Indian Regulatory bodies such as the Indian Computer Emergency Response Team (CERT-In), the National Critical Information Infrastructure Protection Center (NCIIPC), the Insurance Regulatory and Development Authority of India (IRDAI), and the Stock and Exchange Board of India (SEBI) protect critical information infrastructure, address issues related to cybersecurity incidents, regulate the insurance, and securities markets, respectively.
CERT-In
The Indian Computer Emergency Response Team (CERT-In) which falls under the Ministry of Electronics and Information Technology has prepared Guidelines on Information Security Practices for Government Entities that applies for secretariats, ministries, public sector units, etc. This national agency has been authorized under the Section 70B of the Information Technology Act 2000 (IT Act 2000).
It has a significant responsibility regarding issues that concern cyber security events as well as basic activities like predicting events, coordinating responses, issuing advisories, etc. It also encompasses guidance found in section 7. 2 of the official documents, which states that secure data erasure practices for the complete media sanitization of removable media to minimize or eliminate risk of data leakage. Proof of compliance must be created in the form of a detailed log of data erasure activities.
NCIIPC
The National Critical Information Infrastructure Protection Center (NCIIPC) is a part of the National Technical Research Organization (NTRO) that is designated as the national nodal agency for protection of Critical Information Infrastructure (CII) in sectors like banking, telecommunications, govt., power and energy, etc. The term CII is defined in the IT Act 2000 as, “the computer resource, the incapacitation or destruction of which, shall have debilitating impact on economy, national security, public health or safety.”
For protection of the CII, the NCIIPC has formulated guidelines to prevent unauthorized access, modification, usage, and destruction, and ensure the safety of information in critical sectors of the country. These guidelines have been classified into five families: Planning, Implementation, Operational, Disaster Recovery/Business Continuity Planning (BCP), and Reporting and Accounting Controls.
Operational Controls covers subjects such as data storage, incident response, data loss prevention, asset and inventory management, network and cloud protection, etc. Under OC 9 - Critical Information Disposal and Transfer, Section 8.9.2, NCIIPC lays down protocols for transfer and disposal of information covering storage media from files, paper, HDDs, SSDs, servers, to mobile devices.
It further emphasizes that improper implementation or absence of operational controls can jeopardize the safety of information. Three methods, namely, physical destruction, degaussing, and cleaning are suggested to dispose of storage media. Cleaning is also known as data wiping. It means overwriting data using a software-based tool instead of employing the simple ‘delete’ function that does not perform complete erasure. Physical destruction involves burning, shredding, or pulverizing storage media. Degaussing refers to wiping information stored on magnetic tapes.
Section 8.9.3 (a-g) lists essential practices for secure media transfer and disposal. It requires the drafting and enforcement of policies as approved by management detailing administrative and technical guidelines. Periodic reviews and regular audits must be done by senior employees, led by the CISO to ensure compliance. Proper logs for media transfers and disposals must be maintained along with gate pass approvals for media leaving the premises, with updates in the inventory control management system. Returned media should be securely stored in fireproof storage until policies are enforced. Additionally, a clear desk policy should be maintained.
IRDAI
The statutory body, the Insurance Regulatory and Development Authority of India (IRDAI) is responsible for regulating the insurance sector in India. With the rise of digital insurance solutions, voluminous, sensitive, personal, health and financial data has grown exponentially making it important for IRDAI to follow strict guidelines and policies to protect critical data in the insurance sector. The guidelines in the IRDAI’s Organization’s Information and Cyber Security Policy (ICSP) aim to reduce the risks of intentional and unintentional disclosure, modification, misuse, delay, or destruction of information assets. Information assets refer to information stored in verbal, printed, written, electronic, etc. form. From paper, data, network equipment, and storage media to PCs and laptops – all are considered information assets. The policy is applicable to information assets throughout their lifecycles, from creation to disposal. Further, people are also considered information assets. By people, IRDAI’s policy means service providers, vendors, distributors, and customers handling critical information.
IRDAI’s Section 3.4, Lifecycle Processes of Policy 2.1, elaborates on classifying data, labelling, storage, transfer, tracking, and disposal requirements of Confidential Information, Restricted Information, Internal Use Only Information, and Public Information, in that order. The disposal requirements for all these types of information are explained below:
- For Confidential Information: Section 3.4.1.5 states that after the retention period gets over, and at the release of an audit or a litigation, information should be destroyed securely. In addition, sensitive data or systems that need to be occasionally accessed should be removed from the network, unplugged from a power source, or completely virtualized, and used as standalone systems.
- For Restricted Information: Section 3.4.2.5 mentions that data along with their copies and backups must be destroyed securely after the retention period gets over, and at the release of an audit or a litigation.
- For Internal Use Only and Public Information: Section 3.4.3.4 and Section 3.4.4.4 specify that after the retention period gets over, and at the release of an audit or a litigation, information should be disposed of securely.
Under IRDAI guidelines, Section 3.2.6 of Policy 2.2, Asset Management covers the subject of asset disposal. It explains that a process regarding media formatting needs to be established and the finance department must be informed when an asset is supposed to be disposed of. The section highlights:
- Three methods should be employed to securely dispose of sensitive and critical information: shredding, incineration, or data erasure.
- Before employing secure erase or any other disposal technique approved by the management, the information should be removed from the equipment.
- A record of disposed or scrapped assets should be maintained in a register.
- Only after approval from the CTO and CFO, should the elements of critical infrastructure be disposed of.
- The assets can be disposed of only on two conditions:
- if the asset is not suitable for the environment
- if the asset has reached the end of its life
- A risk assessment is required to determine whether damaged devices with sensitive information need to be sent for repair or physically destroyed.
SEBI
The Stock and Exchange Board of India (SEBI) is the statutory body responsible for regulating the securities market and protecting the investors’ interests. Institutions such as depositories, and stock exchanges are known as Market Infrastructure Institutions (MII). Since these institutions are part of operational risk management, they provide necessary infrastructure for the continuous functioning of the securities market. Apart from consistent improvement in IT processes, it is essential for MIIs (stock exchanges, depositories, and clearing corporations) to have a strong cybersecurity posture.
The High Steering Committee on Cyber Security of SEBI, after consultation with MIIs, recommends compliance with guidelines placed at Annexure-A, for improvement in cyber security and cyber resilience. To protect confidentiality, integrity, and availability (CIA) of data, these guidelines include several measures such as taking regular encrypted backups, employing multifactor authentication (MFA), conducting vulnerability scanning, and training employees to identify phishing attempts.
SEBI recommends implementing the advisories issued by NCIIPC or CERT-In. MIIs should therefore implement the standard operating procedure (SoP) of the two regulatory bodies in terms of data disposal and data erasure practices in their IT environment within a clear time period.
Way Forward to Comply with Indian Regulatory Bodies
To protect critical information from getting compromised, it is advised for businesses operating in India to follow the below suggestive practices and remain compliant with not only regulatory bodies but also the Digital Personal Data Protection Act (DPDPA):
- Form and implement policies on safe transfer and disposal of storage media.
- Back up data before disposing of the storage media.
- Store critical, sensitive, and restricted information in an encrypted manner, in a fire-safe space.
- Conduct regular audits to verify the proper implementation of information security policies.
- Salvage damaged devices by repairing them instead of physically destroying them after conducting a risk assessment.
- Dispose of critical information securely by degaussing, shredding, or wiping. Data wiping is a preferred choice for storage media devices that cannot be degaussed, like SSDs.
To wipe information, apply secure erase or a safe wiping method approved by the management. BitRaser Data Eraser software is a certified data wiping tool that employs secure erase (SE) to erase information beyond recovery. By generating detailed reports of the entire erasure process, it helps verify audit trails and remain compliant with laws like DPDPA, EU-GDPR, etc.