National Security Database

From Wikipedia, the free encyclopedia

National Security Database is reportedly an official accreditation program in India, awarded to information respected cybersecurity experts with proven skills to protect the country's National Critical Infrastructure and economy.

Under the program, reportedly developed by the Information Sharing and Analysis Center (ISAC), in support with the Government of India, professionals can apply for the program by clearing a technical lab examination and psychometric test. Program alumni reportedly become instrumental in a pool of ethical defence-testing hackers tasked with fixing the weakness of organizational systems in case of large cyberattacks.

History[edit]

The project was conceived after the 2008 Mumbai attacks to protect India's National Critical Infrastructure and Cyberspace. The program was founded by Rajshekhar Murthy,[1] under a non-profit section 25 company, 'Information Sharing and Analysis Center', supported by the highly specialised technical intelligence agency NTRO, run under the Government of India.

Earlier, the program was announced as a pilot at the International Malware Conference, MalCon, in 2010 in Mumbai, where Indian Government officials reportedly asked Indian hackers to learn Chinese.[2][3]

Program launch[edit]

The program was released on 26 November,[4] the same date as of the 2008 Mumbai Attacks, at the International Malware Conference, MalCon, at JW Marriott, Mumbai. The program was inaugurated by Shri Sachin pilot, Minister of State in the Ministry of Communications and Information Technology.

Access restrictions[edit]

The empanelment in the database can only be applied by Indian citizens, and limited access is available to the Industry to benefit from a list of credible experts. However, most of the database access is restricted to supporting Indian government organisations.

Debate[edit]

The program is largely believed to identify professional, ethical hackers and security experts by the government of India to protect its critical infrastructure and cyberspace. IT Minister Kapil Sibal has reportedly expressed the need for a community of ethical hackers.[5]

Alok Vijayant, director of the information dominance group at the National Technical Research Organisation, quoted[6] in an interview with India's top weekly magazine Outlook, that NSD should not be “trivialised” by describing it as just a group of hackers. “Supported by the government and the industry, NSD is a good initiative since it will provide a ready-aid database of the most credible security professionals. This is more so because information security is a domain where individuals have the skills, not companies, to move from one firm to another regularly..

Official support to the project[edit]

NSD is officially endorsed by the multiple Indian Government organisations, such as CERT-IN and NTRO, for the stated National objectives with recognition of the foundation and declared support for the work being done. The collaboration is open, and all supporting organisations who need to access the database can do so with a formal MoU with the body.

Industry and community contribution[edit]

Various organisations are actively participating and supporting the National Security Database. Notable organisations having voluntary representations governing the NSD advisory panel at a national level include the HoneyNet India Chapter, Microsoft India and the country's oldest security conference clubhack.

Current speciality domains of the NSD[edit]

The National Security Database program has the following speciality domains under which professionals can apply for empanelment:

  1. Information security compliance and penetration testing
  2. Reverse engineering
  3. Web application security
  4. Malware research and analysis
  5. Exploit development
  6. Mobile application security
  7. Digital forensic analysis
  8. Telecom security (by Invitation)
  9. Banking security (by Invitation)

In a quote with Outlook magazine, the director of ISAC, Rajshekhar Murthy, stated[6] that it is necessary to have people who are not only competent, but also have a high degree of trustworthiness and integrity. "The selection process will involve examination of references, technical skills, criminal history, and even psychological assessment to generate a credit report for security clearance.”

More Information[edit]

  • National Security Database Academy[7]
  • National Security Database Certification[8]

Notes[edit]

  1. ^ "JAI VIRU(S)". www.jammag.com. Archived from the original on October 21, 2011. Retrieved November 18, 2011.
  2. ^ J Dey Date: 2010-12-05 Place: Mumbai (2010-12-05). "Ethical hackers asked to learn Chinese to beat red attacks". Mid-day.com. Archived from the original on 2012-09-21. Retrieved 2013-05-16.{{cite web}}: CS1 maint: numeric names: authors list (link)
  3. ^ kohi10 (2010-12-05). "Got Mad Hacking Skillz? Speak Chinese? | MadMark's Blog". Kohi10.wordpress.com. Archived from the original on 2014-04-22. Retrieved 2013-05-16.{{cite web}}: CS1 maint: numeric names: authors list (link)
  4. ^ "techgoss.com". techgoss.com. 2011-11-09. Archived from the original on 2021-10-08. Retrieved 2013-05-16.
  5. ^ ET Bureau Nov 16, 2011, 04.22am IST (2011-11-16). "We need a community of ethical hackers, says IT minister Kapil Sibal – Economic Times". Articles.economictimes.indiatimes.com. Archived from the original on 2013-12-27. Retrieved 2013-05-16.{{cite web}}: CS1 maint: multiple names: authors list (link) CS1 maint: numeric names: authors list (link)
  6. ^ a b "Our Ether Warriors | Debarshi Dasgupta". Outlookindia.com. Archived from the original on 2013-12-10. Retrieved 2013-05-16.
  7. ^ "Information Sharing and Analysis Center | National Security Database". Information Sharing and Analysis Center. Archived from the original on 2021-08-04. Retrieved 2021-10-08.
  8. ^ "Information Sharing and Analysis Center". isacindia.org. Archived from the original on 2021-08-04. Retrieved 2021-10-08.

External links[edit]