Cyber security watchdog CERTin has barred the use of remote desktop softwares like Anydesk and Teamviewer in the government department under new security guidelines released on Friday.
The guidelines prescribe government departments use virtual private networks (VPN) for accessing network resources from remote locations and enable multi-factor authentication (MFA) for VPN accounts.
"Ensure to block access to any remote desktop applications, such as Anydesk, Teamviewer, Ammyy admin etc," Guidelines on Information Security Practices for Government Entities said.
CERT-In (Indian Computer Emergency Response Team ) said the purpose of these guidelines is to establish a prioritised baseline for cyber security measures and controls within government organisations and their associated organisations.
Minister of State for Electronics and IT Rajeev Chandrasekhar in an official statement said the government has taken several initiatives to ensure an open, safe and trusted and accountable digital space.
"We are expanding and accelerating on Cyber Security with focus on capabilities, system, human resources and awareness. The guidelines are an important part of our larger cybersecurity framework being built under the leadership of our PM Narendra Modi ji, as India takes rapid strides towards USD 1 trillion Digital Economy," Chandrasekhar said.
According to the guidelines, critical servers should be either made stand-alone or members of a dedicated secure zone and the servers need not communicate amongst themselves unless they are part of the same application with dedicated ports and authenticated applications.
"In the wake of certain allegations and assumptions that AIIMS servers were compromised by ransomware and alleged leak of government data from entities, it is good that CERT-In has issued standard operating guidelines. These will standardise cyber security postures across India. It will help reduce the number of cyber security attacks in the country," Voyager Infosec, Director of Digital Lab, Jiten Jain, said.
Besides the security of computer and network infrastructure, the guidelines have also incorporated security measures for social media of government department accounts.
The guidelines mandate approval of content from appropriate authorities before it is posted on an official social media account.
"Content to be posted on social media handles should be approved by the appropriate authority within the organisation," the guideline said.
The guidelines bar use of official social media platform accounts on public devices or unauthorised devices.
CERT-In guidelines call for the prevention of IT systems from unauthorised access, physical damage, and tampering by implementing physical security.
"Important and sensitive zones should be monitored through CCTV cameras and footage should be stored for at least 180 days," the guideline said.
(Only the headline and picture of this report may have been reworked by the Business Standard staff; the rest of the content is auto-generated from a syndicated feed.)
You’ve reached your limit of {{free_limit}} free articles this month.
Subscribe now for unlimited access.
Already subscribed? Log in
Subscribe to read the full story →
Smart Quarterly
₹900
3 Months
₹300/Month
Smart Essential
₹2,700
1 Year
₹225/Month
Super Saver
₹3,900
2 Years
₹162/Month
Renews automatically, cancel anytime
Here’s what’s included in our digital subscription plans
Exclusive premium stories online
Over 30 premium stories daily, handpicked by our editors


Complimentary Access to The New York Times
News, Games, Cooking, Audio, Wirecutter & The Athletic
Business Standard Epaper
Digital replica of our daily newspaper — with options to read, save, and share


Curated Newsletters
Insights on markets, finance, politics, tech, and more delivered to your inbox
Market Analysis & Investment Insights
In-depth market analysis & insights with access to The Smart Investor


Archives
Repository of articles and publications dating back to 1997
Ad-free Reading
Uninterrupted reading experience with no advertisements


Seamless Access Across All Devices
Access Business Standard across devices — mobile, tablet, or PC, via web or app
)