INDIA Law and Practice Contributed by: Anoop Narayanan, Priyanka Gupta and Harshita Sakarya, ANA Law Group
• PCI-DSS standards; • Open Source Security Testing Methodology Manual; and • OWASP Testing Guide. As regards the insurance sector, the IRDAI also has a cybersecurity policy requiring vulnerability assess - ment and penetration testing annually and closing any identified high-risk gaps within a month. The RBI also mandates banks to have periodical vulnerability assessment and penetration testing exercises for all critical systems. Further, the DPDPA requires SDFs to undertake measures including data protection impact assess - ment and periodic audits. The Data Protection Impact Assessment (DPIA) is defined as a process comprising description, purpose, assessment of harm, measures for managing the risk of harm and such other matters concerning the processing of personal data, as may be prescribed. India currently does not have comprehensive spe - cific legislation governing cyber-resilience. However, cyber-resilience obligations are dispersed across sec - tor-specific laws, regulations and binding directions issued under the IT Act. Under the NCIIPC Rules and Guidelines, operators of CII are required to implement security-by-design prin - ciples, including robust access controls, encryption, system hardening, continuous monitoring and secure software development practices for systems that sup - port essential services. Sectoral regulators, such as the RBI, SEBI and IRDAI, also issue guidance requiring banks, financial insti - tutions and insurers to implement resilience meas - ures for ICT products and services, including vendor risk management, business continuity, and incident response controls. For instance, the Telecommunication Cyber Security (TCS) Rules, 2024 aim to strengthen cyber-resilience 4. Cyber-Resilience 4.1 Cyber-Resilience Legislation
through collaborative mechanisms with entities using telecoms identifiers. It requires certain entities such as banks, e-commerce platforms and apps to verify user numbers against a government platform and share telecoms-identifier data with the government in spe - cific circumstances. Overall, India’s approach is largely risk and sector- based, comprised of legally binding rules, sectoral guidance and mandatory directions from nodal agen - cies, rather than a single codified cyber-resilience statute. Compliance is enforced through supervisory oversight, audits and mandatory reporting to authori - ties such as CERT-In, NCIIPC and sectoral regulators. 4.2 Key Obligations Under Legislation Please refer to 4.1 Cyber-Resilience Legislation . 5. Security Certification for ICT Products, Services and Processes 5.1 Key Cybersecurity Certification Legislation The current legal framework in India does not provide for a dedicated statutory regime mandating cyberse - curity certification for ICT products, services or pro - cesses on a horizontal basis. However, India is a participant in the Common Crite - ria Recognition Arrangement (CCRA) and recognises Common Criteria (CC) certifications for IT products. The Indian Common Criteria Certification Scheme (IC3S) has been established by MeitY as part of the government’s cybersecurity assurance initiatives. The objective of the IC3S is to evaluate and certify IT secu - rity products and Protection Profiles (PPs) against the requirements of the Common Criteria standards, at assurance levels ranging from EAL 1 to EAL 4. The IC3S provides national certification under an international mutual recognition arrangement with other CCRA member countries, ensuring that certifi - cations issued under IC3S are acceptable across all CCRA member jurisdictions. Additionally, the SPDI Rules prescribe ISO/IEC 27001 as one of the standards recommended to be imple -
202 CHAMBERS.COM
Powered by FlippingBook