CourtMesh

Section 3: Measures for ensuring information security

The Aadhaar (Data Security) Regulations, 2016.Central Regulations · 2016

(1) The Authority may specify an information security policy setting out inter alia the technical and organisational measures to be adopted by the Authority and its personnel, and also security measures to be adopted by agencies, advisors, consultants and other service providers engaged by the Authority, registrar, enrolling agency, requesting entities, and Authentication Service Agencies.

(2) Such information security policy may provide for:—

(a) identifying and maintaining an inventory of assets associated with the information and information processing facilities;

(b) implementing controls to prevent and detect any loss, damage, theft or compromise of the assets;

(c) allowing only controlled access to confidential information;

(d) implementing controls to detect and protect against virus/malwares;

(e) a change management process to ensure information security is maintained during changes;

(f) a patch management process to protect information systems from vulnerabilities and security risks;

(g) a robust monitoring process to identify unusual events and patterns that could impact security and performance of information systems and a proper reporting and mitigation process;

(h) encryption of data packets containing biometrics, and enabling decryption only in secured locations;

(i) partitioning of CIDR network into zones based on risk and trust;

(j) deploying necessary technical controls for protecting CIDR network;

(k) service continuity in case of a disaster;

(l) monitoring of equipment, systems and networks;

(m) measures for fraud prevention and effective remedies in case of fraud;

(n) requirement of entering into non-disclosure agreements with the personnel;

(o) provisions for audit of internal systems and networks;

(p) restrictions on personnel relating to processes, systems and networks.

(q) inclusion of security and confidentiality obligations in the agreements or arrangements with the agencies, consultants, advisors or other persons engaged by the Authority.

(3) The Authority shall monitor compliance with the information security policy and other security requirements through internal audits or through independent agencies.

(4) The Authority shall designate an officer as Chief Information Security Officer for disseminating and monitoring the information security policy and other security-related programmes and initiatives of the Authority.

Where this provision sits

ActThe Aadhaar (Data Security) Regulations, 2016.
Section3
Marginal noteMeasures for ensuring information security
JurisdictionCentral
StatusIn force as published by the source

Find the provision, not just read it

The full text above is free, and it stays free. What a free CourtMesh account adds is everything you cannot do by reading one page at a time:

  • Search 49,000+ Central and State enactments by what a provision says, not by its number
  • Jump from any section to every judgment that has applied it
  • Search 300 million+ Indian court records alongside the statute
  • Ask a research agent to find and read the case law on a provision for you

Free account. No card. About a minute to create.

Create a free account

Need this as data, not as a page? The Aadhaar (Data Security) Regulations, 2016. is one of 49,000+ enactments on CourtMesh. The Indian court cases API serves the case law that cites these provisions over JSON, with API documentation and plans and pricing. See also the judgment library.