A Computer Security Incident Response Capability (CSIRC) is established to detect and react to computer security incidents in a skilled and efficient manner. A CSIRC is a combination of technically skilled people, policies, and techniques that constitute a proactive approach to handling computer security incidents. A CSIRC can provide organization-wide protection from damaging incidents, saving the organization valuable resources and permitting it to take better advantage of computer technology. Towards the establishment of CSIRC of NIC, named NIC-CIRT - Computer Incident Response Team of NIC, a dedicated website has been hosted. An additional supporting site (http://security.nic.in) has also been hosted for Cyber security guidelines and Security Policies of NICNET. These websites are accessible to all NIC professionals having user accounts on the INTRANIC server. The NIC-CIRT and Security website caters to the following: v Incident Response Service: An online Cyber security incident reporting form is available to enable reporting of security incidents occuring in NICNET. v Security Alerts and Advisory Service: It provides the information on latest releases of patches and alerts for different operating systems, router IOS and applications. Latest virus alerts are also disseminated through the NIC-CIRT site. v Vulnerability Assessment: Online form for requesting the vulnerability scan service is available. Besides the request may be sent through E-mail also to security@nic.in mail account to avail the service. v Security related Information Dissemination Service: Various Information Security Policies worked out by NIC are available for dissemination to the users through this service. Information on Patch management, virus, worms and anti-virus measures, security guidelines, etc., is also available. v Security Awareness Building Service: The website helps increase the security awareness through release of security related news, security incident statistics and security tips on the website. v Security Training: To update the security related skills, training is organized on Information Security periodically. The details of the same are posted on the site. For the aforesaid services, the NIC-CIRT website serves as a communication interface between the Cyber Security Division, Security Experts, Network and System Administrators and the NICNET users. The http://cirt.nic.in website hosts dynamic content and the site is updated almost on daily basis with the latest security alerts, pertaining to the patches or viruses, or security related news item, or a tip or advisory on security related issues. Thus, regular viewing of the website and acting upon the information therein by the NICNET users, in general, and the Network and Systems Administrators in particular, would help alleviate security problems. We call upon the NICNET users to make use of the NIC-CIRT as a single contact point for reporting of any Security Incident to enable coordinated action on such issues.
C YBER GOVERNANCE
Computer Incident Response Team (CIRT)
From January 2004 • Informatics, National Informatics Centre