Security

Global tech industry objects to India’s new infosec reporting regime

Eleven industry associations, representing every tech vendor that matters, warns of economic harm


Eleven significant tech-aligned industry associations from around the world have reportedly written to India’s Computer Emergency Response Team (CERT-In) to call for revision of the nation’s new infosec reporting and data retention rules, which they criticise as inconsistent, onerous, unlikely to improve security within India, and possibly harmful to the nations economy.

The rules were introduced in late April and are extraordinarily broad. For example, operators of datacenters, clouds, and VPNs, are required to register customers’ names, dates on which services were used, and even customer IP addresses, and store that data for five years.

Another requirement is to report over 20 types of infosec incident, even port scanning or attempted phishing, within six hours of detection. Among the reportable incidents are “malicious/suspicious activities” directed towards almost any type of IT infrastructure or equipment, without explanation of where to draw the line between malicious and suspicious activity.

The new rules attracted plenty of local criticism on grounds that a six-hour reporting window is too short, the requirement to record VPN users’ details is an attack on privacy, and that the requirements are too broad and therefore represent an onerous compliance burden.

CERT-In responded by publishing an FAQ that addressed some of the criticism directed at the new rules. But the FAQ remains very vague, offering only limited guidance without addressing matters such as what represents reportable “suspicious activities.

Indian outlet MediaNama on Saturday reported, along with numerous other Indian outlets, that eleven tech or tech-adjacent lobby groups have written to CERT-In to voice their objections to the new rules.

The alleged signatories are heavy hitters – the US Chamber of Commerce, The Alliance (BSA), Digital Europe, the Information Technology Industry Council, techUK, the Cybersecurity Coalition US Chamber of Commerce, the US-India Business Council, and the US-India Strategic Partnership Forum are among the signatories. The collective membership of the above organisations means almost every significant tech vendor is represented by a signatory to the letter.

Among the objections raised by the letter are:

The letter to CERT-In suggests that the rules will make it hard for overseas companies to do business in India, put the country at odds with its allies, and result in costs being passed on to consumers. The groups call for new consultation to revise the rules.

CERT-In has to date been silent in the face of criticism. India’s minister for Skill Development and Entrepreneurship and Electronics and Information Technology, Rajeev Chandrasekhar, has brushed aside criticism too, saying that VPN providers that don’t like the rules can choose to leave the country.

The Register has contacted minister Chandrasekhar and CERT-in for comment on the letter. ®

Send us news
15 Comments

India and EU finally advance HPC collaboration project hatched in 2022

Seek ideas for thorny problems related to both HPC and real-world problems

Cisco creates architecture to improve security and sell you new switches

Hypershield detects bad behavior and automagically reconfigures networks to snuff out threats

OpenAI's GPT-4 can exploit real vulnerabilities by reading security advisories

While some other LLMs appear to flat-out suck

Microsoft squashes SmartScreen security bypass bug exploited in the wild

Plus: Adobe, SAP, Fortinet, VMware, Cisco issue pressing updates

Indian PM's 25-year roadmap laid out with help from AI

AI is so good at drawing pictures and driving cars, why not let it govern a country?

Japanese government rejects Yahoo<i>!</i> infosec improvement plan

Just doesn't believe it will sort out the mess that saw data leak from LINE messaging app

US government excoriates Microsoft for 'avoidable errors' but keeps paying for its products

In what other sphere does a bad supplier not feel pain for its foulups?

Crooks exploit OpenMetadata holes to mine crypto – and leave a sob story for victims

'I want to buy a car. That's all'

Australian operation of web host BlueVPS laid low by storage failure

PLUS: AWS expands India payment options; Alibaba co-founders unite in criticism; Korea invests in AI; and more

H-1B visa fraud alive and well amid efforts to crack down on abuse

It's the gold ticket favored by foreign techies – and IT giants suspected of gaming the system

Ransomware feared as IT 'issues' force Octapharma Plasma to close 150+ centers

Source blames BlackSuit infection – as separately ISP Frontier confirms cyberattack

Fire in the Cisco! Networking giant's Duo MFA message logs stolen in phish attack

Also warns of brute force attacks targeting its own VPNs, Check Point, Fortinet, SonicWall and more