惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Google DeepMind News
Google DeepMind News
U
Unit 42
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
J
Java Code Geeks
D
DataBreaches.Net
B
Blog RSS Feed
D
Docker
L
LangChain Blog
aimingoo的专栏
aimingoo的专栏
F
Fortinet All Blogs
Y
Y Combinator Blog
A
About on SuperTechFans
V
V2EX
罗磊的独立博客
WordPress大学
WordPress大学
宝玉的分享
宝玉的分享
MongoDB | Blog
MongoDB | Blog
博客园 - 【当耐特】
Last Week in AI
Last Week in AI
S
SegmentFault 最新的问题
月光博客
月光博客
Vercel News
Vercel News
H
Hackread – Cybersecurity News, Data Breaches, AI and More
阮一峰的网络日志
阮一峰的网络日志

ashishb.net

A day in Luxembourg - the richest country in the world I was asked to install malware during a fake interview Book summary: Breakneck - China's quest to engineer the future by Dan Wang Book summary: How to Teach Your Baby to Read Book Summary: The Discontented Little Baby Book by Pamela Douglas Introducing Amazing Sandbox - run third-party tools and AI agents securely on your machine Why software outsourcing gets a bad reputation? Book summary: The Natural Baby Sleep Solution by Polly Moore A day in Antwerp, Belgium Journey of online influencers Two days in Brussels, Belgium Shortcuts - when we love them and when we don't A visit to Rakhigarhi Three days in overhyped Paris Empty Japan, crowded Tokyo The real lock-in in GitHub is not the code, but the stars 11-day Norwegian Breakaway East Caribbean cruise Sanskrit and Sri Lankan Air Force Use REST with Open API The Achilles heel of American capitalism Costa Rica in 4 days At a juice stall in Sri Lanka A short stay at Warsaw, Poland Best practices for using Python & uv inside Docker Two days in Vilnius, Lithuania How IntelliJ IDEs waste disk space Pregnancy Why there aren't many digital nomads from India Two days in Riga, Latvia To keep your machine secure, run third-party tools inside Docker
Cyber Security in India : Role of CERT-In
Ashish Bhatia · 2010-09-28 · via ashishb.net

CERT-In is a low-profile (Indian) government organization.

The Government of India established the Computer Emergency Response Team (“CERT-IN”) to ensure Internet security. Many institutions, including the Ministry of Home Affairs, courts, the intelligence services, the police, and the National Human Rights Commission, may call on it for specialist expertise. CERT-IN’s stated mission is “to enhance the security of India’s Communications and Information Infrastructure through proactive action and effective collaboration” [ Source]

I had a chance to visit CERT-In last week. The experience was overall good, unlike the typical dirty government office with laid-back employees, I saw employees enthusiastic about their work (and a colorful office).

As I understood the primary job of CERT-In is to

  1. raise awareness (among public sector and private sector) regarding system and network security through regular training sessions.
  2. provide help during website defacements
  3. release regular security bulletins to keep Indian (security) community on recent threats and attacks

I met a few employees there and the key things which came out of the discussion are

  1. Cert-In is too small as compared to Cert-US due to budget constraints (and hence employees are over-burdened).
  2. They do not offer “government job”[read job security], just a contract-based employment.
  3. They do not offer a competitive pay hence people regularly move to take jobs in private sector.

A view at the CERT-In defacement statistics show how grave is this threat for India. At this crucial stage, when apart from air, water and land, internet is the new way of inflicting significant monetary damage as well as intelligence. When other countries are establishing new cyber defensive and offensive capabilities, I wonder when will the Indian government realize that rather than spending billions on establishing new IITs, its probably better to spend a fraction of that to hire good cyber security specialists. Readers should note that unlike USA, Cert-In has to play a much bigger role in India due to lack of other equivalents organizations like DHS cyber command (USA).

Disclaimer: _The article is based on the personal experience of the author and the claims made are not verified independently. In case you have any objections, please mention that in comments.