SAMARTH- Sustainable Agrarian Mission on use of Agri-Residue in Thermal Power Plants


NATIONAL MISSION ON USE OF BIOMASS IN THERMAL POWER PLANTS

Security Policy

  • National Biomass Mission website has been placed in protected zones with implementation of firewalls and IDS (Intrusion Detection System) and high availability solutions.
  • Before launch of the website, simulated penetration tests have been conducted.
  • Penetration testing has also been conducted 3 times after the launch of the website.
  • Website has been audited for known application level vulnerabilities before the launch and all the known vulnerability has been addressed.
  • Hardening of servers has been done as per the guideline of Cyber Security division before the launch of the website.
  • Access to web servers hosting the website is restricted both physically and through the network as far as possible.
  • Logs at 2 different locations are maintained for authorized physical access of website servers.
  • Web-servers hosting the website are configured behind IDS, IPS (Intrusion Prevention System) and with system firewalls on them.
  • All the development work is done on separate development environment and is well tested on staging server before updating it on the production server.
  • After testing properly on the staging server the applications are uploaded to the production server using SSH and VPN through a single point.
  • The content contributed by/from remote locations is duly authenticated & is not published on the production server directly. Any content contributed has to go through the moderation process before final publishing to the production server.
  • All contents of the web pages are checked for intentional or unintentional malicious content before final upload to web server pages.
  • Audit and Log of all activities involving the operating system, access to the system, and access to applications are maintained and archived. All rejected accesses and services are logged and listed in exception reports for further scrutiny.
  • Help Desk staff monitor the website at intervals of 1 week to check the web pages to confirm that the web pages are up and running, that no unauthorized changes have been made, and that no unauthorized links have been established.
  • All newly released system software patches; bug fixes and upgrades are expediently and regularly reviewed and installed on the web server.
  • On Production web servers, Internet browsing, mail and any other desktop applications are disabled. Only server administration related task is performed.
  • Server passwords are changed at the interval of 3 months.
  • NBM website has been re-audited for the application level vulnerability after major modification in application development [Not applicable at first launch].