CS Atal Dulloo Mandates IT Deptt For Swift Revival Of Unaudited Websites

Chief Secretary Atal Dulloo recently chaired a crucial meeting to bolster the cybersecurity framework for government websites and digital assets within the Union Territory. The discussion highlighted the critical need for strong cyber resilience in today’s digital landscape.

Key Directives and Initiatives
Dulloo emphasized the immediate restoration of all government websites and web applications that were taken offline due to non-compliance with security audits. He stressed that prolonged shutdowns were unacceptable and directed the IT Department to provide compliance reports from all departments every Monday and Thursday.

The Chief Secretary instructed the National Informatics Centre (NIC) and the IT Department to promptly bring all currently offline websites and applications back online.

Enhancing Data Security and Infrastructure
To enhance data safety, Dulloo imposed a strict ban on using private email IDs for official communications, mandating the exclusive use of authorized government email addresses. He also directed the swift migration of mini data centers (used by offices like JPDCL, KPDCL, and SICOP) to more secure, centralized facilities.

Capacity Building and Proactive Measures
The meeting also focused on continuous capacity building for government officers to foster a culture of cyber hygiene. Dulloo called for the creation of “master trainers” within each department to disseminate best practices and implement long-term strategies for digital security.

Piyush Singla, Secretary IT, informed the Chief Secretary about a recent two-day cybersecurity workshop attended by approximately 250 officers. He added that Chief Information Security Officers (CISOs) or Information Security Officers (ISOs) have been nominated in each department to safeguard IT assets.

Current Progress and Technical Safeguards
It was reported that about 110 websites are undergoing security audits, with 45 in their final stage and ready to go live soon. The Secretary IT reiterated that all websites and applications must strictly comply with CERT-In and OWASP guidelines before being brought back online.

In terms of technical safeguards, Endpoint Detection and Response (EDR) solutions have been installed on 4011 devices, and Unified Endpoint Management (UEM) solutions on 1617 devices. Comprehensive measures like VPN security, geo-fencing, port security, and robust firewall and router policies have also been adopted to enhance cyber protection.