OYO strengthens focus on information security; develops a comprehensive Bug Bounty program

Image
ANI
Last Updated : Feb 21 2020 | 8:35 AM IST

OYO Hotels & Homes, the world's leading hospitality chain announced that it will continue to ramp up efforts to improve its information security framework as well as roll-out stronger ethical hacking and bug bounty programs to encourage continuous improvement and collaboration with ethical hacking experts.

This development is in line with the company's commitment towards ensuring data privacy and building a robust cyber-security network.

"One of our biggest assets is the trust of our customers, partners, and employees place in us. We understand that trust is hard to earn and easy to lose. One key responsibility in earning this trust is protecting the data our customers and other stakeholders have with us from any unauthorised use. Our team of 1100 plus world-class security, network and software engineers and external partners across multiple geographies is at work 24x7 ensuring the protection of this data, so our customers and stakeholders can rest easy", said Jagbir Singh, Engineering Manager - DevOps and InfoSec, OYO Hotels & Homes.

The Bug Bounty program that the company aims to introduce is towards ensuring that there is a credible and continuous flow of positive feedback from independent security groups and individual researchers to mitigate against any bug or shortfall in the company's systems.

This is in line with the established practice of recognition and reward for ethical hackers who help responsibly investigate shortfalls within the tech architecture of several tech companies including the likes of Silicon Valley giants like Facebook, Google, etc.

OYO has accordingly developed an improved responsible disclosure policy to encourage honest and responsible reporting of any potential risks.

Additionally, OYO has partnered with a specialized cyber-security start-up, AppSecure/Hackerhive, that connects companies and ethical hackers to help the former discover and fix security vulnerabilities and is in the process of developing a full-fledged Bug Bounty program.

Security a priority

Security is an integral part of any process at OYO; beginning from the collection of data, during transfer and processing to storage at rest. OYO follows a comprehensive information security framework based on NIST (National Institute of Standards and Technology, USA), ISO 27001 and other stringent industry standards.

OYO's commitment also extends to employee training and sensitization at every step. All new joiners at OYO go through information security training as part of the new employee orientation.

The company's software developers and other information security personnel also attend a mandatory quarterly refresher since the technology in this space are dynamic and evolving very quickly. There is also annual mandatory refresher training for all existing employees.

"We have a robust and world-class security team comprising of in-house and external experts employing best in class security techniques including virtual private networks/cloud, firewalls, intrusion prevention and detection devices (IPS and IDS), security trainings for all engineers, static and dynamic code analysis, regular vulnerability assessments and network penetration tests. In today's digital world, a cyber-attack is a real concern. Hence, in line with our efforts to continually improve, we are investing in ethical hacking programs as well", said Anil Goel, Group Chief Technology and Product Officer.

OYO also joined hands with other technology companies to address the issue of increasing online frauds and save guests from cyber-crimes. Along with other companies, OYO met the Reserve Bank of India (RBI) representatives and made a joint representation on the issue that also addressed the plan on how to curb these online frauds followed by a meeting with other stakeholders in the telecom industry.

The company has a long way to go and as it continues to amplify investments in this ever-evolving space, it aims to continually improve.

This story is provided by BusinessWire India. ANI will not be responsible in any way for the content of this article.

Disclaimer: No Business Standard Journalist was involved in creation of this content

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Feb 21 2020 | 7:52 AM IST

Next Story