Saturday, May 21, 2011

CBI Director Stresses Upon Technology Awareness Among Bank Officers

Recently the third conference of chief vigilance officers (CVOs) of public sector banks and financial institutions was held at the new central bureau of investigation (CBI) headquarters building. The director of CBI Shri Amar Pratap Singh advised the CVOs of banks and financial institutions to adapt to changing technology and sensitise staff to new methods of frauds.

Delivering the Key Note Address, Director CBI Shri Amar Pratap Singh said that CBI’s role is to investigate the criminality in bank frauds and it does not interfere in cases of prudent commercial judgement, even if such decisions involve risks or have resulted in losses to banks.

The Director, CBI called upon banks to adapt to changing technology and to sensitise its officers to new methods of fraud which are of late, noticed in electronic payments, technology related payments like RTGS, Credit Cards, ATM, Cell Banking, Internet Banking etc. Director CBI said the Banking Sector has lost as much as Rs.1883 crore and Rs. 2017 crore during 2008-09 and 2009-2010 respectively. These include over 200 frauds of above Rs One crore during each year.

Shri A.P. Singh stated that banking officials are guiding Investigating Officers in scrutiny of financial statement, credit appraisal etc which has enhanced the professionalism of CBI, in detecting bank frauds.

The Conference discussed important issues such as Preventive Vigilance, E-Tendering/E-Procurement and Forensic Auditing. The services of bank officers are being utilised in various branches of CBI such as Bank Security and Fraud Cell, Economic Offences Unit and Anti Corruption Units in the CBI Headquarters as well as regions.

The call from CBI director came after G Gopalakrishna, the executive director of Reserve Bank of India (RBI) said that all Banks would have to create a position of Chief Information Officers (CIOs) as well as Steering Committees on Information Security at the Board Level at the earliest. The idea is to use information technology to the maximum possible extent while maintaining the cyber security of banks.

While RBI and CBI have done a great job yet banks and financial institutions in India are not taking these directions and recommendations seriously. Till now the directions of RBI to appoint CIOs and steering committee has not been followed by banks of India. Similarly, banks of India are also at fault for ignoring the cyber security requirements. The RBI has even said that mobile banking in India is not yet popular due to low adoption of technology by banks. Let us hope the banks and financial institutions would take cyber law, cyber crimes and cyber security issues seriously very soon.

UK Looking Forward For Cyber Crimes Fighters

Till now it is an established fact that government of any nation by itself is not capable of dealing with cyber crimes and cyber security related issues. This is the reason why public private partnerships (PPP) is often adopted as a model to enhance capabilities of various national governments.

Further, contests and tournaments are also good source of talent mobilisation. For instance, the UK’s computer security industry has been conducting a series of games and tournaments to acquire fresh talents that can fight against the growing cyber crimes in UK.

UK will launch the Cyber Security Challenge next week that would bring out the best brains in the cyber security industry and common people. The search for new cyber security professionals follows warnings from chancellor George Osborne earlier this month, that government offices such as the Treasury were being bombarded with cyber attacks on a daily basis.

The government allocated £650m additional funding to fight cyber crime last autumn, indicating how tacking online crime had become a priority issue. However, 99 per cent of computer security companies surveyed last year said they could not recruit enough people for the work they were doing.

This is not a UK specific problem. In India as well Indian companies are finding it difficult to get talented workforce in IT field. Keeping in mind the international trend, India urgently needs to upgrade its skill development initiatives. There is an urgent need to develop techno legal skills development initiatives in India. Further, ICT skill development initiatives are also urgently required in India. There is also a need to club skill development and technical education in India.

Cyber security is an area that has not received much attention of Indian policy makers. Even private companies and industry is looking forward for skilled workforce in India. It is high time for India to invest in cyber security both in terms of technology and capacity development.

Friday, May 20, 2011

National Intelligence Grid Of India In Doldrums

National intelligence grid (Natgrid) is a pilot project of Home Ministry of India. Natgrid has been launched to tackle growing terrorist attacks and terrorism cases in India. Besides, Natgrid can also be used to prevent serious crimes and cyber crimes.

Natgrid project is accompanies by national counter terrorism centre (NCTC) of India. However, till now neither Natgrid nor NCTC has been able to see the light of the day. Bureaucratic hurdles and lack of proper planning is the main reason why these crucial projects are not even able to take a start.

After 26/11, India vowed it would never be caught napping again and the ambitious idea of National Intelligence Grid was born. It was widely believed to be Home Minister P. Chidambaram's visionary plan, a powerful real-time 24X7 networking of 21 databases to stitch all information and raise alarm. It has now been almost two years and there is no sign of any implementation of Natgrid project.

There seems to be two main reasons for non functional Natgrid and NCTC projects. The first is the fear that Home Ministry would become all powerful Ministry to deal with intelligence related works. If sensitive information is left at the disposal of Home Ministry other Ministries may not like the idea. Further, this is the reason why NCTC project has not moved an inch forward.

The second reason for the failure of Natgrid and NCTC projects is absence of privacy, data security and data protection safeguards in these projects. In a zeal to deal with terrorism related cases, Home Minister P Chidambaram ignored the civil liberties requirements altogether. To make the matter worst we have no e-surveillance policy in India and our intelligence agencies and law enforcement agencies are practically governed by no law and without any Parliamentary oversight. Thus, fears of privacy violations have also plagued Natgrid and NCTC projects.

Although the intentions of Home Ministry are good yet they have not been executed in a planned and coordinated manner. In these circumstances the Cabinet Committee on Security (CCS) may not clear these much needed projects. I wish the Home Ministry would take care of all these issues so that both Natgrid and NCTC may be operational in India.

International Cyber Crime Fight Getting Serious

The biggest hurdle before the fight against international cyber crimes is the lack of coordination and collaboration among various nations and international organisations. There is no universally acceptable cyber crime treaty and India has yet to become a part of any international treaty or convention in this regard.

Although cyberspace is not a safe place for any person yet children are more vulnerable to the evils of cyber crimes. Protecting children in cyberspace is of utmost importance. Now the International Telecommunications Union (ITU) and the United Nations Office on Drugs and Crime (UNODC) are expected to jointly work in this direction.

They have entered into a memorandum of understanding (MOU) that would enable the two bodies to work together and to make available the necessary expertise and resources to establish legal measures and legislative frameworks at national level, for the benefit of all interested countries. It is the first time that two organisations within the UN system have formally agreed to cooperate at the global level on cyber crimes and cyber security.

This can also be seen as a coordinated global effort towards harmonisation of legal framework and fight against cyber crimes. We at Perry4Law and Perry4Law Techno Legal Base (PTLB) have been suggesting ICT Policies and Strategies in general and need for International Cyber Crime Treaty and International Cyber Security Treaty in particular.

It seems that nations across the world must concentrate upon a coordinated and focused approach towards cyber crimes and cyber security. The national approach alone cannot solve the growing dangers that are lurking at large in the cyberspace.

Indian Companies Are Facing Shortage Of Skilled Workforce

According to a recent survey, Indian companies are finding it difficult to fill in key positions in research, sales and IT due to lack of training and experience. The main reason for such supply shortage is the lack of training and the required experience for the positions which are in very high demand by the industry.

This is no surprise as studies in the past have also indicated that only 25% management students and 20% engineers are fit to be absorbed in to mainstream industry. The main reason for this poor performance is the highly academic nature of Indian education system. Further, little emphasis is given to practical trainings and education in India.

India urgently needs to upgrade its skill development initiatives. There is an urgent need to develop techno legal skills development initiatives in India. Further, ICT skill development initiatives are also urgently required in India. There is also a need to club skill development and technical education in India.

However, India is a big country with diverse languages and culture. It is not possible to accommodate the gigantic population of India through institutional education mechanism. India must use e-learning and online education and skill development model as much as possible.

Similarly, India must also pay more attention to higher research and education. More PhD candidates must be enrolled so that research in India can be strengthened. Finally, a special emphasis must be given to lifelong learning in India and continuing legal education in India.

European Union India Free Trade Agreement May Be Tough

India and European Union (EU) have been trying really hard to formulate a comprehensive free trade policy to apply to both goods and services, and facilitate more European investment in India. EU and India now believe that they are getting closer to an agreement which would be more fruitful for both parties.

This is so despite the differences between EU and India regarding intellectual property rights (IPRS) especially regarding pharmaceutical patents. IPRs in India are governed by respective legislation and at the International level they are governed by TRIPS Agreement. Now EU is insisting upon “TRIPS Plus Conditions” that India is not interested in agreeing to. India’s stand on highly sensitive IPRs issues has been formulated by the high-powered Trade and Economic Relations Committee (TERC) at its recent meeting Chaired by Prime Minister Manmohan Singh.

Meanwhile, EU’s Trade Commissioner, Karel De Gucht, has announced plans to slash the number of countries, from 176 to 80, that benefit from the generalised system of preferences (GSP) scheme, whereby eligible nations enjoy reduced or zero customs tariffs on imported goods. He said that the action is aimed at large emerging economies like India, Brazil and Russia, which did not require continued specialised assistance, given their newly muscular economies.

Bilateral trade in goods and services between India and the EU was estimated at €72bn ($103bn, £63bn) in 2009, a figure that could rise to an estimated €160bn by 2015 if the pact is completed.

But, with both Brussels and New Delhi keeping the precise details of the deal a closely guarded secret, the talks have aroused serious concern in both Europe and India. In February, Corporate Europe Observatory, a research and campaigning group, sued the European Commission over its conduct of the free trade talks. The lawsuit accused the commission of violating rules on transparency and democracy by refusing to disclose details of the negotiations publicly, despite sharing them with powerful European business groups.

A more rigorous stand has been taken by NGOs and other dealing with healthcare. If TRIPS Plus provisions are pushed by EU and accepted by India, it would hamper the ability of developing countries to fight against life threatening diseases. The EU, in the face of the protests, has backed away from some of its demands, including its request for protection of multinational drug companies’ clinical trial data, which Indian companies use to get their own low-cost generic copies approved. It seems the EU India free trade agreement would not be an easy ride especially due to large public interest attached to healthcare and affordable medicines.

Thursday, May 19, 2011

Phil Reitinger Resigns From Homeland Security's Post

United States (US) has recently declared its international strategy for cyberspace. With this it has also shown its willingness to take cyberspace issues like cyber law, cyber crimes and cyber security seriously. This is a good step in right direction for any country including India. However, nothing is more beneficial than a harmonised and international standard in this regard.

US is also entering into bilateral agreements with countries like India in this regard. For instance, India and US are going to have a homeland security dialogue very soon. Further, a greater India US cyber security cooperation is also on the cards.

In a significant development, Phil Reitinger, the Department of Homeland Security's (DHS) top cyber and computer crimes official, is resigning just days after the administration launched its most ambitious cyber security initiative.

The DHS cyber team has monitored a surge of major cyber attacks in the private sector, with crises like the penetration of Google by Chinese hackers, aggressive attempts to break into NASDAQ's computers, and most recently, an audacious but simple infiltration of RSA, a top cyber security company perhaps best known for its SecurID computer security product.

DHS's National Cyber Security Division provides warning and advice to the government and private sector about potential threats through its National Cyber Security and Communications Integration Center, runs exercises to test the government's response to major intrusions, and has completed guidelines for the feds to follow in the event of a cyber-emergency.

Reported friction between DHS and other government agencies has diminished under the watch of White House senior director for cyber policy Howard Schmidt, who was charged by President Obama with de-conflicting and streamlining cyber response and policy priorities associated with it. Last week, Schmidt sent to Congress detailed guidance from the White House about legislation to establish a formal way to protect and certify the nation's critical private infrastructure, as well as formally give DHS authority over the dot.gov domain.