Showing posts with label Telecom Security Policy Of India. Show all posts
Showing posts with label Telecom Security Policy Of India. Show all posts

Friday, June 17, 2011

New National Telecom Policy (NTP) 2011 Of India

Telecom Policy of India is one of the most important Policies of India. For some strange reason, the Telecom Policy of India was poorly drafted and badly implemented. Naturally, there were many “Loopholes” that gave rise to scams, bad policy decisions, financial losses to Governmental exchequer, poor consumer performances and so on.

That is a thing of past as Government of India is now planning to introduce the new National Telecom Policy (NTP) of India 2011. Although the intentions are good yet the actual execution and implementation of this intention is missing. Further, the efforts of Indian Government in general and Ministry of Communication and Information technology (MCIT) in particular are “Vague” and “Non Holistic”.

There are various “Crucial Components” of any sound, effective and robust Telecom Policy. These include, issues pertaining to Encryption, Telecom Security, wider Broadband Penetration, Telecom Equipment Security, E-Surveillance and Phone Tapping Policies, Lawful Interceptions and Eavesdropping Policies, Harmonisation of National Security and Civil liberties, etc.

I have labeled the present efforts of Indian Government and MCIT as vague and non holistic because these components must be an “Essential and Integral Part” of the proposed Indian National Telecom Policy (NTP) 2011. However, instead of being a “Composite Telecom Policy” the proposed Policy is not even considering these aspects “Singularly” and “Individually”. In short, these components are “Missing” from the proposed Telecom Policy of India.

This would again produce a Policy Document that would be “Open and Prone” to many sorts of Irregularities and Misuses. Consumer and Telecom Companies Disputes, Privacy Violations cases, Civil Liberties Violations, etc may also arise in future.

Fortunately, till now the new Telecom Policy of India 2011 has not been formulated and implemented. The concerns and suggestions mentioned above can still be incorporated in the same by MCIT Minister Kapil Sibal and Government of India.

Tuesday, May 31, 2011

Telecom Equipments Security Framework Of India

Telecom equipments, especially imported one, have been in controversy for long. The security agencies of India have shown their apprehension regarding imported telecom hardware and equipments. For some time, even import of the same was hampered.

This is primarily due to the fact that India has no telecom security policy that must essentially carry norms for import of telecom equipments and hardware. Meanwhile, it has been proposed to get the telecom equipments checked by Telecom Engineering Centre (TEC) mandatorily before use in India. Now intelligence agencies of India are asking telecom companies to store call data records for five years.

The Department of Telecommunications (DoT) has approved new security norms governing telecom equipment that could cost operators at least Rs 5,000 crore each to implement. DoT has unveiled a new telecom security framework that did away with many existing controversial clauses such as mandating foreign equipment companies to put their software in the equivalent of a sealed envelope and submit it to the government.

Another controversial clause that stipulates penalties of 100% of the contract value on vendors if any spyware or malware is found in the imported equipment has also been dropped. Instead, any security breach will invite a maximum penalty of 50 crore in addition to criminal proceedings against the mobile phone company.

The new policy also dilutes the earlier rule that mandated vendors to employ only Indian engineers to maintain the networks of local mobile phone companies. The fresh norms say only top personnel with vendors need to be Indians. The names of these individuals will have to be cleared by the telecom and home ministries prior to their appointment. This is in line with the rules for mobile phone companies where top executives are required to be resident Indians.

Besides, with phone tapping in the limelight, the changed policy also mandates that mobile phone companies must only appoint Indians as chief technical officer, chief information security officer or as nodal executives for handling monitoring and interception functions across mobile networks.

The new framework is a good step in the right direction. Perry4Law and Perry4Law Techno Legal Base (PTLB) welcome this effort of DoT. However, this is just a piecemeal effort and DoT must come out with a proper telecom security policy of India as soon as possible.