<?xml version="1.0" encoding="utf-8" ?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns="http://purl.org/rss/1.0/">




    



<channel rdf:about="https://cis-india.org/search_rss">
  <title>Centre for Internet and Society</title>
  <link>https://cis-india.org</link>
  
  <description>
    
            These are the search results for the query, showing results 91 to 105.
        
  </description>
  
  
  
  
  <image rdf:resource="https://cis-india.org/logo.png"/>

  <items>
    <rdf:Seq>
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/cyfy-2018"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/events/roundtable-on-cyber-security-and-the-private-sector"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/conceptualizing-an-international-security-regime-for-cyberspace"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/hindu-businessline-arindrajit-basu-october-30-2018-lessons-from-us-response-to-cyber-attacks"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/cis-cybersecurity-series-part-21-gyanak-tsering"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/news/cybersecurity-the-intersection-of-policy-and-technology"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/files/cultivating-india2019s-cyber-defense-strategy"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/draft-security-standards-for-the-financial-technology-sector-in-india"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/arindrajit-basu-gurshabad-grover-elonnai-hickok-january-22-2019-response-to-gcsc-on-request-for-consultation"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/indias-national-cyber-security-policy-in-review"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/saket-modi-calls-for-stronger-cyber-security-discussions"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/internet-governance/blog/cis-cybersecurity-series-part-10-lawrence-liang"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/news/consultation-to-frame-rules-under-whistle-blowers-protection-act-2011"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/news/the-hindu-business-line-july-2-2014-kv-kurmanath-cyber-crimes-shoot-up-in-india-over-last-year"/>
        
        
            <rdf:li rdf:resource="https://cis-india.org/events/why-cyber-security-and-online-privacy-are-vital-for-success-of-democracy-and-freedom-of-expression"/>
        
    </rdf:Seq>
  </items>

</channel>


    <item rdf:about="https://cis-india.org/internet-governance/news/cyfy-2018">
    <title>CyFy 2018 </title>
    <link>https://cis-india.org/internet-governance/news/cyfy-2018</link>
    <description>
        &lt;b&gt;Swaraj Paul Barooah and Arindrajit Basu participated in CyFy 2018 organized by Observer Research Foundation at Hotel Taj Mahal, New Delhi from October 3 - 5, 2018.&lt;/b&gt;
        &lt;p&gt;&lt;a class="external-link" href="http://cis-india.org/internet-governance/files/cyfy-2018-agenda"&gt;Click to see the agenda&lt;/a&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/cyfy-2018'&gt;https://cis-india.org/internet-governance/news/cyfy-2018&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Admin</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Cyber Security</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    

   <dc:date>2018-10-08T15:36:40Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/events/roundtable-on-cyber-security-and-the-private-sector">
    <title>Roundtable on Cyber-security and the Private Sector</title>
    <link>https://cis-india.org/internet-governance/events/roundtable-on-cyber-security-and-the-private-sector</link>
    <description>
        &lt;b&gt;The Centre for Internet &amp; Society (CIS) invites you to a roundtable discussion on cyber-security and the private sector. The event will be held at Omidyar Network office in Bangalore from 10.00 a.m. to 4.00 p.m.&lt;/b&gt;
        
&lt;p style="text-align: justify;"&gt;An increased proliferation of cyber attacks from multiple vectors and a  variety of actors has necessitated a multi-stakeholder response to  cyber-security that requires private sector involvement, both at the  policy and technical fields. This contribution has come in the recent  past not only through active involvement at the domestic levels but also  through norm-setting in the international arena.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;This symposium seeks to discuss the various cyber-security concerns in  the Indian private sector and maps initiatives being undertaken by  various actors towards furthering cyber-security in an attempt to  identify challenges, points of tension, brainstorm solutions-thereby  mapping the way forward through engagement not only with private sector  actors but also in dialogue with civil society and policy-makers. CIS  has undertaken some preliminary research in this area to further  discussion in this area and serve as a forum for sharing perspectives  for various stakeholders.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;The symposium will be divided into three sessions, broadly in the form  of a roundtable with different modus operandi in each session.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;A Concept Note for the event can be found &lt;a href="https://cis-india.org/internet-governance/concept-note-pvt-sector-cybersecurity-roundtable" class="internal-link" title="Concept Note: Pvt Sector Cybersecurity Roundtable"&gt;here&lt;/a&gt;, and the agenda can be found &lt;a href="https://cis-india.org/internet-governance/pvt-sector-cyber-security-agenda" class="internal-link" title="Pvt Sector Cyber-security Agenda"&gt;here&lt;/a&gt;. If you would like to attend, please rsvp pranav@cis-india.org, or register &lt;a class="external-link" href="https://goo.gl/forms/j3PSo56sdLyX8aNw2"&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;p style="text-align: justify;"&gt;&amp;nbsp;&lt;/p&gt;

        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/events/roundtable-on-cyber-security-and-the-private-sector'&gt;https://cis-india.org/internet-governance/events/roundtable-on-cyber-security-and-the-private-sector&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>pranav</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Cyber Security</dc:subject>
    
    
        <dc:subject>Event</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    

   <dc:date>2018-10-15T09:18:35Z</dc:date>
   <dc:type>Event</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/conceptualizing-an-international-security-regime-for-cyberspace">
    <title>Conceptualizing an International Security Regime for Cyberspace</title>
    <link>https://cis-india.org/internet-governance/blog/conceptualizing-an-international-security-regime-for-cyberspace</link>
    <description>
        &lt;b&gt;This paper was published as part of the Briefings from the Research and Advisory Group (RAG) of the Global Commission on the Stability of Cyberspace (GCSC) for the Full Commission Meeting held at Bratislava in 2018.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;Policy-makers often use past analogous situations to reshape questions and resolve dilemmas in current issues. However, without sufficient analysis of the present situation and the historical precedent being considered, the effectiveness of the analogy is limited.This applies across contexts, including cyber space. For example, there exists a body of literature, including The Tallinn Manual, which applies key aspects (structure, process, and techniques) of various international legal regimes regulating the global commons (air, sea, space and the environment) towards developing global norms for the governance of cyberspace.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Given the recent deadlock at the Group of Governmental Experts (GGE), owing to a clear ideological split among participating states, it is clear that consensus on the applicability of traditional international law norms drawn from other regimes, will not emerge if talks continue without a major overhaul of the present format of negotiations. The Achilles Heel of the GGE thus far has been a deracinated approach to the norms formulation process. There has been excessive focus on the content and the language of the applicable norm rather than the procedure underscoring its evolution, limited state and non state participation, and a lack of consideration for social, cultural, economic and strategic contexts through which norms emerge at the global level. Even if the GGE process became more inclusive and included all United Nations members, strategies preceding the negotiation process must be designed in a manner to facilitate consensus.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;There exists to date, no scholarship that traces the negotiation processes that lead to the forging of successful analogous universal regimes or an investigation into the nature of normative contestation that enabled the evolution of the core norms that shaped these regimes. To develop an effective global regime governing cyberspace, we must consider if and how existing international law or norms for other global commons might also apply to ‘cyberspace’, but also transcend this frame into more nuanced thinking around techniques and frameworks that have been successful in consensus building. This paper focuses on the latter and embarks on an assessment of how regimes universally maximized functional utility through global interactions and shaped legal and normative frameworks that resulted, for some time, at least, in  broad consensus.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;&lt;b&gt;&lt;a class="external-link" href="http://cis-india.org/internet-governance/files/gcsc-research-advisory-group.pdf"&gt;Click to read more&lt;/a&gt;&lt;/b&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/conceptualizing-an-international-security-regime-for-cyberspace'&gt;https://cis-india.org/internet-governance/blog/conceptualizing-an-international-security-regime-for-cyberspace&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Elonnai Hickok and Arindrajit Basu</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Cyber Security</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    

   <dc:date>2018-10-26T15:09:23Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/hindu-businessline-arindrajit-basu-october-30-2018-lessons-from-us-response-to-cyber-attacks">
    <title>Lessons from US response to cyber attacks</title>
    <link>https://cis-india.org/internet-governance/blog/hindu-businessline-arindrajit-basu-october-30-2018-lessons-from-us-response-to-cyber-attacks</link>
    <description>
        &lt;b&gt;Publicly attributing the attacks to a state or non-state actor is vital for building a credible cyber deterrence strategy.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article was published in &lt;a class="external-link" href="https://www.thehindubusinessline.com/opinion/lessons-from-us-response-to-cyber-attacks-ep/article25372326.ece"&gt;Hindu Businessline&lt;/a&gt; on October 30, 2018. The article was edited by Elonnai Hickok.&lt;/p&gt;
&lt;hr style="text-align: justify; " /&gt;
&lt;p style="text-align: justify; "&gt;In September, amidst the brewing of a new found cross-continental romance between Kim Jong-Un and Donald Trump, the US Department of Justice filed a criminal complaint indicting North Korean hacker Park Jin Hyok for playing a role in at least three massive cyber operations against the US. This included the Sony data breach of 2014; the Bangladesh bank heist of 2016 and the WannaCry ransomware attack in 2017. This indictment was followed by one on October 4, of seven officers in the GRU, Russia’s military agency, for “persistent and sophisticated computer intrusions.” Evidence adduced in support included forensic cyber evidence like similarities in lines of code or analysis of malware and other factual details regarding the relationship between the employers of the indicted individuals and the state in question.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;While it is unlikely that prosecutions will ensue, indicting  individuals responsible for cyber attacks offers an attractive option  for states looking to develop a credible cyber deterrence strategy.&lt;/p&gt;
&lt;h2 style="text-align: justify; "&gt;Attributing cyber attacks&lt;/h2&gt;
&lt;p style="text-align: justify; "&gt;Technical  uncertainty in attributing attacks to a specific actor has long  fettered states from adopting defensive or offensive measures in  response to an attack and garnering support from multilateral fora.  Cyber attacks are multi-stage, multi-step and multi-jurisdictional,  which complicates the attribution process and removes the attacker from  the infected networks.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Experts at the RAND Corporation have argued  that technical challenges to attribution should not detract from  international efforts to adopt a robust, integrated and  multi-disciplinary approach to attribution, which should be seen as a  political process operating in symbiosis with technical efforts. A  victim state must communicate its findings and supporting evidence to  the attacking state in a bid to apply political pressure.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Clear  publication of the attribution process becomes crucial as it furthers  public credibility in investigating authorities; enables information  exchange among security researchers and fosters deterrence by the  adversary and potential adversaries.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Although public attributions  need not take the form of a formal indictment and are often conducted  through statements by foreign ministries, a criminal indictment is more  legitimate as it needs to comply with the rigorous legal and evidentiary  standards required by the country’s legal system. Further, an  indictment allows for the attack to be conceptualised as a violation of  the rule of law in addition to being a geopolitical threat vector.&lt;/p&gt;
&lt;h2 style="text-align: justify; "&gt;Lessons for India&lt;/h2&gt;
&lt;p style="text-align: justify; "&gt;India  is yet to publicly attribute a cyber attack to any state or non-state  actor. This is surprising given that an overwhelming percentage of  attacks on Indian websites are perpetrated by foreign states or  non-state actors, with 35 per cent of attacks emanating from China, as  per a report by the Indian Computer Emergency Response Team (CERT-IN),  the national nodal agency under the Ministry of Electronics and  Information Technology (MEITY) which deals with cyber threats.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Along  with other bodies, such as the National Critical Information Protection  Centre (NCIIPC) which is the nodal central agency for the protection of  critical information infrastructure, CERT-IN forms part of an ecosystem  of nodal agencies designed to guarantee national cyber security.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;There  are three key lessons that policy makers involved in this ecosystem can  take away from the WannaCry attribution process and the Park  indictment. First, there is a need for multi-stakeholder collaboration  through sharing of research, joint investigations and combined  vulnerability identification among the various actors employed by the  government, law enforcement authorities and private cyber security  firms.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The affidavit suggested that the FBI had used information  from various law enforcement personnel, computer scientists at the FBI;  Mandiant — a cyber security firm retained by the US Attorney’s Office  and publicly available materials produced by cyber security companies.  Second, the standards of attribution need to demonstrate compliance both  with the evidentiary requirements of Indian criminal law and the  requirements in the International Law on State Responsibility. The  latter requires an attribution to demonstrate that a state had  ‘effective control’ over the non-state actor.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Finally, the  attribution must be communicated to the adversary in a manner that does  not risk military escalation. Despite the delicate timing of the  indictment, Park’s prosecution by the FBI did not dampen the temporary  thaw in relations between US and North Korea.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;While building  capacity to improve resilience, detect attacks and improve attribution  capabilities should be a priority, we need to remember that regardless  of the breakthrough in both human and infrastructural capacities,  attributing cyber attacks will never be an exercise in certainty.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;India  will need to marry its improved capacity with strategic geopolitical  posturing. Lengthy indictments may not deter all potential adversaries  but may be a tool in fostering a culture of accountability in  cyberspace.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/hindu-businessline-arindrajit-basu-october-30-2018-lessons-from-us-response-to-cyber-attacks'&gt;https://cis-india.org/internet-governance/blog/hindu-businessline-arindrajit-basu-october-30-2018-lessons-from-us-response-to-cyber-attacks&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Arindrajit Basu</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Cyber Security</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    

   <dc:date>2018-11-01T05:53:42Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/cis-cybersecurity-series-part-21-gyanak-tsering">
    <title>CIS Cybersecurity Series (Part 21) – Gyanak Tsering</title>
    <link>https://cis-india.org/internet-governance/blog/cis-cybersecurity-series-part-21-gyanak-tsering</link>
    <description>
        &lt;b&gt;CIS interviews Gyanak Tsering, Tibetan monk in exile, as part of the Cybersecurity Series.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;&lt;i&gt;“I have three mobile phones but I use only one to exchange information to and from Tibet. I don't give that number to anyone and nobody knows about it. High security forces me to use three phones. Usually a mobile phone can be tracked easily in many ways, especially by the network provider but my third mobile phone is not registered so that makes sure that the Chinese government cannot track me. The Chinese have a record of all mobile phone numbers and they can block them at anytime. But my third number cannot be traced and that allows me to communicate freely. This is only for security reasons so that my people in Tibet don't get into trouble.”&lt;/i&gt;&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Centre for Internet and Society presents its twenty-first installment of the CIS Cybersecurity Series.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The CIS Cybersecurity Series seeks to address hotly debated aspects of cybersecurity and hopes to encourage wider public discourse around the topic.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Gyanak Tsering is a Tibetan monk in exile, studying at Kirti Monastery, Dharamshala. He came to India in 1999, and has been using the internet and mobile phone technology, since 2008, to securely transfer information to and from Tibet. Tsering adds a new perspective to the cybersecurity debate and explains how his personal security is interlinked with internet security and mobile phone security.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Video&lt;/h3&gt;
&lt;table class="plain"&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;th&gt;&lt;iframe frameborder="0" height="315" src="http://www.youtube.com/embed/mqSw3cy7MEc?list=UUwD4YvZvns0xOedAnzt6CYA" width="560"&gt;&lt;/iframe&gt;&lt;/th&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p&gt;&lt;i&gt;This work was carried out as part of the Cyber Stewards Network with aid of a grant from the International Development Research Centre, Ottawa, Canada&lt;/i&gt;.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/cis-cybersecurity-series-part-21-gyanak-tsering'&gt;https://cis-india.org/internet-governance/blog/cis-cybersecurity-series-part-21-gyanak-tsering&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>purba</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Cyber Security</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Cyber Security Interview</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2014-09-06T05:08:44Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/news/cybersecurity-the-intersection-of-policy-and-technology">
    <title>Cybersecurity: The Intersection of Policy and Technology</title>
    <link>https://cis-india.org/internet-governance/news/cybersecurity-the-intersection-of-policy-and-technology</link>
    <description>
        &lt;b&gt;Sunil Abraham and Aayush Rathi attended a round-table on 'Cybersecurity: The Intersection of Policy and Technology'. The event was organised by Synergia Foundation, Bengaluru.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The speakers for the round-table were  Deborah Housen-Couriel, Professor at the Kennedy School of Government,  Gaurav Gupta - Principal Secretary for IT, BT, and S&amp;amp;T, Government of  Karnataka, and Dana Kursh, Consul General of Israel to South India.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The discussion at the round-table centred around developing approaches aimed at resolving the 'grand challenge' of cyber security. The role of deeper collaborations between various stakeholders such as academia, corporate enterprises, law enforcement and the government in arriving at cogent solutions was emphasised upon. For more on the discussion at the round-table, a press note can be found &lt;a class="external-link" href="https://www.synergiafoundation.in/news-analysis/cybersecurity-intersection-policy-technology"&gt;here&lt;/a&gt;.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/news/cybersecurity-the-intersection-of-policy-and-technology'&gt;https://cis-india.org/internet-governance/news/cybersecurity-the-intersection-of-policy-and-technology&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Admin</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Cyber Security</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    

   <dc:date>2018-03-25T03:24:23Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/files/cultivating-india2019s-cyber-defense-strategy">
    <title>Cultivating India’s Cyber Defense Strategy</title>
    <link>https://cis-india.org/internet-governance/files/cultivating-india2019s-cyber-defense-strategy</link>
    <description>
        &lt;b&gt;&lt;/b&gt;
        
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/files/cultivating-india2019s-cyber-defense-strategy'&gt;https://cis-india.org/internet-governance/files/cultivating-india2019s-cyber-defense-strategy&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Admin</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Cyber Security</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    

   <dc:date>2019-11-13T14:39:19Z</dc:date>
   <dc:type>File</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/draft-security-standards-for-the-financial-technology-sector-in-india">
    <title>Draft Security Standards for The Financial Technology Sector in India</title>
    <link>https://cis-india.org/internet-governance/blog/draft-security-standards-for-the-financial-technology-sector-in-india</link>
    <description>
        &lt;b&gt;Information security standards provide a framework for the secure development, implementation and maintenance of information systems and technology architecture. This document includes draft information security standards, which seek to ensure that not only the data of users is dealt with in a secure and safe manner but also that the smaller businesses in the fintech industry have a specific standard to look at in order to limit their liabilities for any future breaches.
&lt;/b&gt;
        
&lt;p id="docs-internal-guid-d14bad43-7fff-1d2b-c873-9850851b223a" dir="ltr"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p dir="ltr"&gt;By: &lt;strong&gt;Vipul Kharbanda&lt;/strong&gt;&lt;/p&gt;
with inputs from: &lt;strong&gt;Prem Sylvester
&lt;/strong&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;hr /&gt;
&lt;p id="docs-internal-guid-47476e0d-7fff-b341-0372-b39d8cd99bcb" style="text-align: justify;" dir="ltr"&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="text-align: justify;" dir="ltr"&gt;Information security standards provide a framework for the secure development, implementation and maintenance of information systems and technology architecture. Regulatory policies often cite several information security standards as a baseline that is to be complied with in order to ensure the adequate protection of information systems as well as associated architecture. Information security standards for the financial industry provide consideration to the specific risks and threats that financial institutions may face, making them an integral part of the process of ensuring business and operational sanctity.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style="text-align: justify;" dir="ltr"&gt;There is an urgent economic interest in ensuring robust security of the financial technology sector within the country. This interest is amplified considerably due to the policy push seeking to shift India towards the realisation of a ‘cashless society’. This recent policy push has in part led to the ubiquitous adoption of technology-centric financial services such as PayTM, PhonePe, Mobikwik and others. The current landscape with respect to security standards for financial institutions in India appears to be multi-pronged; with multiple standards in place for companies to implement.&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;br /&gt;&lt;strong&gt;The report can be accessed in full &lt;a href="https://cis-india.org/internet-governance/resources/security-standards-for-the-financial-technology-sector-in-india"&gt;here.&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;

        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/draft-security-standards-for-the-financial-technology-sector-in-india'&gt;https://cis-india.org/internet-governance/blog/draft-security-standards-for-the-financial-technology-sector-in-india&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Vipul Kharbanda</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Cyber Security</dc:subject>
    
    
        <dc:subject>Security Standards</dc:subject>
    
    
        <dc:subject>Financial Technology</dc:subject>
    

   <dc:date>2019-11-18T09:51:36Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/arindrajit-basu-gurshabad-grover-elonnai-hickok-january-22-2019-response-to-gcsc-on-request-for-consultation">
    <title>Response to GCSC on Request for Consultation: Norm Package Singapore</title>
    <link>https://cis-india.org/internet-governance/blog/arindrajit-basu-gurshabad-grover-elonnai-hickok-january-22-2019-response-to-gcsc-on-request-for-consultation</link>
    <description>
        &lt;b&gt;The GCSC opened a public comment procedure to solicit comments and obtain additional feedback. CIS responded to the public call-offering comments on all six norms and proposing two further norms.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The Global Commission on the Stability of Cyberspace, a multi-stakeholder initiative comprised of eminent individuals across the globe that seeks to promote awareness and understanding among the various cyberspace communities working on issues related to international cyber security. CIS is honoured to have contributed research to this initiative previously and commends the GCSC for the work done so far.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The GCSC &lt;a href="https://cyberstability.org/research/singapore_norm_package/"&gt;announced the release of its new Norm Package&lt;/a&gt; on Thursday November 8, 2018 that featured six norms that sought to promote the stability of cyberspace.This was done with the hope that they may be adopted by public and private actors in a bid to improve the international security architecture of cyberspace&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The norms introduced by the GCSC focus on the following areas:&lt;/p&gt;
&lt;ul style="text-align: justify; "&gt;
&lt;li&gt;Norm to Avoid Tampering&lt;/li&gt;
&lt;li&gt;Norm Against Commandeering of      ICT Devices into Botnets&lt;/li&gt;
&lt;li&gt;Norm for States to Create a      Vulnerability Equities Process&lt;/li&gt;
&lt;li&gt;Norm to Reduce and Mitigate      Significant Vulnerabilities&lt;/li&gt;
&lt;li&gt;Norm on Basic Cyber Hygiene as      Foundational Defense&lt;/li&gt;
&lt;li&gt;Norm Against Offensive Cyber      Operations by Non-State Actors&lt;/li&gt;
&lt;/ul&gt;
&lt;p style="text-align: justify; "&gt;The GCSC opened a public comment procedure to solicit comments and obtain additional feedback. CIS responded to the public call-offering comments on all six norms and proposing two further norms. We sincerely hope that the Commission may find the feedback useful in their upcoming deliberations.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;&lt;a href="https://cis-india.org/response-to-gcsc-on-request-for-consultation-norm-package-singapore/at_download/file"&gt;Read the full submission here&lt;/a&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/arindrajit-basu-gurshabad-grover-elonnai-hickok-january-22-2019-response-to-gcsc-on-request-for-consultation'&gt;https://cis-india.org/internet-governance/blog/arindrajit-basu-gurshabad-grover-elonnai-hickok-january-22-2019-response-to-gcsc-on-request-for-consultation&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>Arindrajit Basu, Gurshabad Grover and Elonnai Hickok</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Cyber Security</dc:subject>
    
    
        <dc:subject>International Relations</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    

   <dc:date>2019-01-27T15:43:12Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/indias-national-cyber-security-policy-in-review">
    <title>India's National Cyber Security Policy in Review</title>
    <link>https://cis-india.org/internet-governance/blog/indias-national-cyber-security-policy-in-review</link>
    <description>
        &lt;b&gt;Earlier this month, the Department of Electronics and Information Technology released India’s first National Cyber Security Policy. Years in the making, the Policy sets high goals for cyber security in India and covers a wide range of topics, from institutional frameworks for emergency response to indigenous capacity building.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;What the Policy achieves in breadth, however, it often lacks in depth. Vague, cursory language ultimately prevents the Policy from being anything more than an aspirational document. In order to translate the Policy’s goals into an effective strategy, a great deal more specificity and precision will be required.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;The Scope of National Cyber Security&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;Where such precision is most required is in &lt;i&gt;definitions&lt;/i&gt;. Having no legal force itself, the Policy arguably does not require the sort of legal precision one would expect of an act of Parliament, for example. Yet the Policy deals in terms plagued with ambiguity, &lt;i&gt;cyber security&lt;/i&gt; not the least among them. In forgoing basic definitions, the Policy fails to define its own scope, and as a result it proves remarkably broad and arguably unfocused.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The Policy’s preamble comes close to defining &lt;i&gt;cyber security&lt;/i&gt; in paragraph 5 when it refers to "cyber related incident[s] of national significance" involving "extensive damage to the information infrastructure or key assets…[threatening] lives, economy and national security." Here at least is a picture of cyber security on a national scale, a picture which would be quite familiar to Western policymakers: computer security practices "fundamental to both protecting government secrets and enabling national defence, in addition to protecting the critical infrastructures that permeate and drive the 21st century global economy."&lt;a href="#fn*" name="fr*"&gt;[*]&lt;/a&gt; The paragraph 5 definition of sorts becomes much broader, however, when individuals and businesses are introduced, and threats like identity theft are brought into the mix.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Here the Policy runs afoul of a common pitfall: conflating threats to the state or society writ large (e.g. cyber warfare, cyber espionage, cyber terrorism) with threats to businesses and individuals (e.g. fraud, identity theft). Although both sets of threats may be fairly described as cyber security threats, only the former is worthy of the term &lt;i&gt;national&lt;/i&gt; cyber security. The latter would be better characterized as cyber &lt;i&gt;crime&lt;/i&gt;. The distinction is an important one, lest cyber crime be “securitized,” or elevated to an issue of national security. National cyber security has already provided the justification for the much decried Central Monitoring System (CMS). Expanding the range of threats subsumed under this rubric may provide a pretext for further surveillance efforts on a national scale.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Apart from mission creep, this vague and overly broad conception of national cyber security risks overwhelming an as yet underdeveloped system with more responsibilities than it may be able to handle. Where cyber crime might be left up to the police, its inclusion alongside true national-level cyber security threats in the Policy suggests it may be handled by the new "nodal agency" mentioned in section IV. Thus clearer definitions would not only provide the Policy with a more focused scope, but they would also make for a more efficient distribution of already scarce resources.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;What It Get Right&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;Definitions aside, the Policy actually gets a lot of things right — at least as an aspirational document. It certainly covers plenty of ground, mentioning everything from information sharing to procedures for risk assessment / risk management to supply chain security to capacity building. It is a sketch of what could be a very comprehensive national cyber security strategy, but without more specifics, it is unlikely to reach its full potential. Overall, the Policy is much of what one might expect from a first draft, but certain elements stand out as worthy of special consideration.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;First and foremost, the Policy should be commended for its commitment to “[safeguarding] privacy of citizen’s data” (sic). Privacy is an integral component of cyber security, and in fact other states’ cyber security strategies have entire segments devoted specifically to privacy. India’s Policy stands to be more specific as to the &lt;i&gt;scope&lt;/i&gt; of these safeguards, however. Does the Policy aim primarily to safeguard data from criminals? Foreign agents? Could it go so far as to protect user data even from its &lt;i&gt;own&lt;/i&gt; agents? Indeed this commitment to privacy would appear at odds with the recently unveiled CMS. Rather than merely paying lip service to the concept of online privacy, the government would be well advised to pass &lt;a href="https://cis-india.org/internet-governance/blog/privacy-protection-bill-2013-with-amendments-based-on-public-feedback"&gt;legislation&lt;/a&gt; protecting citizens’ privacy and to use such legislation as the foundation for a more robust cyber security strategy.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The Policy also does well to advocate “fiscal schemes and incentives to encourage entities to install, strengthen and upgrade information infrastructure with respect to cyber security.” Though some have argued that such regulation would impose inordinate costs on private businesses, anyone with a cursory understanding of computer networks and microeconomics could tell you that “externalities in cybersecurity are so great that even the freest free market would fail”—to quote expert &lt;a href="http://www.schneier.com/blog/archives/2012/10/stoking_cyber_f.html"&gt;Bruce Schneier&lt;/a&gt;. In less academic terms, a network is only as strong as its weakest link. While it is true that many larger enterprises take cyber security quite seriously, small and medium-sized businesses either lack immediate incentives to invest in security (e.g. no shareholders to answer to) or more often lack the basic resources to do so. Some form of government transfer for cyber security related investments could thus go a long way toward shoring up the country’s overall security.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;The Policy also “[encourages] wider usage of Public Key Infrastructure (PKI) within Government for trusted communication and transactions.” It is surprising, however, that the Policy does not &lt;i&gt;mandate&lt;/i&gt; the usage of PKI. In general, the document provides relatively few details on what specific security practices operators of Critical Information Infrastructure (CII) can or should implement.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Where It Goes Wrong&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;One troubling aspect of the Policy is its ambiguous language with respect to acquisition policies and supply chain security in general. The Policy, for example, aims to “[mandate] security practices related to the design, &lt;i&gt;acquisition&lt;/i&gt;, development, use and operation of information resources” (emphasis added). Indeed, section VI, subsection A, paragraph 8 makes reference to the “procurement of indigenously manufactured ICT products,” presumably to the exclusion of imported goods. Although supply chain security must inevitably factor into overall cyber security concerns, such restrictive acquisition policies could not only deprive critical systems of potentially higher-quality alternatives but—depending on the implementation of these policies—could also &lt;a href="http://csis.org/blog/diffusion-and-discrimination-global-it-marketplace"&gt;sharpen the vulnerabilities&lt;/a&gt; of these systems.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Not only do these preferential acquisition policies risk mandating lower quality products, but it is unlikely they will be able to keep pace with the rapid pace of innovation in information technology. The United States provides a cautionary tale. The U.S. National Institute of Standards and Technology (NIST), tasked with producing cyber security standards for operators of critical infrastructure, &lt;a href="http://www.computerweekly.com/news/2240183045/NIST-revises-US-federal-cyber-security-standards"&gt;made its first update&lt;/a&gt; to a 2005 set of standards earlier this year. Other regulatory agencies, such as the Federal Energy Regulatory Commission (FERC) move at a marginally faster pace yet nevertheless are delayed by bureaucratic processes. FERC has already &lt;a href="http://www.tripwire.com/state-of-security/compliance/nerc-cip/nerc-cip-version-5-one-giant-leap/"&gt;moved to implement&lt;/a&gt; Version 5 of its Critical Infrastructure Protection (CIP) standards, nearly a year before the deadline for Version 4 compliance. The need for new standards thus outpaces the ability of industry to effectively implement them.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Fortunately, U.S. cyber security regulation has so-far been technology-neutral. Operators of Critical Information Infrastructure are required only to ensure certain functionalities and not to procure their hardware and software from any particular supplier. This principle ensures competition and thus security, allowing CII operators to take advantage of the most cutting-edge technologies regardless of name, model, etc. Technology neutrality does of course raise risks, such as those &lt;a href="http://www.businessweek.com/magazine/content/10_20/b4178036082613.htm"&gt;emphasized by the Government of India&lt;/a&gt; regarding Huawei and ZTE in 2010. Risk assessment must, however, remain focused on the technology in question and avoid politicization. India’s cyber security policy can be technology neutral as long as it follows one additional principle: &lt;i&gt;trust but verify&lt;/i&gt;.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Verification may be facilitated by the use of free and open-source software (FOSS). FOSS provides &lt;i&gt;security through transparency &lt;/i&gt;as opposed to &lt;i&gt;security through obscurity&lt;/i&gt; and thus enables more agile responses to security responses. Users can identify and patch bugs themselves, or otherwise take advantage of the broader user community for such fixes. Thus open-source software promotes security in much the same way that competitive markets do: by accepting a wide range of inputs.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Despite the virtues of FOSS, there are plenty of good reasons to run proprietary software, e.g. fitness for purpose, cost, and track record. Proprietary software makes verification somewhat more complicated but not impossible. Source code escrow agreements have recently gained some traction as a verification measure for proprietary software, even with companies like Huawei and ZTE. In 2010, the infamous Chinese telecommunications giants &lt;a href="http://www.ft.com/intl/cms/s/0/bd360448-7733-11e1-baf3-00144feab49a.html#axzz2ZUalpnWq"&gt;persuaded the Indian government&lt;/a&gt; to lift its earlier ban on their products by concluding just such an agreement.  Clearly&lt;i&gt; trust but verify&lt;/i&gt; is imminently practicable, and thus technology neutrality.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;What’s Missing&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;Level of detail aside, what is most conspicuously absent from the new Policy is any framework for institutional cooperation beyond 1) the designation of CERT-In “as a Nodal Agency for coordination of all efforts for cyber security emergency response and crisis management” and 2) the designation of the “National Critical Information Infrastructure Protection Centre (NCIIPC) to function as the nodal agency for critical information infrastructure protection in the country.” The Policy mentions additionally “a National nodal agency to coordinate all matters related to cyber security in the country, with clearly defined roles &amp;amp; responsibilities.” Some clarity with regard to roles and responsibilities would certainly be in order. Even among these three agencies—assuming they are all distinct—it is unclear who is to be responsible for what.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;More confusing still is the number of other pre-existing entities with cyber security responsibilities, in particular the National Technical Research Organization (NTRO), which in an earlier draft of the Policy was to have authority over the NCIIPC. The Ministry of Defense likewise has bolstered its cyber security and cyber warfare capabilities in recent years. Is it appropriate for these to play a role in securing civilian CII? Finally, the already infamous Central Monitoring System, justified predominantly on the very basis of cyber security, receives no mention at all. For a government that is only now releasing its first cyber security policy, India has developed a fairly robust set of institutions around this issue. It is disappointing that the Policy does not more fully address questions of roles and responsibilities among government entities.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Not only is there a lack of coordination among government cyber security entities, but there is no mention of how the public and private sectors are to cooperate on cyber security information—other than oblique references to “public-private partnerships.” Certainly there is a need for information sharing, which is currently facilitated in part by the sector-level CERTS. More interesting, however, is the question of liability for high-impact cyber attacks. To whom are private CII operators accountable in the event of disruptive cyber attacks on their systems? This legal ambiguity must necessarily be resolved in conjunction with the “fiscal schemes and incentives” also alluded to in the Policy in order to motivate strong cyber security practices among all CII operators and the public more broadly.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Next Steps&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;India’s inaugural National Cyber Security Policy is by and large a step in the right direction. It covers many of the most pressing issues in national cyber security and lays out a number of ambitious goals, ranging from capacity building to robust public-private partnerships. To realize these goals, the government will need a much more detailed roadmap.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Firstly, the extent of the government’s proposed privacy safeguards must be clarified and ideally backed by a separate piece of &lt;a href="https://cis-india.org/internet-governance/blog/privacy-protection-bill-2013-with-amendments-based-on-public-feedback" class="external-link"&gt;privacy legislation&lt;/a&gt;. As Benjamin Franklin once said, “Those who would give up essential Liberty, to purchase a little temporary Safety, deserve neither Liberty nor Safety.” When it comes to cyberspace, the Indian people must demand both liberty and safety.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Secondly, the government should avoid overly preferential acquisition policies and allow risk assessments to be technologically rather than politically driven. Procurement should moreover be technology-neutral. Open source software and source code escrow agreements can facilitate the verification measures that make technology neutrality work.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Finally, to translate this policy into a sound &lt;i&gt;strategy&lt;/i&gt; will necessarily require that India’s various means be directed toward specific ends. The Policy hints at organizational mapping with references to CERT-In and the NCIIPC, but the roles and responsibilities of other government agencies as well as the private sector remain underdetermined. Greater clarity on these points would improve inter-agency and public-private cooperation—and thus, one hopes, security—significantly.&lt;/p&gt;
&lt;div id="_mcePaste"&gt;
&lt;p class="MsoNormal" style="text-align:justify; "&gt;&lt;span&gt;Not only is there a lack of coordination among government cyber security entities, but there is no mention of how the public and private sectors are to cooperate on cyber security information—other than oblique references to “public-private partnerships.” Certainly there is a need for information sharing, which is currently facilitated in part by the sector-level CERTS. More interesting, however, is the question of liability for high-impact cyber attacks. To whom are private CII operators accountable in the event of disruptive cyber attacks on their systems? This legal ambiguity must necessarily be resolved in conjunction with the “fiscal schemes and incentives” also alluded to in the Policy in order to motivate strong cyber security practices among all CII operators and the public more broadly.&lt;/span&gt;&lt;/p&gt;
 &lt;/div&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;[&lt;a href="#fr*" name="fn*"&gt;*&lt;/a&gt;]. Melissa E. Hathaway and Alexander Klimburg, “Preliminary Considerations: On National Cyber Security” in &lt;i&gt;National Cyber Security Framework Manual&lt;/i&gt;, ed. Alexander Klimburg, (Tallinn, Estonia: Nato Cooperative Cyber Defence Centre of Excellence, 2012), 13&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/indias-national-cyber-security-policy-in-review'&gt;https://cis-india.org/internet-governance/blog/indias-national-cyber-security-policy-in-review&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>jon</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Cyber Security</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-07-31T10:40:22Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/saket-modi-calls-for-stronger-cyber-security-discussions">
    <title>'Ethical Hacker' Saket Modi Calls for Stronger Cyber Security Discussions</title>
    <link>https://cis-india.org/internet-governance/blog/saket-modi-calls-for-stronger-cyber-security-discussions</link>
    <description>
        &lt;b&gt;Twenty-two year old Saket Modi is the CEO and co-founder of Lucideus, a leading cyber security company in India which claims to have worked with 4 out of 5 top global e-commerce companies, 4 out of 10 top IT companies in the world, and 3 out of 5 top banks of the Asia Pacific. &lt;/b&gt;
        &lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;&lt;i&gt;This research was undertaken as part of the 'SAFEGUARDS' project that CIS is undertaking with Privacy International and IDRC&lt;/i&gt;&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;At the Confederation of Indian Industry (CII) conference on July 13, titled “&lt;a href="https://cis-india.org/internet-governance/blog/cii-conference-on-act" class="external-link"&gt;ACT – Achieving Cyber-Security Together&lt;/a&gt;,” Modi as the youngest speaker on the agenda delivered an impromptu talk which lambasted the weaknesses of modern cyber security discussions, enlightened the audience on modern capabilities and challenges of leading cyber security groups, and ultimately received a standing ovation from the crowd. As a later speaker commented, Modi’s controversial opinions and practitioner insight had "set the auditorium ablaze for the remainder of the evening". Since then the Centre for Internet and Society (CIS) has had the pleasure of interviewing Saket Modi over Skype.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;It is quite easy to find accounts of Saket Modi's introduction into hacking just by typing his name in the search engine. Faced with the pressure of failing, a teenage Saket discovered how to hack into his high school Chemistry teacher’s test and answer database. After successfully obtaining the answers, and revealing his wrong doings to his teacher, the young man grew intrigued by the possibilities of hacking. "I thought, if I could do this in a couple hours, four hours, then what might I be able to do in four days, four weeks, four months?"&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Nowadays, Modi describes himself and his Lucideus team as "ethical hackers", a term recently espoused by hacker groups in the public eye. As opposed to "hacktivists", who utilize hacking methods (including attacks) to achieve or bring awareness to political issues, ethical hackers claim to exclusively use their computer skills to support defenses. At first, incorporation of &lt;i&gt;ethics&lt;/i&gt; into a for-profit organization’s game plan may seem confusing, as it leaves room for key questions, like how does one determine which clients constitute ethical business? When asked, however, Modi clarifies by explaining how the ethics are not manifest in the entities Lucideus supports, but instead inherent in the choice of building defensive networks as opposed to using their skills for attack or debilitation. Nevertheless, considerations remain as to whether supporting the cyber security of some entities can lead to the insecurity of others, for example, strengthening the agencies which work in covert cyber espionage. On this point, Modi seems more ambivalent, saying "it depends on a case by case basis". But he still believes cyber security is a right that should be enjoyed by all, "entitled to [you] the moment you set foot on the internet".&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;As an experienced professional in the field who often gives input on major cyber policy decisions, Modi emphasizes the necessity of youth engagement in cyber security practice and policy. He calls his age bracket the “web generation,” those who have “grown with technology.” According to Modi, no one over 50 or 60 years of age can properly meet the current challenges of the cyber security realm. It is "a sad thing" that those older leaders carry the most power in policy making, and that they often have problems with both understanding and acceptability of modern technological capabilities. For the public, businesses, and also government, there are misconceptions about the importance of cyber security and the extent of modern cyber threats, threats which Modi and his company claim to combat regularly. "About 90 per cent of the crimes that take place in cyber space are because of lack of knowledge, rather than the expertise of the hacker,” he explains. Modi mentions a few basic misconceptions, as simple as, "if I have an anti-virus, my system is secured" or "if you have HTTPS certificate and SSL connection, your system is secured". “These are like wearing an elbow guard while playing cricket,” Modi tells. “If the ball comes at the elbow then you are protected, but what about the rest of the body?”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;This highlights another problem evident in India’s current cyber security scene, the problem of lacking “quality institutes to produce good cyber security experts.” For example, Modi takes offence at there not being “a single institute which is providing cyber security at the undergraduate level [in India].” He alludes to the recently unveiled National Cyber Security Policy, specifically the call for five lakh cyber security experts in upcoming years. He calls this “a big figure,” but agrees that there needs to be a lot more awareness throughout the nation. “You really have to change a lot of things,” he says, “in order to get the right things in the right place here in India.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;When considering citizen privacy in relation to cyber security, and the relationship between the two (be it direct or inverse), Saket Modi says the important factor is the governing body, because the issue ultimately resolves to trust. Citizens must trust the “right people with the right qualifications” to store and protect their sensitive data, and to respect privacy. Modi is no novice to the importance of personal data protection, and his company works with a plethora of extremely sensitive information relating to both their clients and their clients’ clients data, so it operates with due care lest it create a “wikileaks part two.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;On internationalization and cyber security, he views the connection between the two as natural, intrinsic. “Cyberspace has added a new dimension to humanity,” says Modi, and tells how former constructs of physical constraints and linear bounds no longer apply. International cooperation is especially pertinent, according to Modi, because the greatest challenge for catching today’s criminal hackers is their international anonymity, “the ability to jump from one country to the other in a matter of milliseconds.”&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;With the extent of the challenges facing cyber defense specialists, and with the somewhat disorderly current state of Indian cyber security, it is curious to see that Saket Modi has devoted himself to the "ethical" side of hacking. Why hasn’t he or the rest of the Lucideus team resorted to offensive hacking, since Modi claims the majority of cyber attacks of the world who are committed by people also fall between the ages of 15 and 24? Apparently, the answer is simple. “We believe in the need for ethical hacking,” he defends. “We believe in the purpose of making the internet safer.”&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/saket-modi-calls-for-stronger-cyber-security-discussions'&gt;https://cis-india.org/internet-governance/blog/saket-modi-calls-for-stronger-cyber-security-discussions&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>kovey</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Cyber Security</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2013-08-05T13:11:08Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/internet-governance/blog/cis-cybersecurity-series-part-10-lawrence-liang">
    <title>CIS Cybersecurity Series (Part 10) - Lawrence Liang</title>
    <link>https://cis-india.org/internet-governance/blog/cis-cybersecurity-series-part-10-lawrence-liang</link>
    <description>
        &lt;b&gt;CIS interviews Lawrence Liang, researcher and lawyer, and co-founder of Alternative Law Forum, Bangalore, as part of the Cybersecurity Series.&lt;/b&gt;
        
&lt;p&gt;&lt;em&gt;"The right to privacy and the right to free speech have often been understood as distinct rights. But I think in the ecology of online communication, it becomes crucial for us to look at the two as being inseparable. And this is not entirely new in India. But, interestingly, a lot of the cases that have had to deal with this question in the Indian context, have pitted one against the other. Now, India doesn't have a law for the protection of whistle-blowers. So how do we now think of the idea of whistle-blowers being one of the subjects of speech and privacy coming together? How do we use the strong pillars that have been established, in terms of a very rich tradition that Indian law has, on the recognition of free speech issues but slowly start incorporating questions of privacy?" - Lawrence Liang, researcher and lawyer, Alternative Law Forum.&amp;nbsp;&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Centre for Internet and Society presents its tenth installment of the CIS Cybersecurity Series.&amp;nbsp;&lt;/p&gt;
&lt;p&gt;The CIS Cybersecurity Series seeks to address hotly debated aspects of cybersecurity and hopes to encourage wider public discourse around the topic.&lt;/p&gt;
&lt;p&gt;Lawrence Liang is one of the co-founders of the Alternative Law Forum where he works on issues of intellectual property, censorship, and the intersection of law and culture. He is also a fellow with the Centre for Internet and Society and serves on its board.&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;iframe src="//www.youtube.com/embed/odQajlxcLLA" frameborder="0" height="315" width="420"&gt;&lt;/iframe&gt;
&lt;div&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;&lt;strong&gt;&lt;em&gt;This work was carried out as part of the Cyber Stewards Network with aid of a grant from the International Development Research Centre, Ottawa, Canada.&lt;/em&gt;&lt;/strong&gt;&lt;/div&gt;

        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/internet-governance/blog/cis-cybersecurity-series-part-10-lawrence-liang'&gt;https://cis-india.org/internet-governance/blog/cis-cybersecurity-series-part-10-lawrence-liang&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>purba</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Cybersecurity</dc:subject>
    
    
        <dc:subject>Cyber Security</dc:subject>
    
    
        <dc:subject>Cybercultures</dc:subject>
    
    
        <dc:subject>Cyber Security Interview</dc:subject>
    

   <dc:date>2013-09-10T08:31:31Z</dc:date>
   <dc:type>Blog Entry</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/news/consultation-to-frame-rules-under-whistle-blowers-protection-act-2011">
    <title>Consultation to Frame Rules under the Whistle Blowers Protection Act, 2011</title>
    <link>https://cis-india.org/news/consultation-to-frame-rules-under-whistle-blowers-protection-act-2011</link>
    <description>
        &lt;b&gt;The National Campaign for People's Right to Information (NCPRI) and Centre for Communication Governance at National Law University, Delhi (CCG at NLUD) invite you to a consultation to draft rules under the Whistle Blowers Protection Act, 2011. &lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The consultation will bring together various stakeholders to discuss the initial stages of framing the draft rules for the legislation. It will take place from 10:00 a.m. to 5:00 p.m. on July 5, 2014 at National Law University, Delhi. Bhairav Acharya will be participating in this event.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Click to download:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://cis-india.org/internet-governance/blog/consultation-to-frame-rules-under-whistle-blowers-protection-act-2014.pdf" class="internal-link"&gt;Consultation to Frame Rules under the Whistle Blowers Protection Act, 2014&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://cis-india.org/internet-governance/blog/whistle-blowers-protection-act-2014.pdf" class="internal-link"&gt;The Whistle Blowers Protection Act, 2014&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/news/consultation-to-frame-rules-under-whistle-blowers-protection-act-2011'&gt;https://cis-india.org/news/consultation-to-frame-rules-under-whistle-blowers-protection-act-2011&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Cyber Security</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    

   <dc:date>2014-07-02T08:03:55Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/news/the-hindu-business-line-july-2-2014-kv-kurmanath-cyber-crimes-shoot-up-in-india-over-last-year">
    <title>Cyber crimes shoot up 52% in India over last year</title>
    <link>https://cis-india.org/news/the-hindu-business-line-july-2-2014-kv-kurmanath-cyber-crimes-shoot-up-in-india-over-last-year</link>
    <description>
        &lt;b&gt;There has been a sharp increase in the incidence of cyber crime in the country. The number of cases registered in 2013 under the IT Act has gone up by 52 per cent to 4,192 as against 2,761 in the previous year. &lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;The article by K.V.Kurmanath was &lt;a class="external-link" href="http://www.thehindubusinessline.com/news/cyber-crimes-shoot-up-52-in-india-over-last-year/article6168812.ece?utm_source=RSS_Feed&amp;amp;utm_medium=RSS&amp;amp;utm_campaign=RSS_Syndication"&gt;published in the Hindu Businessline&lt;/a&gt; on July 2, 2014. Bhairav Acharya gave his inputs.&lt;/p&gt;
&lt;hr /&gt;
&lt;p style="text-align: justify; "&gt;If you add the cases registered under the IPC, the total number of cyber crime cases crosses the 5,500-mark. Police across the country arrested 3,301 persons in connection with these cases.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Maharashtra and Andhra Pradesh (undivided) have topped the list with 681 and 635 cases respectively under the IT Act, both showing an almost 50 per cent growth in cyber crimes over the previous year. In the previous year, Maharashtra had registered 471 and Andhra Pradesh 429.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Cyber security experts have been cautioning people to be careful while using the Internet. Besides increasing the security of the networks they are using, users must be careful while engaging with strangers.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;A recent Microsoft report said many customer infections involve users tricked to install secondary offers, indicating a shift in malware proliferation. According to the latest data provided by the National Crime Records Bureau, the official chronicler of crime in the country, cyber crime registered under the Indian Penal Code (IPC) has shown a much higher growth rate of 122 per cent in 2013 over the previous year’s figure. IPC cases went up to 1,316 in 2013 from 595 in the previous year. Maharashtra topped the list here too with the cops booking 226 cases in this category.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Wrong nomenclature?&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;Bhairav Acharya of the Centre for Internet and Society feels that the term cyber crime has not been defined well. “It is time we do away with the practice of calling any crime a ‘cyber crime’ just because the person who does it uses a computer,” he said.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;“Instead, I think the term ‘cyber crime’ should only be used in relation to offences that can only be committed by using information and communications technology (ICT) such as the internet (which is comprised of the world wide web, email protocols, file transfer protocols, and more) as well as network infrastructure that is not the internet,” he said.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Hence, only if there is a direct causal link between the crime and ICT and network technology should a crime be called a cyber crime, Acharya says.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Other States with a high number of cases booked under the IT Act include Karnataka (513), Kerala (349), Madhya Pradesh (282) and Rajasthan (239). Gujarat showed a decline with the number coming down to 61 from 68 in the previous year.&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/news/the-hindu-business-line-july-2-2014-kv-kurmanath-cyber-crimes-shoot-up-in-india-over-last-year'&gt;https://cis-india.org/news/the-hindu-business-line-july-2-2014-kv-kurmanath-cyber-crimes-shoot-up-in-india-over-last-year&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Cyber Security</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Social Media</dc:subject>
    

   <dc:date>2014-07-03T10:14:26Z</dc:date>
   <dc:type>News Item</dc:type>
   </item>


    <item rdf:about="https://cis-india.org/events/why-cyber-security-and-online-privacy-are-vital-for-success-of-democracy-and-freedom-of-expression">
    <title>Digital Citizens: Why Cyber Security and Online Privacy are Vital to the Success of Democracy and Freedom of Expression</title>
    <link>https://cis-india.org/events/why-cyber-security-and-online-privacy-are-vital-for-success-of-democracy-and-freedom-of-expression</link>
    <description>
        &lt;b&gt;Michael Oghia will give a presentation which will show why cyber security and online privacy are vital for democracy and freedom of expression.&lt;/b&gt;
        &lt;p style="text-align: justify; "&gt;In the time when Edward Snowden is fighting for both clemency and to be known as a brave whistle blower that exposed government wrongdoing, cyber security and online privacy have never been more important. As &lt;a class="external-link" href="https://www.youtube.com/watch?feature=player_embedded&amp;amp;v=H0I7wi3ZLG8&amp;amp;noredirect=1"&gt;Jacob Applebaum discussed in May last year&lt;/a&gt;, and CIS’ Maria Xynou &lt;a href="https://cis-india.org/internet-governance/events/big-democracy-big-surveillance-a-talk-by-maria-xynou" class="external-link"&gt;presented recently in December&lt;/a&gt;, surveillance throughout the world is increasing. With security apparatus’ likethe NSA and now India’s Central Monitoring System, coupled with corporate data centers around the world storing our e–mails, address books, preferences, and passwords, it is easy to see how our online privacy is increasingly being threatened and often, violated.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;Indeed, online privacy is inextricably linked to freedom of expression, and freedom of expression is a fundamental civil liberty imperative to democracy. Moreover, online security and privacy are essential to good, transparent, and accountable democratic governance. This is largely because surveillance, censorship, and monitoring ultimately create environments where self-censorship is the norm, as is the fear of the government instead of spaces that allow for freedom of expression and democratic dialogue and dissent.&lt;/p&gt;
&lt;p style="text-align: justify; "&gt;What I would like to accomplish my speaking at CIS is not to merely educate about the dangers posed to Internet security or to world democracy, but rather to:&lt;/p&gt;
&lt;ol&gt;
&lt;li style="text-align: justify; "&gt;Reiterate the importance of digital privacy and cyber security to the success of democracy and the continued protection of free expression.&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;Encourage citizens, technology specialists, Internet and privacy advocates, and others to see themselves as part of a larger system of democratic governance and civic participation. This means understanding how technical capabilities intersect with civil society, and then use them to advocate for a more open, accessible, and private cyberspace.&lt;/li&gt;
&lt;li style="text-align: justify; "&gt;Reinforce that digital media literacy education is vital to ensuring a free, open, accessible, and democratic Internet.&lt;/li&gt;
&lt;/ol&gt;
&lt;p style="text-align: justify; "&gt;Additionally, I want to present ideas and recommendations for what you can do to engage with these problems, and how we can collaborate together to address them.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;About the Public Intelligence Project&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;The Public Intelligence Project is an independent, non-partisan, not-for-profit think tank conducting research, education, and advocacy on the importance of diversity, critical thinking, dialogue, and freedom of expression. We seek to promote more robust systems of participatory democracy, civic engagement, and conflict prevention in order to create a culture of democracy.&lt;/p&gt;
&lt;h3 style="text-align: justify; "&gt;Michael Oghia&lt;/h3&gt;
&lt;p style="text-align: justify; "&gt;Michael is responsible for a new project at Meta-Culture called the Public Intelligence Project, which focuses on expanding participatory democracy, civic engagement, and conflict prevention by conducting research, education, and advocacy on the intersections between diversity, dialogue, critical thinking, and freedom of expression. While new to the conflict resolution field, as a poet, musician, editor, writer, blogger, and activist, he is well-versed in the importance of freedom of expression and participating in the democratic process. He was born in Kentucky to Lebanese-Syrian parents, and after graduating with a BS in sociology from the University of Louisville, he moved to Lebanon to pursue an MA in sociology from the American University of Beirut. There, he had the opportunity to witness the Arab Revolutions first-hand while research about topics such as Internet ownership in the Middle East, social movements, Arab media, globalization, Arab youth and family, and his thesis subject, romantic love in the Arab world. Michael enjoys engaging Twitter conversations, and has an unnatural affinity for crunchy peanut butter.&lt;/p&gt;
&lt;hr /&gt;
&lt;p&gt;Date: Tuesday, January 14, 2014&lt;br /&gt;Time: 6.30 p.m. to 8.00 p.m.&lt;br /&gt;Talk by: Michael Oghia&lt;br /&gt;Title: Research &amp;amp; Advocacy Consultant, and Project Manager&lt;br /&gt;Organisation: Meta-Culture / Public Intelligence Project&lt;br /&gt;Websites: &lt;a class="moz-txt-link-abbreviated" href="http://www.meta-culture.in"&gt;www.meta-culture.in&lt;/a&gt; &lt;a class="moz-txt-link-rfc2396E" href="http://www.meta-culture.in"&gt;&amp;lt;http://www.meta-culture.in&amp;gt;&lt;/a&gt; &amp;amp; &lt;a class="moz-txt-link-abbreviated" href="http://www.publicintelligenceproject.org"&gt;www.publicintelligenceproject.org&lt;/a&gt; &lt;a class="moz-txt-link-rfc2396E" href="http://www.publicintelligenceproject.org"&gt;&amp;lt;http://www.publicintelligenceproject.org&amp;gt;&lt;/a&gt;&lt;/p&gt;
        &lt;p&gt;
        For more details visit &lt;a href='https://cis-india.org/events/why-cyber-security-and-online-privacy-are-vital-for-success-of-democracy-and-freedom-of-expression'&gt;https://cis-india.org/events/why-cyber-security-and-online-privacy-are-vital-for-success-of-democracy-and-freedom-of-expression&lt;/a&gt;
        &lt;/p&gt;
    </description>
    <dc:publisher>No publisher</dc:publisher>
    <dc:creator>praskrishna</dc:creator>
    <dc:rights></dc:rights>

    
        <dc:subject>Social Media</dc:subject>
    
    
        <dc:subject>Privacy</dc:subject>
    
    
        <dc:subject>Internet Governance</dc:subject>
    
    
        <dc:subject>Cyber Security</dc:subject>
    
    
        <dc:subject>Event</dc:subject>
    

   <dc:date>2014-01-08T04:59:10Z</dc:date>
   <dc:type>Event</dc:type>
   </item>




</rdf:RDF>
