Contingency Management Plan
Mission SAMARTH website has been placed in protected zones with implementation of firewalls and IDS (Intrusion Detection System) and high availability solutions.
(i) Defacement Protection
- Mission SAMARTH website is audited for protection against Security & Performance degradation.
- Any application level modification on the website requires re-audit.
- All the server configuration and logs are monitored timely.
- Only System administrator users are allowed to access the servers for doing administration and configuration tasks.
- All the backend servers are under lock and net secured.
- Contents are updated through a secure FTP using VPN.
(ii) Monitoring
There are two ways of monitoring of defacement of Mission SAMARTH website.
- Cyber security division monitors by analyzing the log files.
- Website Monitoring Team also monitors the website after interval of every month for possible defacement or undesirable change in the website. (in case the site has a dedicated monitoring team)
(iii) Defacement Response Plan
In case of any eventuality who ever notices the defacement (either Website Monitoring Team or Cyber Security) informs the Web Information Manager on phone as well as through mail. NIC Cyber Security Division or Help Desk also informs the Administrator of website on telephone and also by mail.
As soon as the website Server Administrator gets the information regarding the defacement, s/he takes the following steps.
- According to the degree of defacement, the site is stopped or continued partially.
- Log files are analyzed to troubleshoot the source of defacement and blocking of the service.
- Type of the defacement is analyzed and fixed.
- The Portal Service is started from DR site in case of complete loss of data or during long downtime.
- Log files are given to security division for analysis.
- Based on security recommendation, all vulnerability is fixed and the application is re-audited.
- The affected/corrupted content and the site are restored from the backup.
Time for Restoration after defacement
The time taken for restoration of depends on the degree of defacement and services affected by the defacement. Ideally it will take 6 to 12 Hrs. for the restoration.
(iv) Natural Calamity Response Plan
There could be circumstances whereby due to some natural calamity (it may due to any reason that is beyond control of any person), the entire data centre where the website has been hosted gets destroyed or ceases to exist. In such case first of all the In-charge of National Data Centre will declare the natural calamity and would instruct the sites to be started from the DR site, which is located at New Delhi.