Strategy 2020
•
Adopt a risk-based approach by promoting the development of lightweight, agile, and
dynamism mechanism for product testing that can co-exist with well-established schemes
like common-criteria
•
Promote and incentivize the public and private investment in testing labs and infrastructure
and skill development that can serve both domestic and export market requirements
•
Leverage the country's leadership in semiconductor design, ERnD (Engineering Research
and Design) and emerging destination for deep-tech innovation for driving supply-chain
security agenda globally at strategic, tactical and technical levels
Critical Information Infrastructure Protection: The increased focus of cyberattacks,
systematically planned and executed by non-state as well as state actors, to the target CII sectors
causing more substantial or kinetic impact, demand concerted and smart strategies.
•
The focus of the efforts for CII protection should be to ensure the delivery of essential
services even in the time of the attack, assuring the economic growth, and promising safety
of the citizens
•
Empowering security leadership, ensuring adequate resources with it, and making it
independent from routine ICT and business operations. Moreover, by devising specific
responsibility for the SCADA/OT security and integrating with enterprise security.
•
Developing regulatory capabilities, wherever possible, that would further development of
more contextual and objective norms and guidance
•
Augmenting the due diligence to draw technology profile of the CII sectors by closely
monitoring the digitization and technology adoption, evaluating devices and solutions
planned to deploy for the security, and maintaining a repository of vulnerabilities and
exploits likely to affect them
•
Harmonizing national security efforts to make the compliance more productive and effective
for the organizations falling in the CII
•
Adopting differentiated approaches that cater to specific requirements of the plant, transport,
distribution, and retail deployment of SCADA/OT solutions to ensure risk-based treatment,
specific solutions, and ensure proportionate actions at the desired level
•
Mandating a security-by-design culture in the technical transformation, however, facilitating
that with investing in the aggregate level efforts of security evaluation and testing devices,
issuing guidance and directives, and by notifying reference architectures
•
Promotion of innovation and co-creation for the development of SCADA/OT security
solutions by incentivizing user enterprises, providing funding support to the start-ups and
incubators working in the area, and creating a conducive environment for commercialization
of the research work
A NASSCOM® Initiative