Showing posts with label NATIONAL SECURITY OF INDIA. Show all posts
Showing posts with label NATIONAL SECURITY OF INDIA. Show all posts

Thursday, July 29, 2010

Cyber Security In India Needs Rejuvenation

Cyber security in India needs good political, public and policy support. Issues like cyber law, cyber terrorism, cyber crimes, cyber espionage, cyber war, etc have been long neglected by India. This is detrimental to national security of India and internal security of India.

Strategic information plays a crucial role in launching an attack as well as preventing the same. Similarly, sensitive information in the hands of enemy, cyber terrorists, etc may also not be good for India.

Critical ICT infrastructure protection (CIIP) in India also necessitates that India must pay enough attention to cyber security issues. The Home Ministry, India is stressing too much upon issues like diluting encryption standards of Blackberry, a product of research in motion, e-surveillance of e-mails, telephone tapping capabilities, national intelligence grid (Natgrid), etc.

All these projects would prove to be landmines for India in the absence of proper laws and effective cyber security. Take the example of unique identification project of India (UID Project of India) or Aadhar project of India. It is managed by Nandan Nilekani as the chairman of unique identification authority of India (UIDAI). It would collect crucial biometric information and other details of Indians without any law that protects it from illegal data thefts, privacy breaches, etc. If such a crucial database is targeted by cyber criminals, much worst can happen.

According to Praveen Dalal, CEO of the exclusive techno legal cyber security research and training centre of India (CSRTCI) and managing partner of Perry4Law, India is not yet prepared for cyber threats. In fact, projects like Aadhar, Natgrid, CCTNS, etc are going to create more trouble than solution in the absence of proper laws and effective cyber security, says Dalal.

It seems India has misplaced its priorities and is engaging in unproductive and unconstitutional projects that are neither viable nor legal. Indian government must address these issues as soon as possible in the larger interest of India.

Thursday, December 24, 2009

National Security Of India Must Be Strengthened

National security of India is a crucial aspect that has been ignored by Indian politicians for long. The catastrophic consequences of the same are very apparent in the form of terrorists’ attacks and cyber terrorism in India. Time has arisen when we must rejuvenate the national security and internal security of India. The recent proposal by the Home Minister to strengthen Indian National Security and Internal Security must be strictly adhered to by the Indian government. It should not merely be another proposal with no actual implementation and execution.

National security of India has recently received a rejuvenation attempt by the Government of India (GOI). This is good news at a time where the national security issues are grossly ignored in India. The national security of India and internal security of India are suffering not only on the count of lack of political will but also due to absence of suitable policies and strategies.

The ICT Trends of India 2009 have also proved that India has failed on the fronts of Cyber law of India, Cyber Terrorism in India, E-Courts in India, E-Learning in India, Unique Identification Project of India, Serious Frauds and White Collar Crimes, National Security Issues, Crime Reporting by Media, Internet Banking Frauds, Cyber Security of Defense Forces, Cyber War in India, E-Surveillance in India, etc.

According to Praveen Dalal, Managing Partner of Perry4Law and the leading Techno-Legal Expert of India, “Indian approach in this regard is not sensible at all. We should not invest thousands of crores of Indian rupees into security projects that can be manipulated and sabotaged in minutes. Rather we should first analyse the weaknesses and security holes of the same before buying and installing it.

After all security of a Nation is proper application of “common sense” rather than wasting unlimited amount of money. Crime and Criminal Tracking Network & Systems (CCTNS) of India, Unique Identification Authority of India (UIAI), Rs 800 crores centralised facility to control phone tapping activities in India, etc are some of the projects that require common sense application before their implementation. They have to be tested in a “limited environment” before using them in a full fledged manner, says Praveen Dalal.

It seems Indian security initiatives have to be holistically analysed and suitably applied. The Indian security infrastructure and workforces are not in good shape and require rejuvenation. We need a techno-legal security workforce and not personnel who do not have even the basic facilities and technological means and knowledge. The terrorist attacks have really shattered the deep pervasive false sense of security present in the Indian government mentality. We have to think and act against such internal and external threats by going beyond a "political debate". We can fool ourselves by bragging about India’s capabilities and victories against terrorism and cyber terrorism and keep on facing future attacks and bear the traumatic casualties. Alternatively, we must accept our weaknesses against such attacks and take constructive steps to anticipate, prevent and counter such future terrorist and cyber terrorism activities, warns Praveen Dalal.

With a new ray of hope shown by the recent stress upon national security of India we can expect some good results in this direction. However, India is famous for mere assurances and proposals without actually implementing them. Similarly, due to faulty management and policies even the implemented projects have failed in the past. Let us hope that this time India would do the proper homework before starting an initiative that it cannot implement and run.

Sunday, December 13, 2009

Should IMEI Be A Reasonable National Security Criteria In India?

The Anti Terrorist Squad (ATS) recently arrested five people from a cell phone repair shop for implanting fake International Mobile Equipment Identity (IMEI) numbers in cell phones. It is a general perception that the 15-digit IMEI number can be used to identify a handset on an operator’s network, allowing individual calls to be traced to the phone it came from.

Does this assertion has any significant national security importance? Having knowledge about the IMEI number has many advantages for law enforcement and telecom service providers. The IMEI number is used by the GSM network to identify valid devices and therefore can be used to stop a stolen phone from accessing the network. If a mobile phone is stolen, the owner can call his or her network provider and instruct them to "ban" the phone using its IMEI number. This renders the phone useless, whether or not the phone's SIM is changed.

However, the bigger question is whether absence of an IMEI number per se is as offensive as to attract the “national security clause” and to brand a holder of such mobile a “terrorist”?

According to Praveen Dalal, the leading Techno-Legal Expert of India and Managing Partner of Perry4Law we need to have additional information besides IMEI for national security purposes. The IMEI is only used to identify the device, and has no permanent or semi-permanent relation to the subscriber, says Dalal. However, many network and security features are enabled by knowing the current device being used by a subscriber, suggests Dalal.

Although a good start has been made by the Indian government yet it has to cover a long road ahead. There is an urgent need to impart good techno-legal training to law enforcement and intelligence agencies so that national security can be protected as much as possible. The government must also train law enforcement officers in techno-legal fields so that they may effectively deal with the technology related crimes in India.