेिाएं और सेिा प्रिाता एक तय मानिंड को पूरा करते ह;ैं (य ड) “भद्ये ता” स े सूचना प्रौद्योजगकी (भारतीय कंटयूटर आपात मोचन िल और कायों तथा कतवव्यों के जनष्पािन की रीजत) जनयम, 2013 के जनयम 2 के उप-जनयम (1) के खडं (त) म ेंबताई गई भेद्यता अजभप्रेत ह;ै (य ढ) “िडें र” से मलू उपकरण जनमावता, मलू उपकरण आपूर्तवकताव, प्रणाली इंटीग्रेटर, मलू उपकरण से िडु े हाडविेयर या सॉफ्टिेयर का आपूर्तवकताव, िेकेिार या सेिा प्रिाता, जिसमें क्लाउड सेिा प्रिाता भी िाजमल ह;ै और प्रोज़्यूमर के स्ट्िाजमत्ि िाले जितठरत उत्पािन संसाधन के मूल उपकरण या कंरोल प्रणाली से िडु े हाडविेयर, फमविेयर या सॉफ्टिेयर का जनमावता और आपूर्तकव ताव, इसमें इनिटवर, कम्युजनकेिन मॉड्यलू , मॉजनटटरंग प्रणाली और संबंजधत कंरोल या एनिी मैनेिमटें सॉफ्टिेयर िाजमल हैं, लेदकन ये इन्द्हीं तक सीजमत नहीं ह।ैं
(2) इन जिजनयमों में प्रयुि लेदकन पठरभाजषत नहीं दकए गए िब्िों और पिों का िही अथव होगा िो उनका अजधजनयम, उसके अधीन बनाए गए जनयमों और जिजनयमों में ह।ै अध्याय 2 कंटयटू र सरु क्षा घटना मोचन िल– जिद्यतु
4. (1) कंटयटू र सरु क्षा घटना मोचन िल – जिद्यतु (क) जिद्युत क्षेत्र से िुड ेसाइबर सरु क्षा घटना की ठरपोर्टंग और उन पर कारविाई के जलए समन्द्िय एिेन्द्सी होगी; (ख) साइबर सुरक्षा घटना के जिश्लेषण, भजिष्यिाणी और रोकथाम और उससे संबंजधत िानकारी फैलाने के जलए जिद्युत क्षेत्र की नोडल एिेंसी होगी;
(ग) दकसी भी साइबर सुरक्षा घटना से संबंजधत डेटा और िानकारी दकसी भी संस्ट्था से इकट्ठा करेगी, जिसम ें नेटिकव संरचना, आजस्ट्तयों का जििरण, लॉग्स, साइबर फोरेंजसक ठरकॉडव, फोरेंजसक इमिे , पॉजलसी और प्रदिया, और कोई भी अन्द्य संबंजधत िानकारी उस प्ररूप, रीजत और ढगं म ें िाजमल है, िैसा दक इसके द्वारा जिजनर्िवष्ट दकया गया ह:ै परंत ु इकट्ठा दकया गया संिेिनिील डेटा और संिेिनिील िानकारी को भंग होन े से बचाया िाएगा और इसका प्रयोग जसफव अजभजहत सरकारी अजभकरणों द्वारा साइबर सुरक्षा के प्रयोग से दकया िाएगा, लेदकन संबंजधत संस्ट्था को प्रकट संसूचना के जबना दकसी तीसरे पक्ष को इसका प्रकटन नहीं दकया िाएगा।
(2) जिद्यतु क्षत्रे म ें 'कंटयटू र सरु क्षा घटना मोचन िल- जिद्यतु ' की भजू मकाओं और उिरिाजयत्िों म ें जनम्नजलजखत िाजमल ह,ैं अथातव :् (क) जिद्युत क्षेत्र स े संबंजधत साइबर घटनाओं, कमजोठरयों और खतरों को इकट्ठा करना और उनका जिश्लेषण करना;
(ख) जिद्युत क्षेत्र से संबंजधत साइबर सुरक्षा घटनाओं, खतरों और कमजोठरयों का अनुमान लगाना;6 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4] (ग) जिद्युत क्षेत्र से िडु े साइबर सुरक्षा घटना को सुलझान े के जलए भारतीय कंटयूटर आपात मोचन िल, राष्ट्रीय महत्िपूणव सूचना अिसंरचना संरक्षण केंर और केंर सरकार द्वारा अजभजहत की गई अन्द्य अजभकरणों के साथ समन्द्िय और सहयोग करना;
(घ) भारतीय कंटयूटर आपात मोचन िल, राष्ट्रीय महत्िपूण व सूचना अिसंरचना संरक्षण केंर और केंरीय सरकार द्वारा साइबर सुरक्षा के क्षेत्र में नाजमत दकसी भी अन्द्य एिेंसी के साथ जमलकर अलटव, एडिाइिरी और दििाजनिेि के साथ-साथ खतरे की िानकारी िारी करना;
(ङ) भारतीय कंटयूटर आपात मोचन िल, राष्ट्रीय महत्िपूण व सूचना अिसंरचना सरं क्षण केंर, उप-क्षेत्रीय कंटयूटर सुरक्षा घटना मोचन िलों, जिद्युत जिजनयामक आयोगों, संस्ट्थाओं और केंरीय सरकार द्वारा साइबर सुरक्षा के क्षेत्र म ें नाजमत अन्द्य अजभकरणों के साथ सलाह करके मानक संचालन प्रदियाएं, सुरक्षा नीजतयां, उप-क्षेत्र जिजिष्ट बेंचमाकव, सुरक्षा जनयंत्रण और घटना मोचन गजतजिजधयों के जलए सिोिम प्रथाएं बनाना या जिकजसत करना;
(च) क्षमता जनमावण पहलों और हस्ट्तक्षेपों के माध्यम स े साइबर सुरक्षा िागरूकता बढान े के जलए सदिय उपाय करना; (छ) साइबर सुरक्षा जनधावरण, साइबर सुरक्षा संपरीक्षा, प्रमाणीकरण संपरीक्षा, स्ट्ि- संपरीक्षा, थडव पाटी संपरीक्षा और मॉक-जिल और जसमुलेिन सजहत अभ्यासों द्वारा जिद्युत क्षेत्र की साइबर सुरक्षा जस्ट्थजत में सुधार सुजनजित करना;
(ि) उप-क्षेत्र जिजिष्ट साइबर सुरक्षा ढांचा, प्रोटोकॉल और जनयम बनाने के जलए समन्द्िय करना; (झ) संस्ट्थाओं को उनके साइबर संकट प्रबंधन योिना को तैयार करने में सलाह िने ा; (ञ) िास्ट्तजिक साइबर संकट के िौरान उनके साइबर संकट प्रबंधन योिना के कायावन्द्ियन को सुजनजित करन े के जलए संस्ट्था के साथ समायोिन करना;
(ट) उद्योग, अनुसन्द्धान संस्ट्था और एकेडेजमया के साथ जमलकर साइबर सुरक्षा के क्षेत्र में अनुसन्द्धान एिं जिकास को सुजिधािनक बनाना और बढािा िेना; (ि) केंरीय सरकार या प्राजधकरण द्वारा जिजनर्िवष्ट साइबर आजस्ट्तयों की आपूर्तव चने की साइबर सुरक्षा सुजनजित करने के जलए उपायों को जिरजचत और कायावजन्द्ित करना;
(ड) प्राजधकरण द्वारा िारी एक पथृ क आिेि के अनुसार, कंटयूटर सुरक्षा घटना मोचन िल- जिद्युत को सहयोग करने के जलए जिद्युत क्षेत्र के केंरीय साइबर सुरक्षा समन्द्िय मंच और क्षेत्रीय साइबर सुरक्षा समन्द्िय मंच स्ट्थाजपत करना, तादक साइबर सुरक्षा की जस्ट्थजत की समय-समय पर समीक्षा की िा सके, साइबर सुरक्षा की चुनौजतयों पर जिचार-जिमिव दकया िा सके, िानकारी साझा की िा सके, समायोजित प्रत्युिर योिना बनाई िा सके और क्षेत्र की कुल जस्ट्थजत में सुधार दकया िा सके;
(ढ) केन्द्रीय सरकार या प्राजधकरण द्वारा यथाजनिेजित जिद्युत क्षेत्र में साइबर सुरक्षा स े संबंजधत मामलों से िुड े कोई अन्द्य कायव।
(3) जिद्युत क्षेत्र की साइबर सुरक्षा से िडु े मामलों म ें कंटयूटर सुरक्षा घटना मोचन िल– जिद्युत के जनिेिों और दििा- जनिेिों का पालन, संस्ट्थाओं और िेंडरों, िैसे लागू हो, द्वारा दकया िाएगा।
(4) प्राजधकरण एक पृथक आििे के माध्यम से जिद्युत क्षेत्र म ें उत्पािन, पारेषण, जितरण, जग्रड संचालन और दकसी भी अन्द्य उप-क्षेत्र के जलए उप-क्षेत्रीय कंटयूटर सुरक्षा घटना मोचन िल को नाजमत कर सकेगी, साथ ही कंटयूटर सुरक्षा घटना मोचन िल–जिद्युत की सहायता के जलए उनकी भूजमकाएं और जिम्मेिाठरयां भी तय कर सकेगी। अध्याय 3 साधारण साइबर सरु क्षा अपक्षे ाएं[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 7
5. सस्ट्ं था-
(1) िठरष्ठ प्रबधं न स्ट्तर के जनयजमत कमवचाठरयों को मुख्य सूचना सुरक्षा अजधकारी और िैकजल्पक मख्ु य सूचना सुरक्षा अजधकारी के रूप में जनयिु करेगी;
(2) यह सुजनजित करेगी दक मख्ु य सूचना सुरक्षा अजधकारी और िकै जल्पक मुख्य सूचना सुरक्षा अजधकारी पि एक ही समय पर ठरि न रह;ें
(3) केंरीय सरकार के जनयामक रूपरेखा और संबंजधत दििा-जनिेि के अनुसार मुख्य सूचना सुरक्षा अजधकारी और िैकजल्पक मुख्य सूचना सुरक्षा अजधकारी की भूजमकाएं और जिम्मेिाठरयां तय करेगी;
(4) यह सुजनजित करेगी दक मुख्य सूचना सुरक्षा अजधकारी संस्ट्था के प्रमुख को ठरपोटव करे: परंत,ु यदि कोई संस्ट्था, िैसे दक 'राज्य भार प्रेषण केंर', कोई स्ट्ितंत्र संस्ट्था न होकर दकसी धृजत कंपनी या मूल कंपनी का जहस्ट्सा हो, िो भी लागू हो, तो ऐसी संस्ट्था के जलए एक पृथक 'मुख्य सूचना सुरक्षा अजधकारी' जनयुि दकया िाएगा िो उस धजृ त कंपनी या मूल कंपनी के प्रमखु को ठरपोटव करेगा और एक 'िैकजल्पक मख्ु य सूचना सुरक्षा अजधकारी' भी जनयुि दकया िाएगा;
(5) यह सुजनजित करेगी दक एक कमवचारी को कम से कम तीन िषव की अिजध के जलए मख्ु य सूचना सुरक्षा अजधकारी के रूप म ेंजनयुि दकया िाए;
(6) यह सुजनजित करेगी दक मुख्य सूचना सुरक्षा अजधकारी की भूजमका केिल साइबर सुरक्षा से संबंजधत मामलों के कायों तक ही सीजमत हो;
(7) मुख्य सूचना सुरक्षा अजधकारी और िैकजल्पक मुख्य सूचना सुरक्षा अजधकारी के संपकव जििरण सािविजनक डोमेन म ें उपलब्ध कराएगी और उन्द्ह ेंअद्यजतत करेगी और ऐसी िानकारी कंटयूटर सुरक्षा घटना मोचन िल– जिद्युत के साथ-साथ सभी आंतठरक और बाह्य पणधारकों को भी िेगी;
(8) यह सुजनजित करेगी दक मुख्य सूचना सुरक्षा अजधकारी प्रत्यके जििीय िषव में कम से कम पांच काय-व दििसों के जलए साइबर सरु क्षा प्रजिक्षण पाठ्यिम म ेंभाग ल;े
(9) भारत म,ें सभी साइबर सुरक्षा से िडु े मामलों से जनपटन े के जलए, मुख्य सूचना सुरक्षा अजधकारी की अध्यक्षता में एक समर्पवत सूचना सुरक्षा जिभाग स्ट्थाजपत दकया िाएगा और यह चौबीसों घंटे प्रचालन म ें रहगे ा। इसके अलािा- (क) सूचना सुरक्षा जिभाग म ेंपयावप्त कमिचारी तैनात ककय े जायेंग;े (ख) सूचना सुरक्षा जिभाग में तनै ात कमिचारी के पास कायवक्षेत्र जिजिष्ट साइबर सुरक्षा पाठ्यिम सफलतापूिवक पूरा करन े का िधै प्रमाणपत्र होगा;
(ग) सूचना सुरक्षा जिभाग में तैनात कमिचारी को प्रत्येक जििीय िषव में कम से कम पांच कायवदििस के जलए जिद्युत क्षेत्र से िुड ेसाइबर सरु क्षा प्रजिक्षण पाठ्यिम में िाजमल होना होगा; (घ) कमिचारी को सूचना सुरक्षा जिभाग में कम से कम तीन िष व के कायवकाल के जलए तैनात दकया िाएगा;
(10) में एक तय और प्रलेजखत साइबर सुरक्षा नीजत हो, जिसे, यथाजस्ट्थजत, संस्ट्था के प्रमुख या बोड व द्वारा हर िषव अनुमोदित और समीक्षा दकया िाए;
(11) कंटयूटर सुरक्षा घटना मोचन िल–जिद्युत के साथ परामि व करके एक साइबर संकट प्रबंधन योिना तैयार करें, तादक सभी संभाजित साइबर संकट की जस्ट्थजतयों से कम से कम समय में और व्यापार प्रचालनों पर कम से कम प्रभाि के साथ जनपटा िा सके और उनसे सरु जक्षत हो सके;
परंतु साइबर संकट प्रबंधन योिना को भारतीय कंटयूटर आपातकालीन मोचन िल द्वारा जिधीक्षा दकया िाएगा और, यथाजस्ट्थजत, संस्ट्था के प्रमुख या बोडव द्वारा इसे मंजूरी िी िाएगी और प्रत्येक िषव इसकी समीक्षा की िाएगी;8 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4]
(12) महत्िपूणव सूचना अिसंरचना िाले सूचना प्रौद्योजगकी नेटिकव को इंटरनेट के साथ-साथ बाकी सूचना प्रौद्योजगकी नेटिकव से पृथक रखना सुजनजित करे; परंत ु अगर महत्िपूण व सूचना अिसंरचना िाल े सूचना प्रौद्योजगकी नेटिकव के जलए इंटरनेट अपेजक्षत हो, तो उस े केंरीय सरकार की नाजमत अजभकरणों द्वारा बताए गए उजचत िढृ ीकरण उपायों के साथ सुरजक्षत रूप से सोसव दकया िाएगा;
(13) यह सुजनजित करे दक इलेक्रॉजनक सुरक्षा प्राचल पर फायरिॉल सजहत सभी अपेजक्षत सुरक्षा उपकरण लगाए िाएं, तादक लगाया गया सुरक्षा प्रणाली पैकेट दफल्टटरंग; डीप पैकेट िांच; सामग्री, उपयोगकताव और एजटलकेिन आधाठरत दफल्टटरंग; एजन्द्िटटेड रैदफक का पता लगान े और िांच; घुसपैि का पता लगान े और रोकथाम; जियो-फेंबसंग; स्ट्ितः हस्ट्ताक्षर और व्यिहार अद्यतन की सुजिधा; उपयोगकताव जनयजं त्रत अद्यतन;
हस्ट्ताक्षर और व्यिहार में गडबडी के आधार पर पता लगाने, िांच और दफल्टटरंग िैसी अपक्षे ाओं को पूरा करे;
(14) यह सुजनजित करे दक कोई भी िेब सर्िवस या िेब-आधाठरत एजटलकेिन, जिसमें िेबसाइट, िेब पोटवल और एजटलकेिन प्रोग्राबमंग इंटरफेस िाजमल ह,ैं जिनकी सािविजनक पहुचँ ह,ै उन्द्ह ें साइबर सुरक्षा संपरीक्षा मंजूरी के बाि ही पठरजनयोजित दकया िाएगा;
परंत ु िेब एटलीकेिन और िेब सेिाओं म ें कोई भी सॉफ्टिेयर अद्यतन, जिसमें पैच भी िाजमल ह,ै सफल परीक्षण और पुजष्ट के बाि ही पठरजनयोजित दकया िाएगा, तादक िह अद्यतन दकसी भी साइबर सुरक्षा भेद्यता स े मुि हो, और यह पुजष्ट की िाएगी दक ऐसा अद्यतन दकसी भी साइबर िोजिम स े मुि ह;ै परंत ु यह और दक साइबर सरु क्षा नीजत म ें बताए गए साइबर सरु क्षा संपरीक्षा की जपछली अपेक्षा को पूरा करने िाला कोई भी सॉफ्टिेयर अद्यतन, उसके साइबर सुरक्षा संपरीक्षा मजं ूरी के बाि ही पठरजनयोजित दकया िाएगा:
परंतु यह और भी दक इसके अलािा सभी सॉफ्टिेयर अद्यतन, जिनके जलए पहल े साइबर सुरक्षा संपरीक्षा की जरूरत नहीं ह,ै उनका जनधावरण अगल ेसाइबर सुरक्षा संपरीक्षा के िौरान दकया िाएगा;
(15) साइबर सुरक्षा नीजत के अधीन बताई गई प्रदिया के अनुसार पहचाने गए सभी जरूरी िेब एटलीकेिन के जलए सभी अपेजक्षत सुरक्षा उपकरण लगाना सुजनजित करे, तादक लगाया गया सुरक्षा प्रणाली, एटलीकेिन लेयर दफल्टटरंग की अपेक्षाओं को पूरा करे, जिसमें िेब आधाठरत एजन्द्िटटेड रैदफक का पता लगाना और दफल्टर करना; िोनों तरफ स े सुरक्षा सुजनजित करना; स्ट्िचाजलत हस्ट्ताक्षर और व्यिहार अद्यतन की सुजिधा; घुसपैि का पता लगाना और रोकना, उपयोगकताव जनयंजत्रत अद्यतन दियाजिजध; सामग्री, उपयोगकताव और एटलीकेिन आधाठरत दफल्टटरंग; भ-ू फेंबसंग; हस्ट्ताक्षर और व्यिहार िन्द्य गडबजडयों के आधार पर एजन्द्िटटेड रैदफक का पता लगाना, िांच करना और दफल्टर करना िाजमल ह;ैं
(16) साइबर सुरक्षा नीजत में बताई गई प्रदिया के अनुसार, प्रणाली को महत्िपूणव और कम महत्िपूणव प्रणाली के रूप में पहचान े और पृथक करे;
(17) यह सुजनजित करे दक साइबर आजस्ट्तयों तक ठरमोट पहुचँ , यदि आिश्यक हो, तो साइबर सुरक्षा नीजत के अधीन जिजनर्िवष्ट प्रदिया के अनसु ार, केिल समस्ट्या जनिारण और आपातकालीन अपेक्षाओं के जलए ही दिया िाए: परंतु कम महत्िपूणव प्रणाली से िुडे साइबर आजस्ट्तयों के जलए ऐसी पहुचँ , केिल समस्ट्या जनिारण और आपातकालीन अपेक्षाओं के जलए, मख्ु य सूचना सुरक्षा अजधकारी की मंजूरी के साथ और उजचत सुरक्षा जनयंत्रण उपायों के साथ ही दिया िा सकेगा:
परंतु यह और दक महत्िपूण व प्रणाली या उनके साइबर आजस्ट्तयों तक ऐसे पहुचँ के जलए मंजरू ी एक व्यापक िोजखम जनधावरण करन े और उसके प्रभािी उपायों की पहचान करने के बाि ही िी िा सकेगी, और[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 9 ऐसे पहुचँ की जनरंतर जनगरानी की िाएगी तादक दकसी भी गडबडी या अनजधकृत उपयोग के प्रयासों का पता लगाया िा सके:
परंत ु यह और भी दक इसके अलािा िोजखम मूल्यांकन का ठरकॉडव, मंजूरी का भौजतक िस्ट्तािेज और महत्िपूण व प्रणाली तक ऐस े प्रत्येक पहुचँ स े संबंजधत लॉग को डेटा प्रजतधारण नीजत म ें जिजनर्िवष्ट अिजध के जलए बनाए रखा िाएगा;
(18) प्रत्येक छह महीने में कम से कम एक बार साइबर सुरक्षा िागरूकता कायविम और साइबर सुरक्षा अभ्यास आयोजित करे, जिसमें मॉक-जिल और टेबलटॉप अभ्यास िाजमल ह;ैं
(19) यह सुजनजित करे दक संिेिनिील िानकारी और संिेिनिील डेटा, जिसमें क्लाउड पर होस्ट्ट दकया गया ऐसा डेटा और िानकारी, साथ ही ऐसा ऐजतहाजसक डेटा और िानकारी िाजमल है, एक एजन्द्िटटेड, सुरजक्षत, और संरजक्षत माहौल में संग्रजहत दकया िाए और केिल भारत में ही रह;े
(20) साइबर सुरक्षा नीजत के अधीन, यथाजिजनर्िवष्ट, िेंडरों के साथ सेिा स्ट्तरीय अनुबंध म ें सभी साइबर सुरक्षा अपेक्षाओं के साथ-साथ केंरीय सरकार द्वारा िारी लागू साइबर सुरक्षा जनयमों, जिजनयमों और गरै प्रकटीकरण अनुबंध को िाजमल करे, तादक उनके संजििा की अिजध के िौरान और ऐसी संजििा अिजध पूरी होने के बाि भी संिेिनिील िानकारी की गोपनीयता, अखंडता और उपलब्धता सुजनजित की िा सके:
परंतु महत्िपूण व प्रणाली तक साइबर या भौजतक पहुचँ या िोनों रखने िाले िेंडर को, जिसमें ऐस े प्रणाली के संचालन या रखरखाि या िोनों के जलए लगाए गए िेंडर के कमिचारी िाजमल ह,ैं कार्मवक िोजखम जनधावरण करन े और उसके बाि दकए गए जनिारक उपायों के साथ-साथ सेिा स्ट्तरीय अनुबंध का पालन करन े िाले एक िचनपत्र के बाि अनमु जत िी िा सकेगी:
परंतु यह और दक इसके अलािा दकसी भी साइबर सुरक्षा उल्लंघन के मामले म,ें संस्ट्था मामले की िांच करेगी और ऐसे िेंडर, जिसमें क्लाउड सर्िवस प्रिाता भी िाजमल हैं, जिन्द्होंने साइबर सरु क्षा उल्लंघन दकया ह,ै के जिरुद्ध कारविाई आरंभ करेगी;
(21) साइबर सुरक्षा नीजत में यथाजिजनर्िवष्ट, सभी महत्िपूणव प्रणाली का ऑनलाइन और ऑफलाइन बैकअप एक पृथक, सुरजक्षत और संरजक्षत माहौल म ेंसुजनजित करे;
(22) जिजनयम 13 के अधीन यथाजिजनर्िवष्ट सभी महत्िपूणव प्रणाली को िाजमल करते हुए प्रत्येक जििीय िषव में कम से कम एक बार एक व्यापक साइबर सुरक्षा संपरीक्षा की सुजिधा प्रिान करे, लेदकन िो लगातार साइबर सुरक्षा संपरीक्षा के बीच िमिः कम से कम नौ महीने और अजधकतम पंरह महीने का अंतर हो:
परंत ु संस्ट्था द्वारा जनयुि साइबर सुरक्षा संपरीक्षा संस्ट्था अपन ेयोग्य कर्मवयों को तैनात करेगी, लेदकन ऐसी संस्ट्था के जलए तैनात दकसी भी कमिचारी को छोडकर, यदि कोई हो: परंत ु यह और दक इसके अलािा लगातार तीन ऐसे संपरीक्षा एक ही संपरीक्षा संस्ट्था या कर्मवयों द्वारा नहीं दकए िाएगं े;
(23) यह सुजनजित करे दक खरीि े गए सभी सूचना प्रौद्योजगकी उत्पाि केंरीय सरकार द्वारा िारी आिेिों के अनुपालन म ेंहों और इन आििे ों के पालन म ेंउनका परीक्षण दकया गया हो;
(24) सभी महत्िपूणव प्रणाली को िाजमल करत े हुए आईएसओ/आईइसी 27001 प्रमाणपत्र या तकनीकी मानिंड प्रमाणपत्र का अनुपालन सुजनजित करे और प्राप्त करे: परंतु आईएसओ 27001 या तकनीकी मानिंड प्रमाणपत्र के प्रमाणन के जलए जनरंतर चार संपरीक्षा एक ही संपरीक्षा एिसें ी या कर्मवयों द्वारा नहीं दकए िाएंगे;
(25) आजस्ट्त रजिस्ट्टर बनाए रखे- (क) जिसमें साइबर सुरक्षा नीजत म ें पठरभाजषत प्रदिया के अनुसार, सभी साइबर आजस्ट्त के जलए, स्ट्िाजमत्ि, हाडविेयर, फमविेयर, सॉफ्टिेयर और पैच सजहत जरूरी जििरण िाजमल हों;10 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4] (ख) जिसमें सभी महत्िपूणव प्रणाली का जििरण ठरकॉडव करना, उसका जिन्द्यास, हाडविेयर, सॉफ्टिये र, डेटा प्रिाह दिखाने िाला नेटिकव स्ट्थापत्य और उसमें इस्ट्तेमाल होने िाले संचार प्रोटोकाल िाजमल हों:
परंतु ऐस े रजिस्ट्टर की समीक्षा और अद्यतन प्रत्येक जििीय िषव में कम से कम एक बार या दकसी नए साइबर आजस्ट्त या महत्िपणू व प्रणाली के चाल ू होने पर, जिसमें उनके प्रजतस्ट्थापन भी िाजमल ह,ैं िो भी पहले हो, दकया िाएगा;
(26) साइबर आजस्ट्त रजिस्ट्टर म ें बताए गए सभी आजस्ट्तयों के जलए, साइबर सुरक्षा नीजत में बताई गयी प्रदिया के अनुसार साइबर िोजखम जनधावरण और िमन योिना बनाए रखे: परंत ु साइबर िोजखम जनधावरण और िमन योिना को प्रत्येक छह महीने म ें कम स े कम एक बार अद्यतन दकया िाएगा और प्रत्यके जििीय िषव में कम से से एक बार पनु िवलोकन दकया िाएगा और ऐस े साइबर िोजखम आकलन और िमन योिना को उससे िुडी कमिोठरयों, खतरों और िोजखमों को प्रबंजधत करने के जलए दियाजन्द्ित दकया िाएगा;
(27) यह सुजनजित करे दक दकसी भी नए महत्िपूणव प्रणाली को चालू करने से पहले, जिसमें ऐसे प्रणाली को बिलना भी िाजमल ह,ै साइबर सुरक्षा संपरीक्षा, जिसमें भेद्यता आंकलन और प्रिेि िांच िाजमल ह,ै दकया िाए और साइबर सुरक्षा नीजत म ें बताए गए पठरभाजषत अनुसार महत्िपूण व प्रणाली के जलए भेद्यता और िोजखम को प्रबंजधत दकया िाए;
(28) चालू दकए गए सभी नए महत्िपूणव प्रणाली, जिनमें बिले गए प्रणाली भी िाजमल ह,ैं की जरूरी िानकारी, जिसमें प्रणाली जििरण और कायवक्षमता िाजमल ह,ैं महत्िपूण व प्रणाली से िुडे आजस्ट्त रजिस्ट्टर के अनुसार, ऐसे चालू होने या बिलने के तीस दिनों के अंिर कंटयूटर सुरक्षा घटना मोचन िल– जिद्युत को दे;
(29) महत्िपूणव सूचना अिसंरचना की पहचान के जलए राष्ट्रीय महत्िपूणव सूचना अिसंरचना सरं क्षण केंर को सुसंगत िानकारी प्रिान करे। इसके अजतठरि, राष्ट्रीय महत्िपूणव सूचना अिसंरचना संरक्षण केंर द्वारा दकसी आजस्ट्त को महत्िपूणव सूचना अिसंरचना के रूप म ें पहचाने िाने के साि दिनों के भीतर, संस्ट्था ऐसी आजस्ट्त को संरजक्षत प्रणाली के रूप में अजधसूजचत करने के जलए समुजचत सरकार से संपकव करे;
(30) यह सुजनजित करे दक महत्िपूण व सूचना अिसंरचना और सरं जक्षत प्रणाली प्रणाली सािविजनक टलेटफामों पर उपलब्ध न हों, िब तक दक संस्ट्था के प्रमुख या बोड व द्वारा, लाग ू होन े के अनुसार, व्यािसाजयक अपेक्षाओं, महत्ि और प्रणाली के िोजखम मूल्यांकन के आधार पर अनुमोदित न दकया गया हो;
(31) यह सुजनजित करे दक खरीि प्रदिया में फैक्री स्ट्िीकृजत परीक्षण और साइट स्ट्िीकृजत परीक्षण को िाजमल करना अजनिायव हो, जिसमें सायबर सुरक्षा अपेक्षाओं का परीक्षण िाजमल हो;
(32) यह सुजनजित करे दक सूचना प्रौद्योजगकी और पठरचालन तकनीक प्रणाली के भीतर सभी संबंजधत सूचना प्रसंस्ट्करण प्रणाजलयों के क्लॉक, लाग ू होने के अनुसार, साइबर सुरक्षा नीजत में दिए गए संिभ व समय स्रोत के साथ तल्ु यकालन हों:
परंत ु ऐसे संिभव समय स्रोत के चयन से पहले, जिस्ट्तृत साइबर िोजखम जनधावरण दकया िाएगा;
(33) यह सुजनजित करे दक सभी कर्मवयों, जिनम ें वेंडस ि द्वारा सभी महत्िपूण व प्रणाजलयों के िैजनक संचालन और रखरखाि में लगे कमी भी िाजमल ह,ैं न े जिद्युत क्षेत्र से संबंजधत जनर्िवष्ट साइबर सुरक्षा पाठ्यिम अजनिायव रूप से संपन्न दकए हों;
(34) यह सुजनजित करे दक महत्िपणू व प्रणाजलयों की भौजतक सुरक्षा से संबंजधत प्रणाजलयाँ, नेटिकव, और अनुप्रयोग ऐसी महत्िपूण व प्रणाजलयों के नेटिकव से भौजतक रूप से पृथक हों: परंतु यदि ऐसा भौजतक पृथक्करण संभि न हो, तो संस्ट्था के प्रमुख की स्ट्िीकृजत से, संबंजधत प्रणाजलयों, नेटिकव, और अनुप्रयोगों को ऐसी महत्िपूणव प्रणाजलयों के नेटिकव से तार्कवक रूप से पृथक दकया िाएगा;[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 11
(35) साइबर सुरक्षा नीजत म ें यथाजिजनर्िवष्ट, साइबर घटनाओं से उबरने और िल्ि से िल्ि सामान्द्य संचालन दफर से आरंभ करने के जलए घटना मोचन और पुनप्रावजप्त योिना बनाए रख:े परंतु ऐसी योिना की प्रत्येक छह महीने म ें कम से कम एक बार समीक्षा और अद्यतन दकया िाएगा;
(36) खतरों के साथ-साथ भेद्यिाओं की पहचान के जलए सूचना प्रौद्योजगकी प्रणाली और पठरचालन तकनीक प्रणाली, जैसा िागू हो, की जनगरानी और लगातार मॉजनटटरंग करे, और घटना मोचन और समाधान सहायता प्रिान करे;
(37) यह सुजनजित करे दक इलेक्रॉजनक सुरक्षा पठरजध म ें मौिूि सभी सुरक्षा उपकरणों के लॉग सक्षम हों तादक ऐसे उपकरणों से संचाजलत िाल ेडेटा और सूचना के आिान-प्रिान को ठरकॉडव दकया िा सके;
(38) पठरजध सुरक्षा उपकरणों के जनयमों और नीजतयों की जनयजमत, कम से कम प्रत्येक िषव एक बार, समीक्षा और अद्यतन सुजनजित करे;
(39) यह सुजनजित करे दक सूचना प्रौद्योजगकी उपकरण और सेिाएं केन्द्रीय सरकार द्वारा समय-समय पर िारी दकए गए आििे ों, जनिेिों या दििाजनिेिों के अनुसार जिश्वसनीय स्रोतों से खरीिी िाएं;
(40) इन जिजनयमों के अलािा, सचू ना प्रौद्योजगकी अजधजनयम, 2000 (2000 का 21) के अधीन िारी जनिेिों और अपेक्षाओं और उसके अधीन बनाए गए सभी जनयमों और जिजनयमों का पालन करे;
(41) वेंडसि और कंटयूटर सरु क्षा घटना मोचन िल- जिद्युत के साथ संरजचत भेद्यता प्रकटीकरण और प्रबंधन कायविम रखे;
(42) कंटयूटर सुरक्षा घटना मोचन िल- जिद्युत द्वारा जनधावठरत प्रारूप के अनुसार, सभी साइबर सुरक्षा घटनाओं को प्रासंजगक जििरणों के साथ ठरकॉड वकरन े के जलए एक रजिस्ट्टर बनाए रखे। अध्याय 4 पठरचालन तकनीक प्रणाली स ेसबं जं धत सस्ट्ं थाओं के जलए अजतठरि साइबर सरु क्षा अपक्षे ाएं
6. जिजनयमन 5 के अधीन सस्ट्ं था के जलए आिश्यक अजनिायतव ाओं के अलािा, सस्ट्ं था-
(1) यह सुजनजित करे दक पठरचालन तकनीक प्रणाली को इंटरनेट के साथ-साथ सूचना प्रौद्योजगकी प्रणाली से भौजतक रूप से पृथक रखा िाए: परंत ु यदि व्यापार की अपेक्षाओं के कारण सूचना प्रौद्योजगकी प्रणाली स े ऐसा अलगाि संभि नहीं है, तो साइबर सुरक्षा नीजत म ें पठरभाजषत प्रदिया के अनुसार, ऐसे सूचना प्रौद्योजगकी और पठरचालन तकनीक परस्ट्पर संबंध की पठरचालन तकनीक प्रणाली और सूचना प्रौद्योजगकी प्रणाली के बीच उजचत मजबतू तार्कवक पृथक्कीकरण के साथ, ऐसे परस्ट्पर संबंध के िोजखम आकं लन और संस्ट्था के प्रमुख या बोडव की मंजूरी के आधार पर, िैसा भी लागू हो, अनुमजत िी िा सकेगी:
परंत ु यह और दक ऐसे परस्ट्पर संबंध की जनरंतर जनगरानी की िाए तादक अनुजचत गजतजिजधयों का पता लगाया िा सके और उनके जलए सधु ारात्मक उपाय दकए िा सकें: परंतु यह और भी दक इसके अलािा, ऐसी मंजूरी और ऐस े परस्ट्पर संबंध से िडु े लॉग को डेटा प्रजतधारण नीजत म ेंबताई गई अिजध के जलए रखा िाएगा;
(2) यह सुजनजित करे दक जिद्युत प्रणाली के संपकव प्रणाली के साथ पठरचालन तकनीक प्रणाली के परस्ट्पर संबंध के बबंि ु पर उपयिु पठरजध स्ट्तरीय साइबर सुरक्षा उपकरण, जिसमें फायरिॉल िाजमल ह,ै की स्ट्थापना हो, तादक स्ट्थाजपत सुरक्षा प्रणाली, अन्द्य अपेक्षाओं के अलािा, पठरचालन तकनीक से संबंजधत जनयम और रैदफक12 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4] का पता लगाने और दफल्टर करने; सामग्री, उपयोगकताव और एजटलकेिन आधाठरत दफल्टटरंग; डीप पैकेट िांच, घुसपैि का पता लगान;े जियो-फेंबसंग; उपयोगकताव जनयंजत्रत अद्यतन; हस्ट्ताक्षर और व्यिहार संबंधी जिसंगजतयों के आधार पर पता लगान ेऔर उन्द्ह ेंदफल्टर करन ेकी अपेक्षाओं को परू ा करें:
परंत ु ऐस े सुरक्षा प्रणाली का जहस्ट्सा बनन े िाल े उपकरण के जलए हस्ट्ताक्षर सजहत अद्यतन, साइबर सुरक्षा नीजत म ें यथाजिजनर्िवष्ट, ऑफलाइन मोड में दकए िाएगं े;
(3) यह सुजनजित करे दक जिद्युत प्रणाली के तत्िों का जनयंत्रण और प्रचालन और उनकी िानकारी का आिान- प्रिान, जिसमें ठरयल टाइम डेटा िाजमल ह,ै इंटरनेट से पृथक एक समर्पवत संचार चैनल पर होगा िो पठरजध स्ट्तरीय साइबर सुरक्षा उपकरण के माध्यम से होगा और यह केिल राष्ट्रीय सीमाओं तक ही सीजमत रहगे ा:
परंत ु जिन संस्ट्थाओं की कारबार अपेक्षाएं ह ैं या जिनके सीमा पार जिद्युत प्रणाली तत्ि हैं, उनके जलए साइबर सुरक्षा नीजत के अधीन पहचानी गई िानकारी और िास्ट्तजिक समय डेटा का आिान-प्रिान राष्ट्रीय सीमाओं स े परे एक समर्पवत पृथक संचार प्रणाली और एकदििीय गेटि े के माध्यम से भेिने और पान े के जलए, इंटरनेट से पथृ क और साइबर सुरक्षा उपकरणों के साथ, अनुमजत िी िा सकेगी, इस ितव के साथ दक ऐसी िानकारी और डेटा की लगातार जनगरानी की िाए तादक दकसी भी गडबडी या अनजधकृत प्रयास का पता लगाया िा सके:
परंत ु यह और दक अंजतम उपभोिाओं स े संबंजधत िास्ट्तजिक समय िानकारी और डेटा के आिान- प्रिान के मामले म,ें इसे सािविजनक पहुचं से पृथक, सुरजक्षत कनेक्िन के माध्यम से अनुमजत िी िा सकेगी, इस ित व के अधीन दक ऐस े कनेक्िन पर संिेिनिील िानकारी और डेटा का आिान-प्रिान उसकी गोपनीयता, अखडं ता और जनिता सुजनजित करन े के जलए एजन्द्िटटेड होगा;
(4) यह सुजनजित करे दक यदि कारबार अपेक्षाओं के जलए ठरमोट ऑपरेिन आिश्यक है, तो यह संस्ट्था के प्रमुख या बोड व की पूिव मंजरू ी के साथ, िैसा भी लाग ू हो, साइबर सुरक्षा नीजत म ें जिजनर्िवष्ट प्रदिया के अनुसार, इंटरनेट से पृथक एक समर्पवत संचार चनै ल के माध्यम से, जिजनयमन 6(3) के अधीन अजनिाय व साइबर सुरक्षा प्रणाली के साथ भारत के भीतर ही होगा;
(5) यह सुजनजित करे दक जिद्युत प्रणाली के जनयंत्रण और प्रचालन के जलए उपयोग दकए िाने िाले सभी पठरचालन तकनीक उपकरण, अियि और उनके जहस्ट्से केंरीय सरकार द्वारा िारी दकए गए आिेिों का पालन करेंग;े
(6) यह सुजनजित करे दक पठरचालन तकनीक प्रणाली की संचार प्रणाली सूचना प्रौद्योजगकी प्रणाली की संचार प्रणाली से पथृ क हो;
(7) यह सुजनजित करे दक पठरचालन तकनीक उपकरण और सिे ाएँ केंरीय सरकार द्वारा समय-समय पर िारी दकए गए आििे ों, जनिेिों या दििाजनिेिों के अनुसार जिश्वसनीय स्रोतों से उपाप्त की िाए;ँ
(8) यह सुजनजित करे दक पठरचालन तकनीक पयाविरण को महिा, सुरक्षा अपक्षे ाओं और िोजखम मल्ू यांकन के आधार पर पथृ क-पृथक रस्ट्ट स्ट्तर में बाँटा गया हो;
(9) यह सुजनजित करे दक संचार प्रणाली, जििेष रूप स े चैनल, िो िो संस्ट्थाओं के बीच पठरचालन तकनीक डेटा और िानकारी प्रिान करता है, ऐस ेप्रणाली के धारक द्वारा साइबर सुरक्षा खतरों स ेसंरजक्षत हो। अध्याय 5 मख्ु य सचू ना सरु क्षा अजधकारी और सचू ना सरु क्षा जिभाग के कायव
7. (1) मुख्य सूचना सुरक्षा अजधकारी और िैकजल्पक मुख्य सचू ना सुरक्षा अजधकारी भारत के नागठरक और जनिासी होने चाजहए और उनके पास दकसी मान्द्यता प्राप्त संस्ट्थान से इंिीजनयटरंग या समकक्ष जडग्री होनी चाजहए, साथ ही जिद्युत क्षेत्र या सूचना प्रौद्योजगकी के क्षेत्र म ेंकम से कम पंरह िषव का अनुभि होना चाजहए;[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 13 इन जिजनयमनों म ें जनजहत दकसी भी बात के होत े हुए भी, प्राजधकरण पृथक-पृथक आििे ों के माध्यम से संस्ट्था के मुख्य सूचना सुरक्षा अजधकारी के जलए अजतठरि अहतव ाए ंतय कर सकती ह;ै परंतु मख्ु य सूचना सरु क्षा अजधकारी की अनपु जस्ट्थजत में, मख्ु य सूचना सुरक्षा अजधकारी की भूजमकाएं और उिरिाजयत्ि िैकजल्पक मुख्य सूचना सुरक्षा अजधकारी द्वारा जनभाई और परू ी की िाएंगी।
(2) मख्ु य सूचना सुरक्षा अजधकारी- (क) साइबर सुरक्षा से संबंजधत सभी मामलों के जलए नोडल अजधकारी होगा; (ख) साइबर सुरक्षा से संबंजधत मामलों से िडु े सभी संबंजधत पणधारकों के साथ समन्द्िय करेगा;
(3) सचू ना सरु क्षा जिभाग की सहायता स े मख्ु य सचू ना सरु क्षा अजधकारी के कायों म,ें अन्द्य बातों के अलािा, जनम्नजलजखत िाजमल होंग:े (क) साइबर सुरक्षा घटनाओं की ठरपोटव छह घंटे के भीतर कंटयूटर सुरक्षा घटना मोचन िल– जिद्युत और भारतीय कंटयूटर आपातकालीन मोचन िल को िने ा;
परंत ु यदि दकसी घटना को महत्िपूणव प्रणाली म ें साइबर सबोटाि के रूप में जनष्कष व जनकाला िाता ह,ै तो इसकी ठरपोटव चौबीस घटं े के भीतर िी िाएगी; (ख) साइबर सुरक्षा नीजत में आज्ञापक रूप से दकए गए अनुपालनों की जतमाही समीक्षा;
(ग) साइबर सुरक्षा नीजत म ें जिजनर्िवष्ट महत्िपूण व प्रणाली के जलए साइबर सुरक्षा जनयंत्रण उपायों को लाग ू करना, जिससे उनकी साइबर पठरितवनीयता सुिढृ हो सके; (घ) महत्िपूणव सूचना अिसंरचना या संरजक्षत प्रणाली के मामल े में, राष्ट्रीय महत्िपूण व सूचना अिसंरचना संरक्षण केंर के दििाजनिेिों के अनुसार मान्द्य साइबर सुरक्षा जनयंत्रण उपायों को लाग ूकरना;
(ङ) केंरीय सरकार, प्राजधकरण, भारतीय कंटयूटर आपातकालीन मोचन िल और कंटयूटर सरु क्षा घटना मोचन िल– जिद्युत द्वारा िारी साइबर सुरक्षा से संबंजधत जनिेिों, दििाजनिेिों और सलाह पर कारविाई करना; (च) साइबर खतरे की खुदफया िानकारी इकट्ठा करना, उसका जिश्लेषण, खतरे के िेक्टर की पहचान, साइबर सुरक्षा िोजखमों का आकलन और उनके िमन के उपाय करना;
(छ) प्राप्त की गयी साइबर सुरक्षा घटनाओं की जिस्ट्तृत ठरपोटव, की गई कारविाई की ठरपोटव, मूल कारण जिश्लेषण और अन्द्य सुसंगत िानकारी कंटयूटर सुरक्षा घटना मोचन िल–जिद्युत और भारतीय कंटयूटर आपातकालीन मोचन िल के साथ साझा करना;
(ि) डेटा प्रजतधारण नीजत म ें जिजनर्िवष्ट रीजत से, रूप और अिजध के अनुसार सभी साइबर सुरक्षा से संबंजधत डेटा, सूचना और िस्ट्तािेिों को रखना; (झ) इन जिजनयमों की पहली अनुसचू ी में जिजनर्िवष्ट सभी िस्ट्तािेिों का संरक्षण करना;
(ञ) साइबर सुरक्षा नीजत में प्रिान दकए गए पैच के साथ, सभी महत्िपूणव प्रणाली के फमविेयर और सॉफ्टिेयर के अद्यतन को सुजनजित करना; (ट) सभी सूचना और संचार प्रौद्योजगकी प्रणाली के लॉग और साइबर सुरक्षा घटनाओं से सबं ंजधत फोरेंजसक ठरकॉडव को, साइबर सुरक्षा नीजत में बताई गई अिजध के जलए संरजक्षत करना सुजनजित करना;
(ि) कंटयूटर सुरक्षा घटना मोचन िल– जिद्युत को जरूरी िानकारी िेना, जिसम ें आिंठटत दकए गए, उपयोग दकए गए और उपयोग न दकए गए पजब्लक आईपी िाजमल ह;ैं (ड) महत्िपूणव प्रणाली के दिनप्रजतदिन के प्रचालनों की यािजृ छछक िांच यह सुजनजित करने के जलए करना दक ि े साइबर सुरक्षा नीजत के अनुरूप ह ैंऔर सुधारात्मक उपाय करना;
(ढ) अनािश्यक प्रणाली स े िुड े साइबर आजस्ट्तयों तक ठरमोट पहुचँ को आसान बनाने के जलए एक प्रदिया तैयार14 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4] करना, जिससे गडबडी िीक करन े िालों और आपातकालीन अपेक्षाओं को पूरा दकया िा सके, जिसम ें जरूरी सुरक्षा जनयंत्रण और ऐसे पहुचँ के जलए मंजरू ी िने े की प्रदिया िाजमल है;
(ण) साइबर सुरक्षा नीजत म ें बताए अनुसार, पठरचालन तकनीक प्रणाली के सरु जक्षत ठरमोट ऑपरेिन और उसके अद्यतन को आसान बनाने के जलए एक प्रदिया तैयार करना; (त) साइबर सुरक्षा नीजत, साइबर संकट प्रबंधन योिना, डेटा प्रजतधारण नीजत, और बैकअप नीजत के जिकास, कायावन्द्ियन, समीक्षा और अद्यतन को सुजनजित करना;
(थ) साइबर आजस्ट्तयों और महत्िपणू व प्रणाली के साथ-साथ साइबर िोजखम आकलन और िमन योिना के जलए आजस्ट्त रजिस्ट्टर तैयार करना, अद्यतन करना और समीक्षा करना सुजनजित करना; (ि) साइबर सुरक्षा नीजत के अधीन बताए गए अनुसार, सभी सूचना प्रौद्योजगकी प्रणाली और पठरचालन तकनीक प्रणाली को संिभ वसमय स्रोत के साथ तल्ु यकालन करना सुजनजित करना;
अध्याय 6 साइबर सरु क्षा नीजत
8. साइबर सुरक्षा नीजत को सस्ट्ं था के व्यापार जनरंतरता योिना के साथ संरेजखत दकया िाएगा, जिसमें पठरचालन तकनीक और सूचान प्रौद्योजगकी िातािरण, िैसा लागू हो, िाजमल होगा, और इसमें य ेिाजमल हो सकत े ह-ैं
(1) पठरभाजषत प्रयोिन और पठरजध, साथ ही सभी लाग ूसाइबर सुरक्षा अपक्षे ाएं और उनका पालन;
(2) संरजक्षत प्रणाली के जलए, राष्ट्रीय महत्िपूण व सूचना अिसंरचना संरक्षण केंर दििाजनिेिों और जनयंत्रण आिश्यकताओं के साथ संरेखन सुजनजित करन े िाल ेउपबंध;
(3) संबंजधत आंतठरक और बाहरी पणधारकों की पठरभाजषत भूजमकाएँ और उिरिाजयत्ि;
(4) सभी साइबर आजस्ट्तयों का साइबर आजस्ट्त रजिस्ट्टर तैयार करने की पठरभाजषत प्रदिया, जिसमें सभी साइबर आजस्ट्तयों और साइबर िोजखम आकलन और िमन योिना में पहचाने गए उनकी गंभीरता और िोजखम के आधार पर उनका िगीकरण िाजमल है; और ऐसी प्रदिया को सभी साइबर आजस्ट्तयों की जिस्ट्ततृ िश्ृ यता और प्रबंधन के जलए अद्यतन करना;
(5) व्यवसाय लनरंिरिा योजना पर उनके प्रभाव पर लवचार करि े हुए एक पररभालिि मानदंड के आधार पर सभी प्रणालियों की पहचान करने और ऐसी प्रणालियों को महत्वपूणि प्रणालियों के रूप म ें वगीकृि करन े के लिए पररभालिि प्रकिया, साथ ही एक रलजस्टर म ेंऐसी प्रणालियों के लववरण को दज ि करनाैंः परंत ु ऐसी प्रकिया की समीक्षा की जाएगी और प्रत्येक लवत्तीय वि ि म ें कम स े कम एक बार अद्यिन ककया जाएगा;
(6) प्रत्येक साइबर आजस्ट्त और उससे जुड े जोलखम के जिरुद्ध भेद्यताओं और खिरों की पहचान करन े के लिए साइबर जोलखम मूलयांकन और शमन योजना के लिए पररभालिि प्रकिया, ऐसे जोलखमों और उनके कायािन्वयन की महत्वपूणििा के अनुरूप लनयंत्रण और शमन उपायैंः परंत ु ऐसी प्रकिया की समीक्षा की जाएगी और प्रत्येक लवत्तीय वि ि म ें कम स े कम एक बार अद्यिन ककया जाएगा;
(7) महत्िपूणव प्रणाली में कमिोठरयों और िोजखमों को प्रबंजधत करने के जलए पठरभाजषत तत्रं , जिसमें ऐस े प्रणाली म ेंकजमयों और खतरों की समय पर पहचान करना िाजमल है, जिसमें आंतठरक और बाहरी स्रोतों स े संबंजधत िानकारी प्राप्त करना, ऐसी िानकारी का जिश्लेषण, िोजखम मूल्यांकन और उसका प्रबंधन िाजमल ह:ै[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 15 परंत ु ऐसे तंत्र की समीक्षा और उस े हर जििीय िष व में कम से कम एक बार या दकसी भी नए महत्िपूणव प्रणाली के चालू होने पर, जिसमें उसका प्रजतस्ट्थापन भी िाजमल ह,ै िो भी पहले हो, अद्यतन दकया िाएगा;
(8) महत्िपूणव प्रणाली म ें साइबर नकु सान की पहचान करन े और ठरपोटव करन े की प्रदिया, जिसम ें आंतठरक और बाहरी पणधारकों स ेऐसी िानकारी प्राप्त करना िाजमल है;
(9) पठरभाजषत घटना मोचन और पुनप्रावजप्त योिना, जिसम ें सभी प्रकार की घटनाओं की सूची, िोजखम जिश्लेषण, और प्रभाजित प्रणाली की प्रभािी और समय पर बहाली के जलए िोजखम-आधाठरत घटना-जिजिष्ट मोचन योिना का जििरण दिया गया ह:ै परंतु कोई ऐसी घटना जिसके जलए संस्ट्था स्ट्तर कायवनीजतक पुनप्रावजप्त योिना की जरूरत हो, उस े संकट के रूप में िगीकृत दकया िाएगा;
(10) महत्िपूणव प्रणाली के दिनप्रजतदिन के प्रचालनों की यािजृ छछक िाँच के जलए प्रणाली, जिससे िे साइबर सुरक्षा के क्षेत्र में केंर सरकार द्वारा नाजमत कंटयूटर सुरक्षा घटना मोचन िल– जिद्युत और अन्द्य अजभकरणों द्वारा िारी लाग ूनीजतयों, जनयमों और जिजनयमों के अनुरूप हों:
परंतु ऐसी िांच से ऐसे प्रणाली के प्रचालनों और कायवक्षमता और उनकी सुरक्षा में कोई रुकािट न आए;
(11) महत्िपूणव प्रणाली और उनस े िुडे साइबर आजस्ट्तयों, सािविजनक पहुचँ िाल े एजटलकेिन, संिेिनिील िानकारी और संिेिनिील डेटा के जलए पहुचँ जनयंत्रण प्रणाली, प्रमाणीकरण, प्राजधकृत और अकाउंटटंग मानिंडों और उनकी आिश्यकता के जसद्धांतों के आधार पर पहुचँ प्रबंधन द्वारा जनयंजत्रत दकया िाएगा:
परंतु डेटा प्रजतधारण नीजत के अधीन जनर्िष्टव िस्ट्तािेज और ठरकॉर्डसव तक भौजतक और तार्कवक पहुचँ को प्रजतबंजधत करन े के जलए एक जिस्ट्तृत प्रदिया अजभकजथत की िा सकती है;
(12) िेंडर द्वारा तनै ात कर्मवयों स े िडु े िोजखमों की पहचान करने के जलए कार्मवक िोजखम मूल्याकं न प्रदिया, जिनके पास महत्िपूणव प्रणाली और उनसे िडु े आजस्ट्तयों तक अजधकृत साइबर या भौजतक पहुचँ ह ै या िो ऐसे प्रणाली के संचालन या रखरखाि या िोनों के जलए लगे हुए ह,ैं उनकी भूजमकाओं और उिरिाजयत्िों के आधार पर, जिसमें ऐसी भूजमकाओं और उिरिाजयत्िों में बिलाि िाजमल है; और इसके िमन उपाय:
परंत,ु दिनप्रजतदिन के संचालन और रखरखाि में लग े कमवचाठरयों के जलए या जिनके पास आिश्यक प्रणाली और उनसे िुडे आजस्ट्तयों तक अजधकृत साइबर या भौजतक पहुचँ है, उनके रोिगार स े समाजप्त, इस्ट्तीफे और सेिा-जनिजृ ि के बाि, उनके द्वारा जनभाई गई भूजमकाओं और ऐसे सौंपे गए कायों में तैनाती की अिजध के आधार पर कार्मवक िोजखम मूल्यांकन दकया िाएगा;
(13) यह सुजनजित करने के जलए कायव जिजध दक महत्िपूणव प्रणाली के सभी पहुचँ बबंि ुभौजतक रूप से सुरजक्षत ह ैं और लगातार जनगरानी दकए िात े ह ैं और साथ ही इन प्रणाली और उनस े िुड े साइबर आजस्ट्तयों की भौजतक सुरक्षा के जलए ऐसे पहुचँ को प्रजतबंजधत दकया िाता ह:ै परंतु इनमें से दकसी भी प्रणाली या उसके आजस्ट्तयों को भौजतक नुकसान के दकसी भी संभाजित खतरे के मामल े में, ऐस े प्रणाली या आजस्ट्त के जलए दकसी भी व्यजि को दिया गया भौजतक पहुचँ रद्द दकया िा सकता ह;ै
(14) महत्िपूणव प्रणाली और उनसे िडु ी सेिाओं की सटलाई चेन से िुडे साइबर सुरक्षा िोजखमों की पहचान करन े और उनका आकलन करने के जलए साइबर सटलाई चेन िोजखम प्रबंधन प्रदिया, साथ ही उन्द्ह ें कम करने के उपाय;
(15) साइबर आजस्ट्तयों तक ठरमोट पहुचँ के जलए तय प्रदिया, साथ ही उनकी महिा के आधार पर ऐस े पहुचँ के जलए मंजरू ी िेन े के प्राजधकृत का जििरण, जिससे ऐसा पहुचँ सही जनयंत्रण उपायों के माध्यम से सुरजक्षत हो, जिसमें कम से कम समय के जलए कम से कम अजधकार, बहु-कारक प्रमाणीकरण और जियो-16 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4] फेंबसंग िाजमल ह;ैं
(16) कारबार की अपेक्षा को परू ा करने के जलए, पठरचालन तकनीक प्रणाली के ठरमोट प्रचालन के जलए ऐस े ऑपरेिन स ेिुड ेसाइबर िोजखमों के आकलन और उन्द्ह ेंकम करने के उपायों के आधार पर तय प्रदिया: परंत ु ऐसी प्रदिया की व्यापार की अपेक्षाओं को परू ा करन े या दकसी भी जरूरी बिलाि पर, िो भी पहले हो, की हर साल एक बार समीक्षा और अद्यतन दकया िाएगा;
(17) केंरीय सरकार द्वारा िारी लाग ू जनयमों और जिजनयमों के अनुसार जडजिटल डेटा सरु क्षा और गोपनीयता नीजत;
(18) यह सुजनजित करन े के जलए तय बैकअप नीजत दक सभी महत्िपूणव प्रणाली का ऑनलाइन या ऑफलाइन बैकअप डेटा या िोनों, िैसा भी लाग ू हो, अद्यजतत हो, दकन्द्त ु एक महीन े से ज़्यािा पुराना न हो, और डेटा प्रजतधारण नीजत में तय अिजध के जलए एक पथृ क और सुरजक्षत माहौल में रखा िाए:
परंत ु बैकअप नीजत की हर जििीय िषव म ें कम स े कम एक बार समीक्षा और अद्यतन दकया िाएगा और यह सुजनजित दकया िाएगा दक बैकअप डेटा की अखंडता और उसकी बहाली का परीक्षण दकया िाए जिससे िह व्यापार जनरंतरता योिना की अपेक्षाओं को परू ा करे;
(19) तय प्रणाली जिससे संिेिनिील डेटा और उसके बैकअप के स्ट्टोरेि, साथ ही समर्पवत संपकव चैनल या इंटरनेट पर इसके संचरण, को कोडीकृत दकया िाए जिससे इसकी गोपनीयता, अखंडता और उपलब्धता सुजनजित हो सके: परंतु यदि व्यापार की अपेक्षाओं के कारण कुछ संिेिनिील डेटा का कोडीकरण संभि नहीं ह,ै तो उसे जबना कोडीकृत दकए हुए रूप में एक समर्पवत संपकव चनै ल पर अनुमजत िी िा सकती ह;ै
(20) सभी कर्मवयों के क्षमता जिकास के जलए िार्षवक साइबर सुरक्षा प्रजिक्षण कायविम जिनके पास महत्िपूणव प्रणाली और उनसे िडु े आजस्ट्तयों तक अजधकृत साइबर या भौजतक पहुचँ या िोनों ह;ैं
(21) इंटरनेट रैदफक की जनगरानी और उसे प्रजतबंजधत करने के जलए इंटरनेट पहुचँ नीजत जिससे केिल पठरभाजषत और अजधकृत उपयोग सुजनजित हो सके;
(22) पुराने साइबर आजस्ट्तयों के साथ-साथ उन आजस्ट्तयों के जलए चरणबद्ध रीजत से हटान े की योिना िो उपयोगी िीिन के अंत के करीब ह ैंऔर उनका प्रबंधन, साथ ही उनका सुरजक्षत जनपटान;
(23) साइबर सुरक्षा के क्षेत्र म ें अनुसंधान एिं जिकास दियाकलापों को बढािा िेने के जलए उद्योग, अनुसंधान सस्ट्ं थानों, पणधारकों और जिक्षाजििों के साथ सहयोग की योिना: परंतु ऐसे सहयोग के जलए िायरा और आजस्ट्तयों की पहचान जिस्ट्तृत िोजखम मूल्यांकन करन े के बाि की िा सकती ह ैऔर ऐसा सहयोग गैर प्रकटीकरण समझौते पर हस्ट्ताक्षर करने के बाि ही प्रभािी होगा;
(24) महत्िपूणव प्रणाजलयों में सॉफ्टिये र अद्यतन, जिसमें पैच भी िाजमल ह,ैं को िो श्रेजणयों में िगीकृत करने के जलए मानिंड पठरभाजषत करें- (क) एक सॉफ्टिेयर अद्यतन िो इसके पठरजनयोिन से पहले पूिव साइबर सुरक्षा अंकेक्षण की अपक्षे ा को पूरा करता ह,ै और (ख) एक सॉफ्टिेयर अद्यतन जिसके पठरजनयोिन से पहल े पूि व साइबर सुरक्षा अंकेक्षण की अपक्षे ा नहीं होती ह,ै लेदकन अगल ेसाइबर सुरक्षा अंकेक्षण म ेंऐसे मल्ू यांकन की अपक्षे ा होती ह।ै इसके अजतठरि, सॉफ्टिेयर अद्यतन की सुझािात्मक सूची, जिसके जलए पूि व साइबर सुरक्षा अंकेक्षण की अपक्षे ा होती ह,ै िसू री अनुसूची म ेंप्रिान की गई ह:ै परंत ु कंटयूटर सुरक्षा घटना मोचन िल-जिद्युत, प्राजधकरण की मंिूरी स,े इस सूची को समय-समय पर संिोजधत कर सकता ह;ै[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 17
(25) सभी महत्िपूणव प्रणाजलयों म ें लाग ू दकए गए पठरितवनों को अजभजलजखत करन े और यह सुजनजित करने के जलए दक ऐसी प्रणाजलयों और उनस े िुडी साइबर आजस्ट्तयों पर जनयोजित पठरितनव जनयंजत्रत हैं, एक पठरभाजषत पठरितवन प्रबंधन प्रदिया:
परंतु ऐसी प्रदिया यह सुजनजित करेगी दक सॉफ्टिेयर अद्यतन, जिसमें पैच भी िाजमल ह,ैं िो पूिव साइबर सुरक्षा अंकेक्षण की अपेक्षा के जलए अर्हतव हैं, िाजपस लेन े के उपबंध के साथ सस्ट्ं करण जनयंजत्रत होंगे: परंत ु इसके अलािा पठरचालन तकनीक प्रणाली म ें अद्यतन, जिसमें पैच भी िाजमल ह,ैं मलू उपकरण जनमावता द्वारा जडजिटल रूप से हस्ट्ताक्षठरत होंगे और ऐस े अद्यतन को उनके िोजखम मूल्यांकन और अनुकरणीय िातािरण में सफल परीक्षण के बाि, ऑफलाइन मोड में पठरजनयोजित दकया िा सकता ह।ै तथाजप, यदि दकसी पैच के जलए मलू उपकरण जनमावता का जडजिटल हस्ट्ताक्षर उपलब्ध नहीं है, तो ऐसे पैच की िैधता और प्रामाजणकता सत्याजपत की िाएगी;
(26) डेटा प्रजतधारण नीजत में अजनिायव रूप से लॉग और फोरेंजसक ठरकॉडव को एक सुरजक्षत और संरजक्षत िातािरण में सग्रं हीत करने की सुजिधा के जलए एक तंत्र;
(27) सूचना प्रौद्योजगकी और पठरचालन तकनीक पयाविरण की सभी प्रसंस्ट्करण प्रणाजलयों को ऐसे स्रोत के साथ तल्ु यकालन करन े के जलए, उससे िडु े साइबर िोजखमों का आकलन करन े के बाि, संिभ व समय स्रोत का चयन करन े की एक प्रदिया:
परंत ु पठरचालन तकनीक प्रणाली के जलए चयजनत संिभव समय स्रोत, या तो स्ट्थलीय या भारत जिजिष्ट उपग्रह आधाठरत और इंटरनेट से स्ट्ितंत्र होगा;
(28) सूचना प्रौद्योजगकी प्रणाली के साथ-साथ पठरचालन तकनीक प्रणाली के सुरजक्षत ऑपरेिन को सुजनजित करन े के जलए पठरचालन तकनीक प्रणाली को सूचना प्रौद्योजगकी प्रणाली से तार्कवक रूप स े पृथक करने के जलए प्रदिया तय की गई ह:ै परंत ु सूचना प्रौद्योजगकी से पठरचालन तकनीक और पठरचालन तकनीक से सूचना प्रौद्योजगकी तक पहचाना गया डेटा और िानकारी पथृ क संपकव चैनल और एकदििीय प्रिाह गेटिे के माध्यम से प्रिाजहत होगी;
(29) सीमा पार संस्ट्थाओं द्वारा िोजखम मूल्यांकन और व्यािसाजयक अपेक्षाओं के आधार पर, राष्ट्रीय सीमाओं से परे संचाठरत करने की अनुमजत िाल े डेटा और िानकारी, जिसमें रीयल टाइम डटे ा िाजमल ह,ै को पहचानने और िगीकृत करने के जलए प्रदिया तय की गई ह:ै परंतु कंटयूटर सरु क्षा घटना मोचन िल-जिद्युत अपेक्षानुसार ऐसी प्रदिया, डेटा और सबं ंजधत िानकारी की समीक्षा और मल्ू यांकन कर सकता ह;ै
(30) िेब एटलीकेिन की पहचान करने के जलए तय प्रदिया, साथ ही व्यापार प्रचालन और जनरंतरता पर उनके असर के आधार पर ऐस े एटलीकेिन को आिश्यक िेब एटलीकेिन के तौर पर िगीकृत करने का मानिंड;
(31) सर्िवस से बाहर या पुरानी साइबर आजस्ट्त और उनमें भंडाठरत डेटा को सुरजक्षत रीजत से जनपटान करन े के जलए तय प्रदिया;
(32) संिेिनिील डेटा और संिेिनिील िानकारी को सुरजक्षत रीजत से जनपटान करने के जलए तय प्रदिया;
(33) डेटा प्रजतधारण नीजत जिसमें पथृ क-पथृ क िस्ट्तािेज और ठरकॉडव के साथ-साथ डेटा और िानकारी को रखने दक रीजत और प्रकार बताया गया ह,ै जिसमें िाजमल ह-ैं (क) महत्िपूणव प्रणाली के डेटा का बैकअप; (ख) महत्िपूणव प्रणाली तक ठरमोट पहुचँ की हर अनुमजत के जलए लॉग, िोजखम आंकलन और उसकी18 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4] मंजूरी का ठरकॉड;व (ग) पठरचालन तकनीक प्रणाली को सूचना प्रौद्योजगकी प्रणाली से िोडने से िडु े लॉग और मंजूरी;
(घ) साइबर सुरक्षा िस्ट्तािेज, जिसमें साइबर सरु क्षा परीक्षण के प्रमाणपत्र, फैक्टरी स्ट्िीकृजत परीक्षण और साइट स्ट्िीकृजत परीक्षण के पठरणाम, साइबर सुरक्षा अंकेक्षण ठरपोटव और केंरीय सरकार द्वारा जरूरी अन्द्य िस्ट्तािेज िाजमल ह;ैं (ङ) महत्िपूणव प्रणाली म ें दियाजन्द्ित दकए गए बिलािों का ठरकॉडव, जिसमें सॉफ़्टिेयर अद्यतन और पैच िाजमल ह:ैं परंत ु डेटा प्रजतधारण नीजत की हर जिि िषव म ें कम से कम एक बार समीक्षा और अद्यतन दकया िाएगा और डेटा, िानकारी और िस्ट्तािेज को यह सुजनजित करने के जलए रखा िाएगा दक- (क) कम से कम जपछल ेिो कायव संबधं ी डेटा बैकअप उपलब्ध हों;
(ख) महत्िपूणव प्रणाली तक हर ठरमोट पहुचँ के संबंध में िोजखम आंकलन, मंजरू ी िेन े का भौजतक ठरकॉडव और लॉग कम स ेकम एक िषव के जलए उपलब्ध हों; (ग) फैक्टरी स्ट्िीकृजत परीक्षण और साइट स्ट्िीकृजत परीक्षण की ठरपोटव, जिसमे सायबर सुरक्षा अपेक्षाओं का परीक्षण िाजमल हो, साइबर आजस्ट्त के परू े िीिनकाल के िौरान उपलब्ध हों;
(घ) पठरचालन तकनीक िातािरण म ें ठरमोट ऑपरेिन के जलए िोजखम आंकलन का ठरकॉड व और उसके जलए जमली मंजूरी कम से कम एक िष व के जलए उपलब्ध हों; (ङ) जपछल ेतीन िषों की साइबर सरु क्षा अंकेक्षण ठरपोटव उपलब्ध हों; (च) जपछल ेचार िषों की प्रमाणीकरण अंकेक्षण ठरपोटव उपलब्ध हों;
(छ) जपछल ेतीन िषों की स्ट्िय-ं अंकेक्षण ठरपोटें उपलब्ध हों; (ि) सभी सूचना और संचार प्रौद्योजगकी प्रणाजलयों के लॉग, पठरचालन तकनीक प्रणाली का सूचना प्रौद्योजगकी प्रणाली, के साथ परस्ट्पर संबंध और फोरेंजसक ठरकॉडव 180 दिनों की अिजध के जलए उपलब्ध हों;
(झ) दकसी घटना से िुड े लॉग, जिसमें ऐसी घटना से एक सौ अस्ट्सी दिन पहल े और बाि के लॉग िाजमल ह,ैं ऐसी घटना होने के कम से कम तीन सौ पैंसि दिनों तक उपलब्ध रहगें े: परंत ु ऐसी िानकारी, डेटा और िस्ट्तािेजों तक पहुचं केिल अजधकृत व्यजियों तक ही सीजमत हो सकती ह,ै िो पहुचँ कंरोल दियाजिजध के अधीन पठरभाजषत प्रदिया पर आधाठरत होगा:
परंतु यह और दक प्राजधकरण, पथृ क-पथृ क आिेिों के माध्यम से, दकसी अन्द्य िस्ट्तािेज को िाजमल कर सकता ह ै और डेटा प्रजतधारण नीजत के अधीन िस्ट्तािेजों को बनाए रखने के जलए कोई अन्द्य रीजत, माध्यम और अिजध जनर्िष्टव कर सकता ह।ै अध्याय 7 साइबर सकं ट प्रबधं न योिना
9. साइबर सकं ट प्रबधं न योिना म-ें
(1) सभी घटनाओं का पता लगान े और पहचान करन े के जलए जिस्ट्तृत मानक संचालन प्रदिया, दकसी घटना को संकट के रूप में िगीकृत करन े के मानिडं और सभी संभाजित संकट पठरिश्ृ यों की सूची िाजमल करें;
(2) सभी संभाजित संकटों के जलए पणधारकों की पहचान उनकी भूजमकाओं और उिरिाजयत्िों के साथ[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 19 करें तथा ऐसी भूजमकाओं के साथ-साथ उनकी उिरिाजयत्िों का संचार करें;
(3) संकट के िौरान करीबी तालमले के जलए आंतठरक और बाहरी पणधारकों के साथ बातचीत की रीजत और माध्यम िाजमल करें;
(4) प्रभाि को कम करन ेऔर िल्ि से िल्ि संकट से उबरन े के जलए जनिारक उपाय िाजमल करें।
10. सस्ट्ं थाओं की उिरिाजयत्ि- संस्ट्था -
(1) साइबर संकट के िौरान संबंजधत आंतठरक और बाहरी पणधारकों के साथ सभी आिश्यक संचार की उपलब्धता सुजनजित करे;
(2) साइबर संकट प्रबंधन योिना की प्रभाििीलता को प्रत्येक िषव कम से कम एक बार, उस िषव के जलए चयजनत पठरिश्ृ यों के जलए अभ्यास और मॉक जिल के माध्यम से परीक्षणकरें, िो इसमें बताए गए सभी पहचाने गए संकट पठरिश्ृ यों म ेंसे चुने गए हों:
परंत ु दकसी भी िष व म ें पठरिश्ृ यों का चयन पहल े से परीक्षण और सत्याजपत दकए गए पठरिश्ृ यों के साथ अजधव्याजपत नहीं होगा, िब तक दक सभी सूचीबद्ध पठरिश्ृ यों का परीक्षण और सत्याजपत का चि पूरा न हो िाए;
(3) हर िास्ट्तजिक संकट से जनपटन े और उससे उबरन े की एक जिस्ट्तृत ठरपोटव तैयार करें , साथ ही जमल े अनुभि, सीखे गए सबक, जमली प्रजतदिया, िेखी गई कजमयां और उनके जलए सुझाए गए उपायों के बारे में भी बताए: परंतु सुसंगत िानकारी, जिसमें िास्ट्तजिक संकट, उसके प्रबंधन और मख्ु य जनष्कषव के बारे म ें संजक्षप्त िानकारी िाजमल ह,ै को जिद्युत क्षेत्र के साइबर सुरक्षा पाठरजस्ट्थजतकी तंत्र के सामूजहक सुधार के जलए कंटयूटर सुरक्षा घटना मोचन िल-जिद्युत और अन्द्य पणधारकों के साथ साझा दकया िाएगा:
परंत ु यह और दक साइबर सुरक्षा की जस्ट्थजत को बेहतर बनाने के जलए, साइबर संकट प्रबंधन योिना को अपन ेऔर अन्द्य पणधारकों के महत्िपूण व सुझािों को िाजमल करके अद्यतन दकया िाएगा। अध्याय 8 वडे र के जलए साइबर सरु क्षा अपक्षे ाएँ
11. िडें र के जलए साइबर सरु क्षा अपक्षे ाएँ- वेंडर -
(1) संस्ट्था को िस्ट्तािेिीकृत और टेस्ट्टेड प्रदिया के साथ-साथ पनु प्रािलि योजना भी प्रिान करें, जिससे उनके द्वारा सटलाई दकए गए प्रणाली को संभाजित साइबर संकट की जस्ट्थजतयों से बहाल दकया िा सके;
(2) यह सुजनजित करे दक सभी प्रणाली और उनके घटकों के जलए जडजिटल रूप से साइन दकए गए या मान्द्य और प्रमाजणत दकए गए सरु क्षा पैच और अद्यतन, अनुबंध की अिजध या ऐसे प्रणाली की उपयोगी लाइफ, िो भी बाि में हो, उस िौरान संस्ट्था को उपलब्ध हों;
(3) उस संस्ट्था को एक जिस्ट्तृत िस्ट्तािेज प्रिान करे, जिसमें सभी अपेक्षाएं और प्रदिया िाजमल हों, जिसमें सुरक्षा पैच और थडव-पाटी घटकों पर इंस्ट्टॉल दकए िान े िाल े अद्यतन भी िाजमल हों, जिससे उनके द्वारा सटलाई दकए गए घटकों या सब-प्रणाली को इंटीग्रेट दकया िा सके;
(4) संस्ट्था को उनके द्वारा आपूर्तव दकए गए सॉफ़्टिेयर, हाडविेयर, और प्रणाली के समथनव की समाजप्त या िीिन की समाजप्त का जििरण प्रिान करे, िैसा भी लाग ू हो, जिसमें तृतीय पक्ष स े प्राप्त दकए गए उत्पाि भी िाजमल ह;ैं
(5) भारतीय कंटयूटर आपात मोचन िल द्वारा समय-समय पर िारी दििाजनिेिों के अनुसार, संस्ट्था को 'सामानों का जबल' उपलब्ध कराए, जिसमें महत्िपूण व प्रणाली म ें प्रयिु होन े िाल े सभी घटक, फमविेयर20 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4] सजहत की जिस्ट्तृत सूची िाजमल होगी;
(6) यह सुजनजित करे दक संस्ट्था को सटलाई करन े स े पहले, हाडविये र और सॉफ्टिेयर को सभी अंतर्नवजहत सुरक्षा क्षमताओं, सुरजक्षत कॉजन्द्फगरेिन, और जनयंत्रण को चालू करके मजबूत बनाया गया ह;ै
(7) संस्ट्थाओं के जलए उत्पाि और सेिा में कजमयों की ठरपोटव करने के जलए एक औपचाठरक संरजचत प्रदिया बनाए । इसके अजतठरि, वडें र अपनी िोषपणू व प्रकटन और प्रबंध कायविम के माध्यम से ऐसी कजमयों की िानकारी कंटयूटर सुरक्षा घटना मोचन िल-जिद्युत को िेगा।
12. िडें स वका उिरिाजयत्ि -प्रोज्यूमर के जितठरत उत्पािन संसाधन के मामले म,ें वडें र –
(1) यह सुजनजित करे दक कोई भी आिेिन, संबंजधत जनगरानी और जनयंत्रण सिवर और ऐसे प्रणाली का िास्ट्तजिक समय का डेटा, जिसमें क्लाउड टलेटफॉमव पर होस्ट्ट दकया गया कोई भी डेटा या सूचना और साथ ही संबंजधत ऐजतहाजसक डेटा या सूचना िाजमल ह,ै एक एजन्द्िटटेड, सरु जक्षत और संरजक्षत िातािरण म ें संग्रहीत दकया िाए और केिल भारत में ही रह;े
(2) यह सुजनजित करे दक जग्रड से िुडे जडिाइस का ठरमोट एक्सेस और ठरमोट ऑपरेिन, साथ ही ठरमोट एटलीकेिन, एग्रीगेटर और जितरण लाइसेंसधारी के साथ उनके ठरयल टाइम डेटा और िानकारी का आिान-प्रिान, आपसी प्रमाणीकरण के बाि, सुरजक्षत चैनल के माध्यम से दकया िाएगा और ऐसा संचार कोडीकृत होगा;
(3) केंरीय सरकार द्वारा समय-समय पर िारी दकए गए आिेिों, जनिेिों या दििाजनिेिों के अनुसार, दकसी जिश्वसनीय स्रोत के सत्यापन के जलए आिश्यक सूचना उपलब्ध कराए: परंत ु प्रोज्यूमरों के जिद्यमान जितठरत उत्पािन संसाधन के जलए यह जिजनयमन उस जतजथ को लाग ू होगा, जिसे प्राजधकरण द्वारा पथृ क आिेि के माध्यम से जनर्िवष्ट दकया िाएगा। अध्याय 9 साइबर सरु क्षा अकं ेक्षण
13. साइबर सरु क्षा अकं ेक्षण - संस्ट्था यह सुजनजित करेगी दक-
(1) साइबर सुरक्षा ऑजडट, साइबर सुरक्षा अंकेक्षणदििा-जनिेिों और कंटयूटर सुरक्षा घटना मोचन िल- जिद्युत और केंरीय सरकार द्वारा नाजमत अन्द्य साइबर सुरक्षा अजभकरणों द्वारा िारी जनिेिों म ें दिए गए जिस्ट्ततृ िायरे के अनुसार आयोजित दकया िाएगा;
(2) साइबर सुरक्षा अंकेक्षण के िायरे में जपछले साइबर सुरक्षा अंकेक्षणमें पहचान े गए सभी अंकेक्षणजनष्कषों के समापन का सत्यापन भी िाजमल होगा;
(3) अंकेक्षक अपनी साइबर सुरक्षा अंकेक्षणठरपोटव इसके िुरू होन े के छह सप्ताह के भीतर प्रस्ट्तुत करेगा, और सभी महत्िपूण व और उच्च िोजखम िाली कजमयों को एक महीने की अिजध के भीतर और मध्यम और साथ ही कम िोजखम िाली कजमयों को अंकेक्षक द्वारा साइबर सुरक्षा अंकेक्षणठरपोटव प्रस्ट्तुत करन े की तारीख से तीन महीने की अिजध के भीतर संबोजधत दकया िाएगा:
परंतु गंभीर और उच्च िोजखम िाली कमिोठरयों को जनयंजत्रत करने के जलए उजचत प्रजतपूरक जनयंत्रण लागू दकए िाएंगे, िब तक दक ऐसी कजमयों की अंकेक्षणमंिूरी न हो िाए।
14. मख्ु य सचू ना सरु क्षा अजधकारी का उिरिाजयत्ि –
(1) मुख्य सूचना सुरक्षा अजधकारी अंकेक्षणअनपु ालन की समीक्षा करेगा और यह सुजनजित करेगा दक अंकेक्षक साइबर सुरक्षा अंकेक्षणिुरू होने से छह महीन े के भीतर अपनी साइबर सुरक्षा अंकेक्षणसमापन ठरपोटव प्रस्ट्ततु करे।[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 21
(2) मुख्य सूचना सुरक्षा अजधकारी, साइबर सुरक्षा अंकेक्षणकी समापन ठरपोटव म ें पाई गई अहम अंकेक्षण िानकाठरयों, जिनमें महत्िपूणव और उच्च िोजखम िाली कजमयां िाजमल ह ैं और महत्िपूणव प्रणाजलयों से िुडे जनयमों का पालन न करन े के मामलों की िानकारी, संस्ट्था के प्रमुख या बोड व को, िैसा भी सन्द्िभ व हो, िगे ा:
परंतु जिद्युत मंत्रालय के मख्ु य सूचना सुरक्षा अजधकारी दकसी भी समय िांच के जलए दकसी भी संस्ट्था की अंकेक्षणसमापन ठरपोटव मागं सकता ह ै और यदि आिश्यक हो, तो जलजखत स्ट्पष्टीकरण मांगन े के बाि, प्राजधकरण की पूि व स्ट्िीकृजत और ऐसी संस्ट्था को पूि व सूचना के साथ, अंकेक्षणअनुपालन के सत्यापन के जलए तृतीय पक्ष के अंकेक्षक को जनयुि कर सकता है, जिसकी लागत संस्ट्था द्वारा िहन की िाएगी:
परंत ु यह और दक यदि ततृ ीय पक्ष अंकेक्षण के पठरणाम साइबर सुरक्षा अंकेक्षणसमापन ठरपोटव की ठटटपजणयों से जभन्न हों, तो जिद्युत मंत्रालय के मख्ु य सूचना सुरक्षा अजधकारी आग े आिश्यक कारविाई कर सकता ह।ै अध्याय 10 प्रकीण व
15. स्ट्ि-अकं ेक्षण- इकाई हर जििीय िषव में इन जनयमों के पालन का आकलन करने के जलए स्ट्ि-अंकेक्षण करेगी: परंत ु साइबर सुरक्षा और इन जनयमों का अनुपालन सुजनजित करने के जलए, इकाई बोडव या वररष्ठ प्रबंधन के दकसी सिस्ट्य को, जसै ा भी सन्दभ ि हो, इस अनुपालन के जलए उिरिायी अजभजहत कर सकती ह:ै परंतु यह और दक संस्ट्था समयबद्ध तरीके से गैर-अनुपालन को िीक करेगी और यह सुजनजित करेगी दक अगले जििीय िषव म ेंहोने िाले स्ट्ि-अंकेक्षणसे पहले ऐसे सभी गैर-अनपु ालन को िीक कर जलया िाए:
परंत ु यह और भी दक जिद्युत मत्रं ालय के मख्ु य सूचना सुरक्षा अजधकारी, उपलब्ध तथ्यों या दकसी व्यजि द्वारा िी गई िानकारी के आधार पर, दकसी भी संस्ट्था की अनुपालन ठरपोटव की िांच कर सकते ह।ैं जलजखत स्ट्पष्टीकरण मांगने के बाि, और प्राजधकरण की पूि व मजं ूरी तथा संबंजधत संस्ट्था को पिू व सूचना िेन े के बाि, िे संस्ट्था के िािे की पुजष्ट के जलए दकसी तीसरे पक्ष के अकं ेक्षक को जनयुि कर सकते हैं; इस प्रदिया की लागत संबंजधत संस्ट्था द्वारा िहन की िाएगी।
16. कुछ जिजनर्िवष्ट मामलों में, जलजखत स्ट्पष्टीकरण मांगने और उसकी िांच करने के बाि, जिद्युत मंत्रालय के मुख्य सूचना सुरक्षा अजधकारी, केंरीय सरकार को 'सूचना प्रौद्योजगकी अजधजनयम, 2000 (2000 का 21)' के संबंजधत उपबंधों के अधीन उजचत कायविाही िुरू करने की जसफाठरि कर सकते हैं, या अजधजनयम की धारा 142 के अधीन कायविाही के जलए उजचत आयोग के समक्ष याजचका िायर कर सकते ह।ैं
17. जिजथल करन े की िजि- प्राजधकरण एक आििे के माध्यम से, जलजखत रूप में ििव दकए िाने िाले कारणों के जलए, इन जिजनयमों के दकसी भी उपबंध में अपने स्ट्ियं के प्रस्ट्ताि पर या दकसी इछछुक व्यजि द्वारा उसके समक्ष दकए गए आिेिन पर जिजथलता प्रिान कर सकता ह ै इनम ें स े दकसी भी जिजनयम के संचालन स े उत्पन्न होने िाली कठिनाई को िरू दकया िा सके, िो व्यजियों के एक िगव पर लागू होती ह।ै पहली अनसु चू ी [जिजनयम 7 का खडं 3 (झ) िेख]ें जनम्नजलजखत िस्ट्तािजे और िानकारी सरु जक्षत रखी िाएगी-
1. साइबर सुरक्षा नीजत और उसम ेंदिए गए िस्ट्तािेज और प्रदिया।
2. साइबर संकट प्रबंधन योिना।22 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4]
3. डेटा प्रजतधारण नीजत और उसमें दिए गए सभी िस्ट्तािेज और िानकारी।
4. आईएसओ/आईईसी 27001 प्रमाणपत्र या तकनीकी मानिंड प्रमाणपत्र।
5. साइबर आजस्ट्तयों और महत्िपणू व प्रणाजलयों के जलए आजस्ट्त रजिस्ट्टर।
6. साइबर िोजखम आकलन और िमन योिना।
7. घटना मोचन और पनु प्रावजप्त योिना।
8. साइबर सुरक्षा घटना ठरपोर्टंग रजिस्ट्टर।
9. सामानों का जबल।
10. व्यिसाय जनरंतरता योिना।
11. िरू स्ट्थ प्रचालन प्रदिया।
12. ठरमोट एक्सेस प्रदिया। िसू री अनसु चू ी [जिजनयम 8 का खडं 24 िेख]ें सॉफ़्टिये र अद्यतन के जलए सझु ाए गए मानिडं जिनके जलए पहल ेसाइबर सरु क्षा अकं ेक्षणकी अपक्षे ा होती है एजटलकेिन, िेबसाइट, िेब पोटवल और संबंजधत प्रणाजलयों में सिं ोधन और संिद्धनव सजहत सॉफ़्टिेयर अद्यतन के जलए जनम्नजलजखत मानिडं ों में से दकसी एक को पूरा करने से पहले अजनिायव रूप स े एक सफल साइबर सुरक्षा अंकेक्षणकी अपेक्षा होगी:-
1. महत्िपणू वप्रणाली प्रभाि: ऐसे अद्यतन िो मुख्य पठरचालन प्रदियाओं को प्रभाजित करते हैं, िैसे ऊिा व उत्पािन, संचरण, जितरण या लोड प्रबंधन, जिसमें कजमयां महत्िपूणव बुजनयािी ढांचे की कायवक्षमता या जिश्वसनीयता से समझौता कर सकती ह।ैं
2. पहुचँ जनयत्रं ण सिं ोधन: ऐसे अद्यतन िो उपयोगकताव प्रमाणीकरण, प्राजधकरण तंत्र, या प्रिासजनक जििेषाजधकार को बिलत े ह,ैं जिसमें पहचान प्रबंधन प्रणाली या पहुचँ जनयंत्रण नीजतयां िाजमल ह।ैं
3. ततृ ीय पक्ष प्रणाली के साथ एकीकरण: बाहरी प्रणाली, एजटलकेिन या तृतीय पक्ष सर्िवस के साथ एकीकरण स े िुड े अद्यतन, खासकर िे िो संिेिनिील डेटा का आिान-प्रिान करत े ह ैं या िॉस- टलेटफॉमव संचार को सक्षम बनाते ह।ैं
4. सरु क्षा प्रोटोकॉल म ें बिलाि: एजन्द्िटिन मानक, डेटा रांसजमिन प्रोटोकॉल, या िसू रे सुरक्षा-संबंधी कॉजन्द्फगरेिन म ें बिलाि लान े िाल े अद्यतन, िो संिेिनिील िानकारी की सुरक्षा पर प्रभाि डाल सकते ह।ैं
5. नए फीचस व या इंटरफेस का पठरचय: ऐस े अपडेट्स िो जरूरी नए फंक्िन, यूजर इंटरफेस, या एपीआई िोडते ह,ैं जिनस ेसंभाजित अटैक सरफेस जमल सकत ेह।ैं
6. सरु क्षा कजमयों का समाधान: पहले से पहचानी गई गंभीर और उच्च प्रभाि िाली कजमयों को िीक करने िाल ेअद्यतन, िहाँ अधूरा या अनुजचत कायावन्द्ियन सरु क्षा िोजखमों को और बढा सकता ह।ै
7. घटना मोचन और जनगरानी प्रणाली: साइबर सुरक्षा जनगरानी, घटना मोचन, या लॉग मनै ेिमेंट से िुडे प्रणाली या टूल्स को प्रभाजित करन े िाल े अद्यतन, जिसमें कोई भी रुकािट खतरों का पता लगान े या उन पर असरिार रीजत से मोचन करन े की क्षमता में रुकािट डाल सकती ह।ै
8. सधु ार या जिजनयामक अजनिाय व प्रणाजलया:ँ जिजनयमों के अधीन या समुजचत सरकार के सुधार[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 23 कायविमों के अनुसार प्रणाजलयों को प्रभाजित करन े िाल ेअद्यतन। श्रिण कुमार, सजचि [जिज्ञापन-III/4/असा./253/2026-27] CENTRAL ELECTRICITY AUTHORITY
NOTIFICATION New Delhi, the 31th July, 2026 F. No. CEA-HY-91-19/8/2024-Cyber Security Division.—-Whereas public notices advertising the draft of the Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2025 were published in six newspaper dailies, as required by sub-section (3) of section 177 of the Electricity Act, 2003 (36 of 2003) read with sub-rule (2) of rule 3 of the Electricity (Procedure for Previous Publication) Rules, 2005 for inviting objections and suggestions from all persons likely to be affected thereby, before the expiry of the period of thirty days, from the date on which the copies of the said draft regulations were made available to the public;
And whereas copies of the said newspapers containing the public notices and the said draft regulations on the website of the Central Electricity Authority were made available to the public on 07th October 2025;
And whereas the objections and suggestions received from the public on the said draft regulations were considered by the Central Electricity Authority;
And whereas Ministry of Electronics and Information Technology has accorded its concurrence to make these regulations in respect of the Cyber Security for power sector.
Now, therefore, in exercise of the powers conferred by sub-section (1) of section 177 read with clause (c) of section 73 of the Electricity Act, 2003(36 of 2003), the Central Electricity Authority hereby makes the following regulations relating to Cyber Security in power sector for ensuring safe and secure operation and maintenance of electrical plants and electrical lines, namely: –
Chapter I Preliminary
1. Short title and commencement - (1) These regulations may be called the Central Electricity Authority (Cyber Security in Power Sector) Regulations, 2026.
(2) These regulations shall come into force with effect from 1st April 2027:
Provided that the Regulations 5(9), 5(24), 5(33), 5(39), 6(2) and 6(7) shall come into force on such dates, as may be specified by the Authority through separate orders with prior approval of the Central Government.
2. Scope and extent of applicability - (1) These Regulations shall apply to -
(a) all the entities which own, operate, or manage Operational Technology infrastructure associated with the interconnected power system and their Information Technology infrastructure that is physically or logically connected to such Operational Technology infrastructure, for their existing as
well as upcoming infrastructure:
Provided that in respect of generating companies, captive generating plants, and organisations having Energy Storage System, these regulations shall be applicable only where such entities have an installed capacity of 50 MW or more:
Provided further that the entities having an installed capacity of less than 50 MW are encouraged to implement the minimum baseline cyber security controls outlined in the “15 Elemental Cyber Defense Controls for Micro, Small and Medium Enterprises” issued by Indian Computer Emergency Response Team;
(b) power exchanges and over the counter platforms, except regulations 6, 11, and 12.
(2) The vendor shall comply with the regulations 11 and 12 of these regulations as applicable.
3. Definitions - (1) In these regulations, unless the context otherwise requires -24 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4]
(a) “Act” means the Electricity Act, 2003 (36 of 2003);
(b) “Bill of materials” means a comprehensive list and structured inventories of components, sub- components, material, libraries, and modules used in product or system to facilitate a comprehensive visibility and transparency into composition of such product or system;
(c) “Business continuity plan” means documented procedures that guide an organisation to maintain a defined level of continued business operations;
(d) “Chief Information Security Officer” means the designated employee of senior management level of an entity, having knowledge of cyber security and matters related thereto and who is responsible for cyber security efforts and initiatives;
(e) “Chief Information Security Officer – Ministry of Power” means Chief Information Security Officer of Ministry of Power;
(f) “communication system” means a collection of individual communication networks, communication media, relaying stations, tributary stations, terminal equipment usually capable of inter-connection and inter-operation to form an integrated communication for power sector;
(g) “Computer Security Incident Response Team – Power” means an organisation established by the Ministry of Power as an extended arm of Indian Computer Emergency Response Team (CERT-In) for coordinating, reporting, and responding to cyber security incidents in power sector;
(h) “critical Information Technology system” means Information Technology system of an organisation whose unavailability or degradation would adversely impact its business operations;
(i) “critical Operational Technology system” means Operational Technology system of an organisation whose unavailability or degradation would adversely impact its business operations;
(j) “critical system” means critical Operational Technology system or critical Information Technology system or both, including Critical Information Infrastructure, as applicable, of an entity;
(k) “Critical Information Infrastructure” means Critical Information Infrastructure as defined in
explanation of sub-section (1) of section 70 of the Information Technology Act, 2000 (21 of 2000);
(l) “cyber asset” means the programmable electronic device, with or without computing capabilities including its hardware, software, sub-components and data thereof that are connected over a network;
(m) “cyber asset register” means a record that contains list of all cyber assets and description thereof;
(n) “cyber crisis management plan” means cyber crisis management plan as defined in clause (d) of sub-rule (1) of rule 2 of the Information Technology (Information Security Practices and Procedures for Protected System) Rules, 2018;
(o) “cyber resilience” means the ability to anticipate, withstand, recover from and adapt to adverse conditions, stresses, attacks or compromises on cyber asset;
(p) “cyber security audit” means an audit to assess the cyber security posture by a CERT-In empanelled auditor or any other auditor, as may be designated by the Ministry of Power, Government of India through a separate order;
(q) “Cyber security breach” means cyber security breach as defined in clause (i) of sub-rule (1) of rule 2 of the Information Technology (The Indian Computer Emergency Response Team and Manner of Performing Functions and Duties) Rules, 2013;
(r) “Cyber security incident” means cyber security incident as defined in clause(h) of sub-rule (1) of
rule 2 of the Information Technology (The Indian Computer Emergency Response Team and Manner of Performing Functions and Duties) Rules, 2013;
(s) “Cyber security policy” means procedure and processes for protecting information, computer resources, networks, devices, industrial control systems and Operational Technology resources and to improve the cyber security posture thereof;
(t) “Cyber sabotage” means deliberate action to disrupt, damage or destroy the information systems, networks or data processed therein for malicious purpose;
(u) “Distributed Generation Resource” means a generating station feeding electricity into the electricity system at voltage level of below 33 kV and includes grid-connected rooftop solar systems and Energy Storage System;[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 25
(v) “Electronic Security Perimeter” means the logical border surrounding Information Technology system or Operational Technology system or both that are electronically connected within which the access is monitored and controlled for protection of such system;
(w) “entity” includes generating companies, Captive generating plants, organisations having Energy Storage System; transmission licensees; distribution licensees; National Load Dispatch Centre;
Regional Load Dispatch Centres; State Load Dispatch Centres; Power Exchanges and Over the Counter Platforms;
(x) “Factory Acceptance Test” means structured and documented testing process carried out by the vendor in the presence of the representative of the entity to verify functional, performance, contractual and safety requirements of system or equipment or major component thereof before dispatch;
(y) “Information Technology system” means the Information Technology system consisting of user endpoints, network resources, applications, servers, and communication components deployed therein;
(z) “obsolete asset” means an asset declared by original equipment manufacturer or original equipment supplier whose production and services have discontinued, and its support is no longer available, and that asset is not suitable for its intended purpose due to technological advancement, operational changes and may pose security or operational risk;
(aa) “Operational Technology” means programmable hardware or system that detects or causes changes through the direct monitoring or control of physical devices, processes, and events;
(bb) “prosumer” means a person who consumes electricity from the grid and can also inject electricity into the grid for distribution licensee, using same point of supply;
(cc) “protected system” means protected system as defined in clause (k) of sub-rule (1) of rules 2 of the Information Technology (Information Security Practices and Procedures for Protected System) Rules, 2018;
(dd) “remote access” means an access to any cyber asset of an organisation through an external network;
(ee) “remote operation” means day-to-day operation and control of Information Technology or Operational Technology system of an entity performed from a distant location from such system;
(ff) “self-audit” means an audit by an entity in a financial year to assess its compliance with all applicable regulations specified in these regulations;
(gg) “sensitive information” means data or information that, if disclosed, modified, or destroyed, could negatively impact the privacy, integrity, security or operations of an organisation or an individual;
(hh) “Site Acceptance Test” means structured and documented testing conducted to verify functional, performance, contractual and safety requirements, at the site of installation and ensure that a system or equipment and its major components operate as intended in its final operational environment, before its commissioning;
(ii) “Sub-Sectoral Computer Security Incident Response Team” means an entity designated by the Authority to assist Computer Security Incident Response Team - Power in cyber security related matters;
(jj) “Technical Criteria Certificate” means a certificate issued to an organisation by a designated certification body accredited for ensuring conformance to cyber security standards specified by the Central Government;
(kk) “threat” means any circumstance or event having the potential to exploit a deficiency and negatively impact the confidentiality, integrity or availability of a cyber asset or Information Technology system or Operational Technology system;
(ll) “trusted source” means a mechanism designed to mitigate specific security requirements particularly cyber security supply chain risks by ensuring that equipment, services, manufacturer and service providers, associated with power sector meet an established criteria;
(mm) “Vulnerability” means vulnerability as defined in clause (p) of sub-rule (1) of rule 2 of the Information Technology (The Indian Computer Emergency Response Team and Manner of Performing Functions and Duties) Rules, 2013;
(nn) “vendor” means original equipment manufacturer, original equipment supplier, system integrator, supplier of hardware or software associated with original equipment, contractor or service provider including cloud service provider; and manufacturer and supplier of hardware, firmware, or software26 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4] associated with the original equipment or control systems, including but not limited to inverters, communication modules, monitoring systems, and related control or energy management software, of a Distributed Generation Resource owned by a prosumer.
(2) Words and expressions used but not defined in these regulations shall have their respective meanings assigned to them in the Act, Rules and other regulations made thereunder.
CHAPTER II COMPUTER SECURITY INCIDENT RESPONSE TEAM - POWER
4. (1) The Computer Security Incident Response Team – Power shall -
(a) be the coordinating agency for reporting and responding to cyber security incidents associated with power sector;
(b) be the nodal agency of power sector for analysis, prediction and prevention of cyber security incidents and dissemination of information thereof;
(c) collect data and information pertaining to any cyber security incident from an entity including network architecture, details of assets, logs, cyber forensic records, forensic image, policies and procedures or any other relevant information, in the form, manner and mode as specified by it:
Provided that sensitive data as well as sensitive information collected shall be protected against breaches and shall only be used for cyber security purpose by designated government agencies but not be disclosed to any third party without explicit communication to the concerned entity.
(2) The roles and responsibilities of Computer Security Incident Response Team - Power in Power Sector include the following, namely -
(a) collect and analyze cyber incidents, vulnerabilities and threats related to power sector;
(b) predict cyber security incidents, threats and vulnerabilities related to power sector;
(c) coordinate and collaborate with Indian Computer Emergency Response Team, National Critical Information Infrastructure Protection Centre and other agencies designated by the Central Government in the area of cyber security, to resolve the cyber security incidents related to power sector;
(d) issue alerts, advisories, and guidelines as well as threat intelligence in coordination with Indian Computer Emergency Response Team, National Critical Information Infrastructure Protection Centre and any other agencies designated by the Central Government in the area of cyber security;
(e) create or develop Standard Operating Procedures, security policies, sub-sector specific benchmarks, security controls, and best practices for incident response activities in consultation with Indian Computer Emergency Response Team, National Critical Information Infrastructure Protection Centre, sub-sectoral Computer Security Incident Response Teams, Electricity Regulatory Commissions, entities, and other agencies designated by the Central Government in the area of cyber security;
(f) undertake proactive measures to increase the cyber security awareness through capacity building initiatives and interventions;
(g) ensure the improvement of cyber security posture of the power sector through cyber security assessments, cyber security audits, certification audits, self-audits, third party audits and exercises including mock-drills and simulations;
(h) coordinate for laying down the sub-sector specific cyber security framework, protocols, and rules;
(i) advise the entities in preparation of their Cyber Crisis Management Plan;
(j) coordinate with entity for ensuring the implementation of their Cyber Crisis Management Plan during actual cyber crisis;
(k) facilitate and promote Research and Development in the domain of cyber security through collaboration with Industry, Research Institutes and Academia;
(l) formulate and implement of measures to ensure cyber security of supply chain of cyber assets specified by the Central Government or the Authority;
(m) establish central cyber security coordination forum and regional cyber security coordination forums of power sector to support Computer Security Incident Response Team - Power, in accordance with a separate order issued by the Authority, for periodic review of cyber security posture, deliberate upon cyber security challenges, information sharing, coordinated response planning and improve the overall posture of sector;[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 27
(n) Any other functions associated with cyber security related matters in the power sector, as directed by the Central Government or the Authority.
(3) The directions and guidelines of Computer Security Incident Response Team - Power, in the matters related to cyber security of power sector, shall be complied with by entities and vendors, as applicable.
(4) The Authority through a separate order may designate sub-sectoral Computer Security Incident Response Teams in power sector for generation, transmission, distribution, grid operation, and any other sub-sector, along with their roles and responsibilities to assist Computer Security Incident Response Team - Power.
CHAPTER III General Cyber Security requirements
5. The entity shall -
(1) designate regular employees of senior management level as Chief Information Security Officer and alternate Chief Information Security Officer;
(2) ensure that the positions of Chief Information Security Officer and alternate Chief Information Security Officer shall not remain vacant at the same time;
(3) define roles and responsibilities of Chief Information Security Officer and alternate Chief Information Security Officer in accordance with the Central Government’s regulatory framework and relevant guidelines;
(4) ensure that the Chief Information Security Officer reports to the head of the entity:
Provided that in case any entity such as the State Load Dispatch Centre is not an independent entity but part of a holding company or parent company, such entity shall have a separate Chief Information Security Officer, who shall report to head of such holding company or parent company, as applicable and shall also have Alternate Chief Information Security Officer;
(5) ensure an employee is designated as Chief Information Security Officer, for a minimum period of three years;
(6) ensure that role of the Chief Information Security Officer is ring fenced to the tasks of cyber security related matters only;
(7) provide contact details of the Chief Information Security Officer and alternate Chief Information Security Officer and updation thereof in public domain and communicate such details to Computer Security Incident Response Team - Power as well as all internal and external stakeholders;
(8) ensure that Chief Information Security Officer attends cyber security training courses for at least five man-days in each financial year;
(9) establish a dedicated Information Security Division headed by Chief Information Security Officer, within India, for dealing with all cyber security related matters and the same shall remain operational round the clock. Further-
(a) the Information Security Division shall be deployed with sufficient staffing;
(b) the staff deployed in Information Security Division shall have valid certificate of successful completion of domain specific cyber security course;
(c) the staff deployed in Information Security Division shall attend cyber security training courses associated with power sector for at least five man-days in each financial year;
(d) the staff shall be deployed in Information Security Division for a minimum tenure of three years;
(10) have a defined and documented Cyber Security Policy, which is approved and reviewed annually by the head or board of the entity, as the case may be;
(11) prepare a Cyber Crisis Management Plan in consultation with Computer Security Incident Response Team - Power, to manage and recover from all possible cyber crisis situations in shortest possible time with
minimum impact on business operations:
Provided that the Cyber Crisis Management Plan shall be vetted by Indian Computer Emergency Response Team, approved and reviewed annually by the head or board of the entity, as the case may be;28 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4]
(12) ensure separation of Information Technology networks containing Critical Information Infrastructure
from Internet as well as rest of the Information Technology networks:
Provided that in case internet is required for Information Technology networks containing Critical Information Infrastructure, the same shall be sourced securely with suitable hardening measures as specified by designated agencies of the Central Government;
(13) ensure deployment of all required security devices including firewalls at Electronic Security Perimeter, such that the deployed security system meets the requirements of, inter-alia, packet filtering; deep packet inspection; content, user and application based filtering; detection and inspection of encrypted traffic;
intrusion detection and prevention; geo-fencing; facility for automatic signature and behaviour updates; user controlled updates; detection, inspection and filtering based on signature and behavioural anomalies;
(14) ensure that any web service or web-based application including website, web portal, and Application Programming Interfaces, having public access, shall be deployed only after cyber security audit clearance:
Provided that any software update, including patch, in web applications and web services shall be deployed only after successful testing and confirmation, such that the subject update is free from any cyber security vulnerability, and after ensuring that such update is free from any cyber risk:
Provided further that any software update qualified for prior requirement of cyber security audit, as specified in Cyber Security Policy, shall be deployed only after its cyber security audit clearance:
Provided also that all software updates, those not necessitated for prior cyber security audit, shall be assessed during next cyber security audit;
(15) ensure deployment of all required security devices for all critical web applications, identified as per the procedure detailed under Cyber Security Policy, such that the deployed security system meets the requirements of, inter alia, application layer filtering including detection and filtering of web based encrypted traffic; ensuring bidirectional protection; facility for automatic signature and behavioural updates; intrusion detection and prevention, user controlled update mechanism; content, user and application based filtering;
geo-fencing; detection, inspection and filtering of encrypted traffic based on signature and behavioural anomalies;
(16) identify and segregate systems as critical and non – critical systems, as per the procedure detailed in Cyber Security Policy;
(17) ensure that remote access to cyber assets, if necessary, may be permitted only for troubleshooting and emergency requirements, as per the procedure specified under Cyber Security Policy:
Provided that such access for the cyber assets associated with non – critical system may be permitted with approval of Chief Information Security Officer for troubleshooting and emergency requirements only
along with suitable security control measures:
Provided further that approval for such access to critical systems or cyber assets thereof may be granted after a comprehensive risk assessment is conducted along with identification of effective measures thereof and such access shall be continuously monitored to detect any anomaly or attempts of unauthorised
use:
Provided also that record of risk assessment, physical document of approval and logs with respect to each such access to critical system shall be maintained for a period as specified in data retention policy;
(18) conduct cyber security awareness program and cyber security exercises including mock-drills and tabletop exercises, at least once in every six months;
(19) ensure that sensitive information and sensitive data including such data and information hosted on cloud as well as such historical data and information, is stored in an encrypted, secured, and protected environment and resides within India only;
(20) include all cyber security requirements as well as applicable cyber security rules, regulations issued by the Central Government and Non - Disclosure Agreement in Service Level Agreement with the vendors, as specified under Cyber Security Policy, to ensure the confidentiality, integrity and availability of sensitive
information during their contract period as well as after completion of such contract period:
Provided that vendor having cyber or physical access or both to the critical systems including staff of vendor engaged for operation or maintenance or both of such systems, may be permitted after carrying out personnel risk assessment and mitigative measures taken thereof along with an undertaking complying with
Service Level Agreement:[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 29
Provided further that in case of any cyber security breach, the entity shall enquire into the matter and initiate action against such vendors including cloud service provider committing cyber security breach;
(21) ensure online and offline backups of all critical systems in a separate, safe and secure environment as specified in cyber security policy;
(22) facilitate a comprehensive cyber security audit encompassing all critical systems, as specified under regulation 13, at least once in every financial year but with a minimum and maximum gap of nine months and fifteen months, respectively, between two consecutive cyber security audits:
Provided that the cyber security auditing agency engaged by entity shall deploy its qualified personnel but exclusive of any staff deployed for such entity, if any:
Provided further that no three consecutive audits shall be carried out by the same auditing agency or personnel;
(23) ensure that all Information Technology products procured comply with and tested in adherence with the orders issued by the Central Government;
(24) ensure compliance with and acquire ISO / IEC 27001 certificate or Technical Criteria Certificate
encompassing all critical systems:
Provided that no four consecutive audits for the certification of ISO 27001 or Technical Criteria Certificate shall be carried out by the same auditing agency or personnel;
(25) maintain asset register-
(a) for all cyber assets along with the requisite details including ownership, hardware, firmware, software, and patch as per the procedure defined in Cyber Security Policy;
(b) recording the details of all critical systems along with the requisite details including its configuration, hardware, software, network architecture depicting data flows and communication
protocols used therein:
Provided that such register shall be reviewed and updated at least once in every financial year or upon commissioning of any new cyber asset or critical system including replacements thereof, whichever is earlier;
(26) maintain Cyber Risk Assessment and Mitigation Plan for all assets detailed in cyber asset register, as per
the procedure defined in Cyber Security Policy:
Provided that Cyber Risk Assessment and Mitigation Plan shall be updated at least once in every six months and reviewed at least once in every financial year and such Cyber Risk Assessment and Mitigation Plan shall be implemented to manage the vulnerabilities, threats and risks associated thereof;
(27) ensure that the cyber security audit including vulnerability assessment and penetration testing is carried out prior to the commissioning of any new critical system including replacement of such system and manage vulnerabilities and risks for critical system as per the mechanism defined in Cyber Security Policy;
(28) furnish relevant information including system details and functionality, of all new critical systems commissioned including those replaced, as per asset register associated with critical systems to the Computer Security Incident Response Team - Power within thirty days of such commissioning or replacement;
(29) provide the relevant information to National Critical Information Infrastructure Protection Centre for identification of Critical Information Infrastructure. Further, within sixty days of an asset being identified as a Critical Information Infrastructure by National Critical Information Infrastructure Protection Centre, entity shall approach the Appropriate Government for notifying such asset as a Protected System;
(30) ensure that Critical Information Infrastructure and Protected System are not discoverable on public platforms unless approved by the head or board of the entity, as applicable, on the basis of business requirements, criticality, and risk assessment of such system;
(31) ensure that the procurement process mandates inclusion of Factory Acceptance Test and Site Acceptance Test including testing of cyber security requirements;
(32) ensure that the clocks of all relevant information processing systems within Information Technology and Operational Technology systems, as applicable, are synchronised to a reference time source as provided in
the Cyber Security Policy:
Provided that prior to selection of such reference time source detailed cyber risk assessment shall be carried out;
(33) ensure that all personnel including personnel engaged by vendors in day-to-day operation and30 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4] maintenance of all critical systems, have mandatorily undergone designated cyber security courses pertaining to power sector;
(34) ensure that the systems, networks, and applications associated with physical security of critical systems
are physically separated from the network of such critical systems:
Provided that in case of such physical separation is not feasible, with approval of head of the entity, subject systems, networks, and applications shall be logically separated from the networks of such critical systems;
(35) maintain Incident Response and Recovery Plan, as specified in Cyber Security Policy, to recover from
cyber incidents and resume normal operations at the earliest:
Provided that such plan shall be reviewed and updated at least once in every six months;
(36) have surveillance and continuous monitoring of Information Technology systems and Operational Technology systems, as applicable, for identification of threats as well as vulnerabilities and provide incident response and remediation support thereof;
(37) ensure that logs of all security devices deployed at Electronic Security Perimeter are enabled to record exchange of data and information flowing through such devices;
(38) ensure regular, at least once in every year, review and updation of rules and policies of perimeter security devices;
(39) ensure that the Information Technology equipment and services are procured from trusted sources, in accordance with orders, directions or guidelines issued by the Central Government from time to time;
(40) comply with the directions and requirements issued under the Information Technology Act, 2000 (21 of
2000) and with all rules and regulations made thereunder, in addition to these regulations;
(41) have structured vulnerability disclosure and management programs with vendors and Computer Security Incident Response Team – Power;
(42) maintain a register to record all cyber security incidents along with relevant details, as per the format prescribed by Computer Security Incident Response Team - Power.
CHAPTER IV Additional Cyber Security requirements of Entities related to Operational Technology Systems.
6. In addition to requirements mandated for entities under the regulation 5, the entity shall – (1) ensure physical isolation of Operational Technology system from internet as well as Information Technology
system:
Provided that in case such isolation from Information Technology system is not possible due to business requirements, such Information Technology and Operational Technology interconnection may be permitted, as per the procedure defined in Cyber Security Policy, with suitable hardened logical separation between Operational Technology system and Information Technology system, on the basis of risk assessment of such interconnection and approval of head or board of the entity, as applicable:
Provided further that such inter-connection is continuously monitored for detection of malicious
activities and corrective measures thereof:
Provided also that such approval and logs associated with such inter-connection shall be retained for a period as specified in data retention policy;
(2) ensure deployment of suitable perimeter level cyber security devices including firewall at point of inter- connection of Operational Technology system with communication system of power system such that the deployed security system meets the requirements of, amongst other requirements, the detection and filtering of Operational Technology related protocols as well as traffic; content, user and application based filtering;
deep packet inspection, intrusion detection; geo-fencing; user controlled updates; detection based on
signature and behavioural anomalies and filtering thereof:
Provided that the updates including signatures for devices forming part of such security system shall be carried out in offline mode, as specified in Cyber Security Policy;
(3) ensure that control and operation of power system elements and exchange of information thereof including real time data shall be over a dedicated communication channel isolated from the internet through
perimeter level cyber security devices and shall be confined to national boundaries only:[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 31
Provided that for entities having business requirements or cross border power system elements, the exchange of information and real time data, as identified under Cyber Security Policy, may be permitted beyond the national boundaries only through dedicated separate communication system and unidirectional gateway, isolated from internet and along with cyber security devices, to transmit and receive subject to the condition that such information and data are monitored continuously to detect any anomaly or unauthorised
attempt:
Provided further that in case of exchange of real time information and data associated with end consumers, the same may be permitted through secured connection, isolated from public access, subject to the condition that exchange of sensitive information and data thereof over such connection shall be encrypted to ensure its confidentiality, integrity, and privacy;
(4) ensure that if remote operation is necessary for business requirements, the same shall be, within India, with the prior approval of head or board of the entity, as applicable, as per the procedure specified in the Cyber Security Policy, through a dedicated communication channel, isolated from internet, having cyber security system mandated under the regulation 6(3);
(5) ensure that all Operational Technology equipment, components, and parts thereof deployed for control and operation of power system shall comply with orders issued by the Central Government;
(6) ensure that the communication system of Operational Technology system is isolated from that of Information Technology system;
(7) ensure that the Operational Technology equipment and services are procured from trusted sources, in accordance with orders, directions, or guidelines issued by the Central Government from time to time;
(8) ensure that the Operational Technology environment is segmented into different trust levels on the basis of criticality, security requirements, and risk assessment;
(9) ensure that the communication system particularly channel, catering the Operational Technology data and information between the two entities is protected by owner of such system against cyber security threats.
CHAPTER V Functions of Chief Information Security Officer and Information Security Division
7. (1) The Chief Information Security Officer and Alternate Chief Information Security Officer shall be citizens as well as residents of India and shall possess a degree in engineering or equivalent from a recognised institute, with at least fifteen years of experience in domain of power sector or Information
Technology:
Notwithstanding anything contained in these regulations, the Authority may specify additional qualifications for Chief Information Security Officer of entity, through separate orders:
Provided that in absence of Chief Information Security Officer the roles and responsibilities of the Chief Information Security Officer shall be performed and executed by Alternate Chief Information Security Officer.
(2) The Chief Information Security Officer shall -
(a) be the nodal officer for all cyber security related matters;
(b) coordinate with all concerned stakeholders associated with the cyber security related matters.
(3) The functions of the Chief Information Security Officer, with the assistance of the Information Security Division shall include the following, namely -
(a) reporting of cyber security incidents within six hours to Computer Security Incident Response Team -
Power and Indian Computer Emergency Response Team:
Provided that in case any incident is concluded as a cyber sabotage in critical systems, the same shall be reported within twenty-four hours;
(b) quarterly review of compliances as mandated in Cyber Security Policy;
(c) implementation of cyber security control measures for critical systems, as specified in Cyber Security Policy, to firm up their cyber resilience;
(d) in case of Critical Information Infrastructure or Protected System, implementation of validated cyber security control measure as per guidelines of National Critical Information Infrastructure Protection Centre;
(e) acting upon the cyber security related directives, guidelines and advisories issued by the Central32 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4] Government, the Authority, Indian Computer Emergency Response Team as well as Computer Security Incident Response Team - Power;
(f) gathering of cyber threat intelligence, its analysis, identification of threat vectors, assessment of cyber security risks and mitigation measures thereof;
(g) sharing of the detailed report of detected cyber security incidents, Action Taken Reports, Root Cause Analysis, and other relevant information with Computer Security Incident Response Team - Power and Indian Computer Emergency Response Team;
(h) retention of all cyber security related data, information and documents in the manner, form and period as specified in data retention policy;
(i) custody of all documents specified in First Schedule of these regulations;
(j) ensuring the updation of firmware and software of all critical systems, with patches as provided in Cyber Security Policy;
(k) ensuring the storage of logs of all Information and Communication Technology systems and logs as well as forensic records pertaining to cyber security incidents for the period, as specified in Cyber Security Policy;
(l) providing required information including allocated, used and unused public IPs to Computer Security Incident Response Team - Power;
(m) ensuring random testing of day-to-day operations of critical systems for being in conformance with its Cyber Security Policy and corrective measures thereof;
(n) prepare a procedure to facilitate remote access to cyber assets associated with non-critical system, for troubleshooting and emergency requirements including suitable security controls required and process to grant approval for such access;
(o) prepare a procedure, as specified in Cyber Security Policy, to facilitate safe and secure remote operation of Operational Technology system and updation thereof;
(p) ensure the development, implementation, review and updation of Cyber Security Policy, Cyber Crisis Management Plan, data retention policy, and backup policy;
(q) ensure the preparation, updation and review of asset register for cyber assets and critical systems as well as Cyber Risk Assessment and Mitigation Plan;
(r) ensure synchronisation of all Information Technology systems and Operational Technology systems to the reference time source, as specified under Cyber Security Policy.
CHAPTER VI Cyber Security Policy
8. The Cyber Security Policy shall be aligned with the Business Continuity Plan of entity covering Operational Technology as well as Information Technology environment, as applicable, and the same may include -
(1) defined purpose and scope along with all applicable cyber security requirements and compliances thereof;
(2) for Protected Systems, provisions ensuring alignment with National Critical Information Infrastructure Protection Centre guidelines and control requirements;
(3) defined roles and responsibilities of relevant internal and external stakeholders;
(4) defined procedure to prepare cyber asset register, consisting of all cyber assets and classification thereof on the basis of their criticality and risk identified in Cyber Risk Assessment and Mitigation Plan; and update such procedure for detailed visibility and management of all cyber assets;
(5) defined procedure to identify all systems and classify such systems as critical systems, on the basis of a defined criteria considering their impact on the Business Continuity Plan, as well as record details of such
systems in a register:
Provided that such procedure shall be reviewed and updated at least once in every financial year;
(6) defined procedure for Cyber Risk Assessment and Mitigation Plan to identify vulnerabilities and threats against each cyber asset and risk associated thereof, control and mitigation measures in commensuration with
criticality of such risks and implementation thereof:
Provided that such procedure shall be reviewed and updated at least once in every financial year;[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 33
(7) defined mechanism to manage the vulnerabilities and risks in critical systems by timely identifying deficiencies and threats in such systems, including receipt of associated information from internal and external sources, analysis of such information, risk assessment, and management thereof:
Provided that such mechanism shall be reviewed and updated at least once in every financial year or upon commissioning of any new critical system, including replacement thereof, whichever is earlier;
(8) procedure to identify and report cyber sabotages in critical systems including receipt of such information from internal as well as external stakeholders;
(9) defined Incident Response and Recovery Plan detailing list of all type of incidents, risk analysis, and risk-based incident specific response plan for effective and timely restoration of affected system:
Provided that an incident which necessitates entity level strategic recovery plan shall be classified as a crisis;
(10) mechanism for random testing of day-to-day operations of critical system, for being in conformance with applicable policies, rules and regulations issued by Computer Security Incident Response Team - Power
and other agencies designated by the Central Government in the area of cyber security:
Provided that such testing shall not interrupt the operations and functionality of such systems and safety thereof;
(11) access control mechanism to critical systems and cyber assets associated thereof, applications having public access, sensitive information and sensitive data, shall be governed by Access Management based on the principles of Authentication, Authorisation and Accounting criteria and criticality thereof:
Provided that a detailed procedure may be laid down to restrict the physical and logical access to documents and records specified under data retention policy;
(12) personnel risk assessment process to identify risks associated with personnel deployed by vendor, having authorised cyber or physical access to critical system and assets associated thereof or engaged for Operation or Maintenance or both of such system, on the basis of their roles and responsibilities including
change in such roles and responsibilities and mitigating measures thereof:
Provided that for the employees engaged in day-to-day Operation and Maintenance or having authorised cyber or physical access to critical system and assets associated thereof, personnel risk assessment shall be carried out, on the basis of their roles executed and duration of deployment in such entrusted tasks, after their termination, resignation, and superannuation from their employment;
(13) mechanism to ensure that all access points to critical systems are secured physically and monitored continuously and also such access is restricted for physical protection of these systems and cyber assets
associated thereof:
Provided that in case of a perceptible threat of physical damage to any of these systems or assets thereof, the physical access granted to any individual for such system or asset may be revoked;
(14) cyber supply chain risk management process to identify and assess cyber security risks associated with supply chain of critical systems and services thereof along with mitigative measures;
(15) defined procedure for remote access to cyber assets along with the details of authorisation to grant approval for such access on the basis of their criticality, such that such access is safe and secured through suitable control measures including minimum duration with least privileges, multi-factor authentication, and geo-fencing;
(16) defined procedure for remote operation of Operational Technology systems to meet the business requirement, on the basis of assessment of cyber risks associated with such operation and mitigation
measures thereof:
Provided that such procedure shall be reviewed and updated once in every year or upon any change necessitated to meet business requirements, whichever is earlier;
(17) digital data protection and privacy policy in line with applicable rules and regulations issued by the Central Government;
(18) defined backup policy to ensure that online or offline backup data or both, as applicable, of all critical systems is up to date, but not older than a month, and retained in a separate and safe environment for the
period as specified in the data retention policy:34 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4]
Provided that the backup policy shall be reviewed and updated at least once in every financial year and ensure that the integrity of backup data and its restoration is tested such that the same meets the requirements of Business Continuity Plan;
(19) defined mechanism to ensure storage of sensitive data and its backup, as well as its transmission over dedicated communication channel or internet, is encrypted to ensure its confidentiality, integrity, and
availability:
Provided that in case encryption of certain sensitive data is not feasible due to business requirements, the same, in unencrypted form, may be permitted over a dedicated communication channel;
(20) annual cyber security training program for capacity development of all personnel having authorised cyber or physical access or both to critical system and assets associated thereof;
(21) Internet access policy to monitor and restrict the internet traffic to ensure defined and authorised use only;
(22) phase out plan for obsolete cyber assets as well as those assets nearing end of useful life and management thereof along with their safe and secure disposal;
(23) plan for collaboration with industry, research institutes, stakeholders and academia to promote Research
and Development activities in the domain of cyber security:
Provided that scope and assets for such collaboration may be identified after carrying out detailed risk assessment and such collaboration shall be effected after signing of Non-Disclosure Agreement;
(24) define criteria to classify the software updates including patches in critical systems into two categories-
(a) a software update that qualifies for requirement of prior cyber security audit before its deployment, and
(b) a software update that does not require prior cyber security audit before its deployment but necessitates such assessment in next cyber security audit.
Further, the suggestive list of software updates, which requires prior cyber security audit, is specified at
the Second Schedule:
Provided that Computer Security Incident Response Team - Power, with the approval of Authority, may revise this list from time to time;
(25) defined change management process to record changes implemented in all critical systems and to ensure
that planned changes on such systems and cyber assets associated thereof are controlled:
Provided that such process shall ensure that software updates including patches qualified for prior requirement of cyber security audit shall be version controlled along with provision of roll-back:
Provided further that the updates including patches in Operational Technology system shall be digitally signed by original equipment manufacturer and such updates may be deployed in offline mode, after their risk assessment and successful testing in simulated environment. However, in case the digital signature of original equipment manufacturer is not available for any patch, the validity and authenticity of such patch shall be verified;
(26) a mechanism to facilitate storage of logs and forensic records as mandated in data retention policy in a safe and secured environment;
(27) a procedure to select reference time source, after assessing its associated cyber risks for synchronizing
all processing systems of Information Technology and Operational Technology environment to such source:
Provided that the reference time source selected for Operational Technology system shall be, either terrestrial or India specific satellite based and independent of internet;
(28) defined procedure for logical separation of Operational Technology system from Information Technology system to ensure safe and secure operation of both Information Technology systems as well as
Operational Technology systems:
Provided that the identified data and information from Information Technology to Operational Technology and that from Operational Technology to Information Technology shall flow through separate communication channel and unidirectional gateway;
(29) defined procedure by cross border entities to identify and classify the data as well as information including real time data permitted to be communicated beyond national boundaries, on the basis of risk
assessment and business requirements:[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 35
Provided that Computer Security Incident Response Team - Power may review and assess such procedure, data and relevant information, as and when required;
(30) defined procedure to identify web applications along with a criterion to classify such applications as critical web applications, on the basis of their impact on business operations and continuity;
(31) defined procedure for safe and secure disposal of out of service or obsolete cyber asset and data stored therein;
(32) defined procedure for safe and secure disposal of sensitive data and sensitive information;
(33) data retention policy specifying the manner and form of retention of various documents and records as well as data and information including -
(a) backup of data of critical systems;
(b) record of logs, risk assessment, and approval thereof for each grant of remote access to critical systems;
(c) logs and grant of approval associated with interconnection of Operational Technology system with Information Technology system;
(d) cyber security documents including certificates of cyber security tests, Factory Acceptance Test and Site Acceptance Test results, cyber security audit reports and other documents as mandated by the Central Government;
(e) record of changes including software updates and patches implemented in critical systems:
Provided that the data retention policy shall be reviewed and updated at least once in every financial year and the data, information and documents shall be retained to ensure -
(a) at least last two working data backups are available;
(b) risk assessment, physical record of grant of approval and logs with respect to each remote access to critical system are available for at least one year;
(c) reports of Factory Acceptance Test and Site Acceptance Test including test of cyber security requirements are available throughout life of cyber asset;
(d) record of risk assessment for remote operation in Operational Technology environment along with approval received thereof are available for at least one year;
(e) cyber security audit reports of last three years are available;
(f) certification audit reports of last four years are available;
(g) self-audit reports of last three years are available;
(h) logs of all Information and Communication Technology systems, inter-connection of Operational Technology system with Information Technology system and forensic records are available for a period of one hundred and eighty days;
(i) the logs associated with an incident including logs pertaining to one hundred and eighty days prior and post to such incident are available for at least three hundred and sixty-five days from
occurrence of such incident:
Provided further that the access to such information, data and documents may be restricted to authorised persons only, on the basis of procedure defined under access control mechanism:
Provided also that the Authority may, through separate orders include any other document and specify any other manner, mode, and period for retention of documents under data retention policy.
CHAPTER VII Cyber Crisis Management Plan
9. The cyber crisis management plan shall – (1) include detailed Standard Operating Procedure to detect and identify all incidents, criteria to classify an incident as a crisis and list of all possible crisis scenarios;
(2) identify stakeholders along with their roles and responsibilities for all possible crises and communication of such roles as well as responsibilities thereof;
(3) include the manner and mode of communication with internal as well as external stakeholders for close coordination during the crisis;
(4) include mitigative measures to minimize the impact and recover from crisis at the earliest.36 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4]
10. Responsibilities of the entities – The entity shall -
(1) ensure availability of all essential communications with relevant internal and external stakeholders during cyber crisis;
(2) test the efficacy of Cyber Crisis Management Plan at least once in every year through exercises and
mock drills for scenarios selected for that year out of all identified crisis scenarios specified under it:
Provided that the selection of scenarios in any year shall not overlap with the scenarios tested and verified earlier unless the cycle of all listed scenarios has been completed for testing and verification;
(3) prepare a detailed report of each actual crisis handled and recovered along with experience gained, lessons learnt, feedback received, lapses observed and proposed measures thereof:
Provided that the relevant information including brief about actual crisis, its handling and takeaways shall be shared with Computer Security Incident Response Team - Power and other stakeholders for
collective improvement of cyber security ecosystem of power sector:
Provided further that the Cyber Crisis Management Plan shall be updated by incorporating qualified observations of its own and that of other stakeholders to improve its cyber security posture.
CHAPTER VIII Cyber Security requirements for Vendor
11. Cyber Security requirements for vendor - The vendor shall -
(1) provide documented and tested procedures as well as recovery plan to the entity for restoration of systems supplied by them from potential cyber crisis scenarios;
(2) ensure, either digitally signed or validated and authenticated, security patches and updates for all systems as well as components supplied by them are available to the entity throughout their contract period or useful life of such systems, whichever is later;
(3) provide detailed document to the entity consisting of all requirements and processes including security patches as well as updates required to be installed on the third-party components to integrate a component or sub-system supplied by them;
(4) provide details of end of support or end of life of software, hardware and system to the entity, as applicable, supplied by them including those sourced from third parties;
(5) provide Bill of material to the entity, as per Indian Computer Emergency Response Team guidelines issued from time to time, comprising detailed list of all components supplied by them for applications including firmware, deployed in critical systems;
(6) ensure that the hardware and software are hardened by enabling all inherent security capabilities, secured configuration, and controls, before supplying to the entity;
(7) establish a formal structured process for entities to report vulnerabilities in the products and services.
Further, the vendor shall furnish such vulnerabilities to the Computer Security Incident Response Team - Power, through its vulnerability disclosure and management program.
12. Responsibility of vendors - In the case of Distributed Generation Resource of prosumers, it shall be the responsibility of vendor to -
(1) ensure that any application, associated monitoring and control servers, and the real-time data of such systems including any data or information hosted on cloud platforms as well as associated historical data or information, be stored in an encrypted, secure, and protected environment and shall reside exclusively within India;
(2) ensure that remote access and remote operation of the grid-connected devices as well as exchange of their real time data and information with remote applications, aggregators, and distribution licensees shall be established through secure channel after mutual authentication and such communication shall be encrypted;
(3) provide such information as may be required for the purpose of verification of a trusted source, in accordance with the orders, directions or guidelines issued by the Central Government from time to time:
Provided that this regulation for the existing Distributed Generation Resource of prosumers shall come into force on such date, as may be specified by the Authority through separate order.
Chapter IX[भाग III—खण् ड 4] भारत का रािपत्र : असाधारण 37 Cyber Security Audit
13. Cyber Security Audit - The entity shall ensure that -
(1) cyber security audit shall be conducted, as per scope detailed in cyber security audit guidelines and directions issued by Computer Security Incident Response Team - Power and other cyber security agencies designated by the Central Government;
(2) the scope of cyber security audit shall also include verification of closure of all audit findings identified in the previous cyber security audit;
(3) the auditor submits its cyber security audit report within six weeks of its commencement, and all critical and high-risk vulnerabilities shall be addressed within a period of one month and medium as well as low risks vulnerabilities within a period of three months from the date of submission of cyber security audit
report by the auditor:
Provided that appropriate compensatory controls shall be deployed to contain critical and high-risk vulnerabilities, till audit clearance of such vulnerabilities.
14. Responsibilities of Chief Information Security Officer -
(1) Chief Information Security Officer shall review the audit compliances and ensure that the auditor shall submit its cyber security audit closure report within six months from commencement of cyber security audit.
(2) Chief Information Security Officer shall report major audit findings including critical and high-risk vulnerabilities observed in cyber security audit closure report along with any non - compliances with respect to critical systems to the head or board of the entity, as the case may be:
Provided that Chief Information Security Officer - Ministry of Power, may ask for audit closure report of any entity at any point of time for examination and, if need be, after seeking written clarification, with prior approval of the Authority and prior notice to such entity, may appoint a third-party auditor for verification of audit compliances, the cost of which shall be borne by entity:
Provided further that in case the findings of the third-party audit are in variance with the observations of cyber security audit closure report, Chief Information Security Officer - Ministry of Power may take further necessary action.
CHAPTER X MISCELLANEOUS
15. Self-audit - The entity shall conduct self - audit to assess its compliance with these regulations every
financial year:
Provided that, for cyber security and compliance with these regulations, the entity may designate any member of the board or of senior management, as the case may be, to be responsible for such compliance:
Provided further that the entity shall address the non-compliances in a time bound manner and ensure that all such non-compliances are addressed before self-audit scheduled in next financial year:
Provided also that Chief Information Security Officer - Ministry of Power, based on the facts available or reported by any individual, may examine compliance report of any entity and after seeking written clarification, with prior approval of the Authority and prior notice to such entity, may appoint a third-party auditor to verify claim made by the entity, the cost of which shall be borne by such entity.
16. In specific cases, after seeking written clarifications and examination thereof, Chief Information Security Officer - Ministry of Power may recommend to the Central Government for initiation of appropriate proceedings under relevant provisions of the Information Technology Act, 2000 (21 of 2000) or to file a petition before Appropriate Commission for proceedings under section 142 of the Act.
17. Power to Relax - The Authority through an order, for reasons to be recorded in writing, may relax any of the provisions of these regulations on its own motion or on an application made before it by an interested person to remove the hardship arising out of the operation of any of these regulations, applicable to a class of persons.38 THE GAZETTE OF INDIA : EXTRAORDINARY [PART III—SEC.4] FIRST SCHEDULE [see clause 3(i) of regulation 7] The following documents and information shall be retained -
1. Cyber Security Policy along with documents and procedures listed therein.
2. Cyber Crisis Management Plan.
3. Data Retention Policy and all documents and information listed thereunder.
4. ISO/ IEC 27001 Certificate or Technical Criteria Certificate.
5. Asset register for cyber assets and critical systems.
6. Cyber Risk Assessment and Mitigation Plan.
7. Incident Response and Recovery Plan.
8. Cyber Security Incident Reporting register.
9. Bill of materials.
10. Business Continuity Plan.
11. Remote operation procedure.
12. Remote access procedure.
THE SECOND SCHEDULE [see clause 24 of regulation 8] The suggestive criteria for software updates requiring Prior Cyber Security Audit Software updates including modifications and enhancements to applications, websites, web portals, and associated systems meeting any of the following criteria shall mandatorily require a successful cyber security audit prior to deployment, namely -
1. Critical system impact: Updates that affect core operational processes, such as energy generation, transmission, distribution or load management wherein vulnerabilities could compromise the functionality or reliability of critical infrastructure.
2. Access control modifications: Updates that alter user authentication, authorisation mechanisms, or administrative privileges including those involving identity management systems or access control policies.
3. Integration with third-party systems: Updates involving integration with external systems, applications or third-party services especially those that exchange sensitive data or enable cross-platform communication.
4. Security protocol changes: Updates introducing changes to encryption standards, data transmission protocols or other security-related configurations that could impact the protection of sensitive information.
5. Introduction of new features or interfaces: Updates adding significant new functionalities, user interfaces or Application Programming Interfaces that could present potential attack surfaces.
6. Resolution of security vulnerabilities: Updates addressing previously identified Critical and High impact vulnerabilities where an incomplete or improper implementation could exacerbate security risks.
7. Incident response and monitoring systems: Updates affecting systems or tools related to cyber security monitoring, incident response or log management wherein any disruption could hinder the ability to detect or respond to threats effectively.
8. Reform or regulatory mandated systems: Updates impacting systems subject to regulations or pursuant to reforms programs of Appropriate Government.
SHARVAN KUMAR, Secy. [ADVT.-III/4/Exty./253/2026-27] Uploaded by Dte. of Printing at Government of India Press, Ring Road, Mayapuri, New Delhi-110064 and Published by the Controller of Publications, Delhi-110054.