Justice K.S.Puttaswamy(Retd) vs Union Of India on 26 September, 2018 (b) implementing controls to prevent and detect any loss, damage, theft or compromise of the assets; (c) allowing only controlled access to confidential information; (d) implementing controls to detect and protect against virus/malwares; (e) a change management process to ensure information security is maintained during changes; (f) a patch management process to protect information systems from vulnerabilities and security risks; (g) a robust monitoring process to identify unusual events and patterns that could impact security and performance of information systems and a proper reporting and mitigation process; (h) encryption of data packets containing biometrics, and enabling decryption only in secured locations; (i) partitioning of CIDR network into zones based on risk and trust; (j) deploying necessary technical controls for protecting CIDR network; (k) service continuity in case of a disaster; (l) monitoring of equipment, systems and networks; (m) measures for fraud prevention and effective remedies in case of fraud; (n) requirement of entering into non-disclosure agreements with the personnel; (o) provisions for audit of internal systems and networks; (p) restrictions on personnel relating to processes, systems and networks. (q) inclusion of security and confidentiality obligations in the agreements or arrangements with the agencies, consultants, advisors or other persons engaged by the Authority. (3) The Authority shall monitor compliance with the information security policy and other security requirements through internal audits or through independent agencies. Indian Kanoon - http://indiankanoon.org/doc/127517806/ 25

اختر الفقرة المستهدفة3