Chai pe Charcha – New Delhi 13 Aug 2017
Topic for Discussion – Cyber tryst – cyber security hopes and fears on our 71st I’Day
an unplugged watch on the goings on in India in the cyber domain – comprising our comments, views and thoughts for the country.
Topic for Discussion – Cyber tryst – cyber security hopes and fears on our 71st I’Day
Sometime back we did a quick survey asking infosec people about their expectations from CERT-In and we got a number of inputs. This is being shared here and this is the first in the series, covering Bug Bounty and Internships. The follow up blogs will address issues like audit, responsibility, guidance, certification etc – keep watching!
While there were all signs of a potential riot with thousands of people congregating in Panchkula, the administration and Police did nothing to preempt the situation – this is a shame! Now, as we write this blog, 30 ppl are dead and hundreds are injured!
Every Cyber / Information Security professional carries a smorgasbord of alphabets after his/her name as evidence of skills and knowledge tested and certified by known and unknown organizations…. Indians are among the trainers but the certifications are not! The time has come..
The discussion for the day were on the subject of “Incorporation of private talent for making India cyber war ready”
There are all types of initiatives to manage and address cyber threats and risks, and they don’t seem to be effective (considering the panic that even a website defacement can create). It is apparent we are doing something wrong and it is time to sit back and take a hard look at the path traversed and (high time) make a course correction. We at IW, proposed a Central Command!
Public advisories issued by banks to the poor defrauded and at the same time they sit in their high offices doling out crores to their favorite NRI scamsters without a care for the small victims. High time the bank change their outlook towards the average account holder, relook at their security and risk management… and finally stop trying to own the money which belongs to someone else.
CpC meetings are attended by IS professionals who catch up in informally to discuss / brainstorm on current events / incidents, and upcoming risks / threats in the cybersecurity domain. Mumbai and Delhi meets in April and May
So Hitachi Payment Systems came out with an Admission of Compromise (AoC) that they had a data breach which (possibly) led to the Great Indian Debit Card Security Disaster of October2016 . Please note that we want to avoid the use of the word “hack” because people are associating it with malicious intent (or action) whereas…
For a long time cyber security experts have prescribed Information Sharing as an important practice and apparently the Government talked about this in 2006 <WOW> They call it an Information Sharing and Analysis Center (ISAC) but who is sharing and who is not! Now in 2016, some one or the other keeps talking about it,…