2475 GI/2024 (1) रजिस्ट्री सं. डी.एल.- 33004/99 REGD. No. D. L.-33004/99 xxxGIDHxxx xxxGIDExxx असाधारण EXTRAORDINARY भाग II—खण् ड 3—उप-खण् ड (ii) PART II—Section 3—Sub-section (ii) प्राजधकार से प्रकाजित PUBLISHED BY AUTHORITY इलेक्ट्रॉजिकी और सूचिा प्रौद्योजगकी मंत्रालय (आईपीएचडब्ल्यू प्रभाग ) आदेि िई दद् ली, 9 अप्रैल,…
Official record
Open source page2475 GI/2024 (1) रजिस्ट्री सं. डी.एल.- 33004/99 REGD. No. D. L.-33004/99 xxxGIDHxxx xxxGIDExxx असाधारण EXTRAORDINARY भाग II—खण् ड 3—उप-खण् ड (ii) PART II—Section 3—Sub-section (ii) प्राजधकार से प्रकाजित PUBLISHED BY AUTHORITY इलेक्ट्रॉजिकी और सूचिा प्रौद्योजगकी मंत्रालय (आईपीएचडब्ल्यू प्रभाग ) आदेि िई दद् ली, 9 अप्रैल, 2024 जिषय: "इलेक्ट्रॉजिकी और सूचिा प्रौद्योजगकी माल में संिोधि" (अजििायय पंिीकरण की आिश्यकता) आदेि, 2021" का.आ. 1652(अ).—भारतीय मािक ब्लयूरो अजधजियम, 2016, (2016 का 11) की धारा 25 की उपधारा (3) के साथ पठित धारा 16 की उप-धारा (1) और (2) द्वारा प्रदत्त िजियों का प्रयोग करते हुए, केंद्र सरकार का यह मत है दक साियिजिक जहत में ऐसा करिा आिश्यक या समीचीि है, इसके द्वारा "इलेक्ट्रॉजिकी और सूचिा प्रौद्योजगकी माल (अजििायय पंिीकरण के जलए आिश्यकताएं) आदेि, 2021" में जिम्नजलजखत संिोधि दकए िाते हैं: 2. सी.सी.टी.िी. कैमरे हेतु, कॉलम (5) की जिम्नजलजखत प्रजिजि को "इलेक्ट्रॉजिकी और सूचिा प्रौद्योजगकी माल (अजििायय पंिीकरण के जलए आिश्यकताएं) आदेि, 2021 की अिुसूची में क्रम संख्या 41 पर िोडा िाएगा। क्रमांक (1) माल या सामाि (2) भारतीय मािक (3) भारतीय मािक का िीषयक (4) अपेजित आिश्यकता (आिश्यकताएँ) (5) 41 सीसीटीिी कैमरा आईएस 13252 : भाग 1 : 2010 सूचिा तकिीकी उपकरण - सुरिा सामान्य आिश्यकताएं-- अिुलग्नक के अिुसार सीसीटीिी हेतु अजििायय आिश्यकता (आिश्यकताएँ) सं. 1569] िई दद्ली, मंगलिार, अप्रैल 9, 2024/चैत्र 20, 1946 No. 1569] NEW DELHI, TUESDAY, APRIL 9, 2024/CHAITRA 20, 1946 सी.जी.-डी.एल.-अ.-09042024-253632 CG-DL-E-09042024-253632 2 THE GAZETTE OF INDIA : EXTRAORDINARY [PART II—SEC. 3(ii)] 3. "इलेक्ट्रॉजिकी और सूचिा प्रौद्योजगकी माल (अजििायय पंिीकरण के जलए आिश्यकताएं) आदेि, 2021" के प्रािधाि इस अजधसूचिा के आधार पर उि आदेि की अिुसूची में िोडे गए कॉलम (2) में जिर्दयि माल या सामाि पर आजधकाठरक रािपत्र में इस अजधसूचिा के प्रकािि की तारीख से छह महीिे की समाजि पर, कॉलम (5) में जिर्दयि दकए गए संबंजधत अपेजित आिश्यकताओं के अिुरूप लागू होंगे। बीआईएस अिुरूपता मू्यांकि जिजियम, 2018 की योििा II के अिुसार बीआईएस मान्यता प्राि प्रयोगिालाओं से परीिण ठरपोटय िमा करिा मािक जचन्ह का उपयोग करिे के जलए लाइसेंस प्राि करिे हेतु एक पूिय-आिश्यकता होगी। [फा.सं. डब्ल्यू-43/11/2021-आईपीएचडब्ल्यू] आिा िांजगया, समूह समन्ियक और िैज्ञाजिक 'िी' अिुलग्नक सीसीटीिी की सुरिा के जलए अजििायय आिश्यकता संिेदििील िािकारी की सुरिा और जसस्ट्टम को प्रभािी ढंग से संचाजलत करिे के जलए सीसीटीिी (क्ट्लोि-सर्कयट टेलीजििि) प्रणाली को सुरजित करिा महत्िपूणय है। परीिण के प्रमुख िेत्रों में एक्ट्स्ट्पोस्ट्ड िेटिकय सेिाएं, जडिाइस संचार प्रोटोकॉल, जडिाइस के यूएआरटी,िेटीएिी,एसडब्ल्युडी आदद तक भौजतक पहुंच, मेमोरी और फमयिेयर जिकालिे की िमता, फमयिेयर अपडेट प्रदक्रया सुरिा और डेटा का भंडारण और एजन्क्रप्िि िाजमल हैं। सीसीटीिी जसस्ट्टम की सुरिा के जलए यहां संजिि आिश्यकताएं दी गई हैं: 1. भौजतक सुरिा - भौजतक छेडछाड को रोकिे के जलए छेडछाड-प्रजतरोधी कैमरा एन्क्ट्लोज़र और लॉककंग तंत्र का उपयोग करें। 2. प्रमाणीकरण द्वारा अजभगम जियंत्रण, भूजमका-आधाठरत अजभगम जियंत्रण (आरबीएसी) और कर्मयों के पठरितयिों को प्रजतबबंजबत करिे के जलए अजभगम अिुमजतयों की जियजमत रूप से समीिा और अद्यतिीकरण । 3. डेटा रांसजमिि के एजन्क्रप्िि को जियोजित करके िेटिकय सुरिा 4. जियजमत अपडेट द्वारा सॉफ़्टिेयर सुरिा, अप्रयुि सुजिधाओं को अिम करिा और सुदृढ़ पासिडय िीजतयाँ 5. पेिीरेिि परीिण: साइबर हमलों के जलए जसस्ट्टम के प्रजतरोध का आकलि करिे और कमिोठरयों को दूर करिे के जलए पेिीरेिि परीिण को जियोजित करें। अजििायय सुरिा आिश्यकताएँ क्रमांक िगय परीिण पैरामीटर क्ट्या परीिण दकया िाए अपेजित दस्ट्तािेज़ हाडयिेयर स्ट्तर सुरिा पैरामीटर (सॉफ़्टिेयर द्वारा समर्थयत) 1.1 एक िठटल पासिडय द्वारा यह सत्याजपत करें दक एजप्लकेिि लेयर जडबबगंग इंटरफेस िैसे यूएसबी, यूएआरटी और अन्य सीठरयल िेठरएंट अिम या संरजित हैं। 1. परीिण के तहत जडिाइस में उपयोग दकए िा रहे एसओसी की डेटािीट के माध्यम से यूएसबी, यूएआरटी और अन्य सीठरयल िेठरएंट िैसे जडबबगंग इंटरफेस की उपलब्लधता की पहचाि करिा 2. जिक्रेता दस्ट्तािेज़ीकरण में घोजषत की गई सुरिा के जलए उत्पादि उपकरणों और संबंजधत पहुंच जियंत्रण तंत्र में सिम पोटय/इंटरफेस का सत्यापि और िेधता हाडयिेयर आधाठरत जडबगसय और एक्ट्सेस कंरोल तंत्र का उपयोग करके सभी पोटय और यूएसबी, यूएआरटी और अन्य सीठरयल िेठरएंट िैसे जडबबगंग इंटरफेस को सिम/अिम करिे को सत्याजपत करिे के जलए ओईएम जिक्रेता द्वारा जिम्नजलजखत को उपलब्लध करिा होगा: 1. जडिाइस में उपयोग दकए िा रहे एसओसी की डेटािीट। 2. उत्पादि उपकरणों में सिम पोटय/इंटरफेस से संबंजधत दस्ट्तािेज़ीकरण और उसकी सुरिा के जलए संबंजधत एक्ट्सेस जियंत्रण तंत्र। 3. जडिाइस के जिजिमायण/प्रािधाि की प्रदक्रया प्रिाह [भाग II—खण् ड 3(ii)] भारत का रािपत्र : असाधारण 3 टीम की उपजस्ट्थजत में परीिण। 4. जडबबगंग इंटरफेस के बारे में जिक्रेता के दािे को मान्य करिे के जलए जिजिमायण सुजिधा की प्रदक्रया लेखा परीिा िो प्रािधाि के दौराि बंद/अिम हैं। [उदाहरण के जलए, ब्ललॉक किेक्ट्िि आरेख के माध्यम से होस्ट्ट माइक्रोकंरोलर के बीच जपि किेक्ट्िि और जिजभन्न उप घटकों/पठरधीय के साथ इसकी बातचीत को दिाया गया है।] 1.2 सत्याजपत करें दक दक्रप्टोग्रादफक कुंिी और प्रमाणपत्र प्रत्येक व्यजिगत जडिाइस के जलए अजद्वतीय हैं। जडिाइस इको-जसस्ट्टम में उपयोग की िा रही सभी कुंजियों और प्रमाणपत्रों की पहचाि करिा और इिके माध्यम से सत्यापि करिा: ओईएम टीम की उपजस्ट्थजत में परीिण कोो़ड समीिा कुंिी-िीिि चक्र प्रदक्रया संबंधी प्रदक्रया लेखा परीिा जिक्रेता द्वारा जिम्नजलजखत को प्रस्ट्तुत करिा होगा: 1. जडिाइस इकोजसस्ट्टम में उपयोग की िा रही सभी कुंजियों और प्रमाणपत्रों की सूची 2. मुख्य प्रबंधि िीिि चक्र (उद्देश्य, उत्पादि, भंडारण, जििाि/िून्यीकरण, िैधता, कुंिी पठरितयि/रोटेिि) 1.3 सत्याजपत करें दक िेटीएिी या एसडब्यूडी िैसे ऑि-जचप जडबबगंग इंटरफेस अिम हैं या उपलब्लध सुरिा तंत्र सिम और उजचत रूप से कॉजन्फगर दकया गया है। 1. परीिण के तहत जडिाइस में उपयोग दकए िा रहे एसओसी की डेटािीट के माध्यम से यूएसबी, यूएआरटी और अन्य सीठरयल िेठरएंट िैसे जडबबगंग इंटरफेस की उपलब्लधता की पहचाि करिा 2. जिक्रेता दस्ट्तािेज़ में घोजषत की गई सुरिा के जलए उत्पादि उपकरणों और संबंजधत पहुंच जियंत्रण तंत्र में सिम पोटय/इंटरफेस का सत्यापि और िेधता 3. इंटरफेस सिम होिे की जस्ट्थजत में उिके प्रासंजगक हाडयिेयर आधाठरत जडबगसय और एक्ट्सेस कंरोल तंत्र का उपयोग करके सभी पोटय और यूएसबी, यूएआरटी और अन्य सीठरयल िेठरएंट िैसे जडबबगंग इंटरफेस को सिम/अिम करिे को सत्याजपत करिे के जलए ओईएम टीम की उपजस्ट्थजत में परीिण। 4. जडबबगंग इंटरफेस के बारे में जिक्रेता के दािे को मान्य करिे के जलए जिजिमायण सुजिधा की प्रदक्रया लेखा परीिा िो प्रािधाि जिक्रेता द्वारा जिम्नजलजखत को उपलब्लध करिा होगा: 1. जडिाइस में उपयोग दकए िा रहे एसओसी की डेटािीट। 2. उत्पादि उपकरणों में सिम पोटय/इंटरफेस से संबंजधत दस्ट्तािेज़ीकरण और उसकी सुरिा के जलए संबंजधत एक्ट्सेस जियंत्रण तंत्र। 3. जडिाइस के जिजिमायण/प्रािधाि की प्रदक्रया प्रिाह 4 THE GAZETTE OF INDIA : EXTRAORDINARY [PART II—SEC. 3(ii)] के दौराि बंद/अिम हैं। [उदाहरण के जलए, ब्ललॉक किेक्ट्िि आरेख के माध्यम से होस्ट्ट माइक्रोकंरोलर के बीच जपि किेक्ट्िि और जिजभन्न उप घटकों/पठरधीय के साथ इसकी बातचीत को दिाया गया है।] 1.4 सत्याजपत करें दक जिश्वसिीय जिष्पादि लागू और सिम है, यदद जडिाइस एसओसी या सीपीयू पर उपलब्लध है। जिक्रेता द्वारा प्रस्ट्तुत एसओसी डेटािीट और तकिीकी दस्ट्तािेि के माध्यम से जडिाइस में टीईई/एसई/टीपीएम उपलब्लध है या िहीं, इसकी पहचाि करिा। आगे का मू्यांकि जडिाइस पर लागू पठरदृश्यों के आधार पर दकया िाता है िैसा दक िीचे पठरभाजषत दकया गया है: जस्ट्थजत 1: टीईई/एसई/टीपीएम उपलब्लध िहीं है: कोई और अजग्रम मू्यांकि िहीं जस्ट्थजत 2: टीईई/एसई/टीपीएम उपलब्लध और सिम है: कोड-समीिा के माध्यम से सत्यापि दक दक्रप्टो फंक्ट्िि को टीईई/एसई/टीपीएम एपीआई के माध्यम से बुलाया िाता है। जस्ट्थजत 3: टीईई/एसई/टीपीएम उपलब्लध है लेदकि जिक्रेता द्वारा सिम िहीं दकया गया है: आिश्यकता के अिुरूप ि होिे के रूप में करार ददया गया। टीईई/एसई/टीपीएम को सिम और कायायजन्ित करिे के जलए ओईएम की आिश्यकता होती है। जिक्रेता द्वारा जिम्नजलजखत को उपलब्लध करािा होगा: 1. जडिाइस में उपयोग दकए िा रहे एसओसी की डेटािीट। 2. जडिाइस का उपयोगकताय मैिुअल/तकिीकी जिजिदेि 3. टीईई एपीआई कॉल के कोड जिपेट, िहां भी लागू हो 1.5 सत्याजपत करें दक संिेदििील डेटा, जििी कुंजियाँ और प्रमाणपत्र एक सुरजित तत्ि, टीपीएम, टीईई (जिश्वसिीय जिष्पादि पयायिरण) में सुरजित रूप से संग्रहीत हैं, या सुदृढ़ दक्रप्टोग्राफी का उपयोग करके संरजित हैं। जडिाइस इको-जसस्ट्टम, संिेदििील डेटा और उिके भंडारण तंत्र में उपयोग की िा रही सभी कुंजियों और प्रमाणपत्रों की पहचाि करिा; और इसके माध्यम से सत्यापि करिा : • ओईएम टीम की उपजस्ट्थजत में परीिण • कोो़ड समीिा • कुंिी-िीिि चक्र प्रदक्रया संबंधी प्रदक्रया लेखा परीिा जिक्रेता द्वारा जिम्नजलजखत को प्रस्ट्तुत करिा होगा: 1. जडिाइस इकोजसस्ट्टम में उपयोग की िा रही सभी कुंजियों और प्रमाणपत्रों की सूची 2. जडिाइस में सिम दकए िािे िाले सुरजित कॉजन्फगरेिि के साथ कायायजन्ित सभी संिेदििील डेटा की उिके इजछछत उपयोग और सुरजित भंडारण तंत्र (ओं) के साथ सूची। 3. मुख्य प्रबंधि िीिि चक्र (उद्देश्य, उत्पादि, भंडारण, जििाि/िून्यीकरण, िैधता, कुंिी पठरितयि/रोटेिि) जििी कुंिी [भाग II—खण् ड 3(ii)] भारत का रािपत्र : असाधारण 5 और प्रमाणपत्र। 1.6 टैम्पर रेजसस्ट्टेंस और/या टैम्पर का पता लगािे िाली सुजिधाओं की उपजस्ट्थजत सत्याजपत करें। सॉफ़्टिेयर और हाडयिेयर से टैंपररंग को रोकिे के जलए जडिाइस में लागू दकए गए उपायों को सत्याजपत करिे के जलए ओईएम टीम की उपजस्ट्थजत में परीिण। जिक्रेता द्वारा जिम्नजलजखत को प्रस्ट्तुत करिा होगा: 1. सॉफ्टिेयर से टैंपररंग रोकिे के जलए जडिाइस संबंधी उपलब्लध उपाय। 2. हाडयिेयर से टैंपररंग रोकिे के जलए जडिाइस संबंधी उपलब्लध उपाय। 1.7 जचप जिमायता द्वारा प्रदाि की गई कोई भी उपलब्लध बौजिक संपदा सुरिा तकिीक सिम है। यदद उपलब्लध हो तो जचप जिमायता द्वारा प्रदाि की गई बौजिक संपदा सुरिा तकिीकों को सिम करिे के जलए ओईएम टीम की उपजस्ट्थजत में परीिण। जिक्रेता द्वारा जिम्नजलजखत को प्रस्ट्तुत करिा होगा: 1. एसओसी की डेटािीट 2. जचप जिमायता द्वारा प्रदाि की गई बौजिक संपदा संरिण प्रौद्योजगदकयों के संबंध में दस्ट्तािेज़ीकरण, जिन्हें सिम दकया गया है। 3. यदद जचप जिमायता द्वारा कोई बौजिक संपदा संरिण तकिीक प्रदाि िहीं की िा रही है, तो एक घोषणा जिसमें समरूप बात हो। 1.8 सत्याजपत करें दक जडिाइस लोड करिे से पहले बूट छजि हस्ट्तािर को सत्याजपत करता है। जिम्नजलजखत को सत्याजपत करिे के जलए ओईएम टीम की उपजस्ट्थजत में परीिण करिा : 1. िैध बूट छजि प्रदाि दकए िािे पर जडिाइस दस्ट्तािेज़ीकृत सुरजित बूट प्रदक्रया के साथ सफलतापूियक बूट हो िाता है। 2. छेडछाड की गई बूट छजि (िैसे जमबसंग हस्ट्तािर, अमान्य हस्ट्तािर) प्रदाि दकए िािे पर जडिाइस बूट िहीं होता है। जिक्रेता द्वारा जिम्नजलजखत को प्रस्ट्तुत करिा होगा: 1. एसओसी की डेटािीट 2. सुरजित बूट के संबंध में जडिाइस के तकिीकी जिजिदेि (इसमें िाजमल कुंजियाँ और उिका प्रबंधि िीिि चक्र * , हस्ट्तािर सत्यापि प्रदक्रया और लागू होिे पर कोई अन्य सुरजित तंत्र िाजमल होिा चाजहए।) 1.9 एम्बेडेड जडिाइस पर दक्रप्टोग्रादफक रूप से सुरजित छद्म- यादृजछछक संख्या ििरेटर के उपयोग को सत्याजपत करें (उदाहरण के जलए, जचप-प्रदत्त यादृजछछक संख्या ििरेटर का उपयोग करके)। जडिाइस में उपयोग दकए िा रहे यादृजछछक संख्या ििरेटर के संबंध में जिक्रेता द्वारा प्रदाि दकए गए दस्ट्तािेज़ का सत्यापि करिा । कोड-समीिा के माध्यम से सत्यापि दक जडिाइस में यादृजछछक संख्या ििरेटर या संबंजधत लाइब्रेरी का उपयोग दकया िा रहा है। जिक्रेता को अपिे इजछछत उपयोग के साथ जडिाइस में उपयोग दकए िा रहे यादृजछछक िेिरेटर (या तो हाडयिेयर आधाठरत या सॉफ़्टिेयर आधाठरत या दोिों) के संबंध में दस्ट्तािेज़ प्रस्ट्तुत करिा होगा। यदद हाडयिेयर आधाठरत यादृजछछक संख्या ििरेटर का उपयोग दकया िा रहा है, तो जिक्रेताओं को जिम्नजलजखत प्रस्ट्तुत करिा होगा: 1. एसओसी की डेटािीट 2. यादृजछछक ििरेटर के संबंध में जडिाइस की तकिीकी जिजििताएँ यदद सॉफ्टिेयर आधाठरत 6 THE GAZETTE OF INDIA : EXTRAORDINARY [PART II—SEC. 3(ii)] यादृजछछक संख्या ििरेटर का उपयोग दकया िा रहा है, तो जिक्रेताओं को इसके जलए उपयोग की िािे िाली लाइब्रेरी प्रदाि करिी होगी। 2. सॉफ्टिेयर/फमयिेयर 2.1 सत्याजपत करें दक एएसएलआर और डीईपी िैसे मेमोरी सुरिा जियंत्रण एम्बेडेड/आईओटी ऑपरेरटंग जसस्ट्टम द्वारा सिम हैं, यदद लागू हो। कमांड लाइि-आधाठरत टूल/कमांड या डीईपी, ईएमईटी टूल िैसे दकसी अन्य ओपि-सोसय टूल का उपयोग करके जडिाइस में उपलब्लध और सिम घोजषत मेमोरी सुरिा जियंत्रणों को सत्याजपत करिे के जलए ओईएम टीम की उपजस्ट्थजत में परीिण करिा । जिक्रेता को जडिाइस में उपलब्लध और सिम मेमोरी सुरिा जियंत्रणों की घोषणा प्रस्ट्तुत करिी होगी। 2.2 सत्याजपत करें दक फमयिेयर ऐप्स रांसपोटय लेयर सुरिा का उपयोग करके रांजज़ट में डेटा की सुरिा करते हैं। 1. यह सत्याजपत करिा दक सुरजित संचार स्ट्थाजपत करिे के जलए सुदृढ़ एजन्क्रप्िि ए्गोठरदम और सुरजित टीएलएस संस्ट्करण जडिाइस द्वारा समर्थयत है। 2. यह सत्याजपत करिा दक जडिाइस सियर के टीएलएस प्रमाणपत्र को िीक से मान्य करता है तादक यह सुजिजित हो सके दक यह जिश्वसिीय है और इसके साथ छेडछाड िहीं की गई है। 3. सुभेिताओं का परीिण िो टीएलएस किेक्ट्िि की सुरिा को प्रभाजित कर सकता है िैसे पैबडंग ऑरेकल हमले, या सुभेि जसफर सुइट्स। 4. खुले पॉट्सय की पहचाि करिे के जलए एिएमएपी िैसे टूल का उपयोग करिा जिसके माध्यम से जडिाइस तक पहुंचा िा सकता है जिससे अिपेजित डेटा पुिप्रायजि हो सकती है। 5. यह सत्याजपत करिा दक टीएलएस सत्र बपयसुइट िैसे टूल का उपयोग करके मैि-इि-द- जमजडल हमलों का उपयोग करके िेटिकय रैदफक के अिरोधि और जडदक्रप्िि के प्रयासों के जलए प्रजतरोधी हैं । जिक्रेता रांसपोटय लेयर सुरिा से संबंजधत एजप्लकेिि और फमयिेयर में उपलब्लध कॉजन्फगरेिि से संबंजधत जिजिदेि और दस्ट्तािेि प्रस्ट्तुत करेगा। 2.3 सत्याजपत करें दक फमयिेयर ऐप्स सियर किेक्ट्िि के जडजिटल हस्ट्तािर को मान्य करते हैं। 1. उि पठरदृश्यों की पहचाि करिा िब जडिाइस बाह्य दुजिया के साथ सियर किेक्ट्िि स्ट्थाजपत करता है और जिम्नजलजखत की पुजि करता है: जिक्रेता को उपयोग के मामलों का उ्लेख करते हुए एक दस्ट्तािेज़ प्रस्ट्तुत करिा होगा िब जडिाइस बाहरी दुजिया के साथ सियर किेक्ट्िि स्ट्थाजपत करता है, जिसमें सियर किेक्ट्िि के जडजिटल [भाग II—खण् ड 3(ii)] भारत का रािपत्र : असाधारण 7 • सुरजित सियर किेक्ट्िि और जडजिटल हस्ट्तािर सत्यापि से संबंजधत सुरिा सुजिधाएँ, िैसे सुदृढ़ साईफर सुइट्स, सुरजित टीएलएस संस्ट्करण, एसएसएल जपबिंग आदद कोड िॉकथ्रू द्वारा समर्थयत हैं। • जडिाइस में उजचत प्रमाणपत्र सत्यापि, प्रमाणपत्र श्ृंखला सत्यापि और प्रमाणपत्र जिरस्ट्तीकरण िांच लागू की िाती हैं। 2. सुभेिताओं का परीिण िो टीएलएस किेक्ट्िि की सुरिा को प्रभाजित कर सकता है िैसे पैबडंग ऑरेकल हमले, या सुभेि जसफर सुइट्स। 3. खुले पोटय की पहचाि करिे के जलए एिएमएपी िैसे टूल का उपयोग करिा जिसके माध्यम से जडिाइस तक पहुंचा िा सकता है जिससे अिपेजित डेटा पुिप्रायजि हो सकती है। 4. यह सत्याजपत करिा दक टीएलएस सत्र बपयसुइट िैसे उपकरणों का उपयोग करके मैि- इि-द-जमजडल हमलों का उपयोग करके िेटिकय रैदफक के अिरोधि और जडदक्रप्िि के प्रयासों के जलए प्रजतरोधी हैं । हस्ट्तािरों को मान्य करते समय सुरिा उपायों के बारे में जिस्ट्तृत िािकारी होगी। 2.4 सत्याजपत करें दक प्रजतबंजधत सी फंक्ट्िंस के दकसी भी उपयोग को उजचत सुरजित समकि फंक्ट्िंस के साथ बदल ददया गया है । जिम्नजलजखत में से दकसी भी दृजिकोण के माध्यम से लाइसेंस प्राि स्ट्थैजतक जिश्लेषण उपकरण का उपयोग करके ओईएम टीम की उपजस्ट्थजत में सुरजित कोड समीिा [स्ट्िचाजलत और मैन्युअल दोिों]: 1. फमयिेयर कोड के साथ जिक्रेता द्वारा मू्यांकि एिेंसी का दौरा करिा और मू्यांकि एिेंसी के पास उपलब्लध लाइसेंस प्राि स्ट्थैजतक जिश्लेषण उपकरण को जिक्रेता द्वारा उपलब्लध करिा होगा: 1. कोड समीिा के जलए फमयिेयर बायिेठरज़। 2. आंतठरक कोड समीिा ठरपोटय 8 THE GAZETTE OF INDIA : EXTRAORDINARY [PART II—SEC. 3(ii)] अपिे जसस्ट्टम में स्ट्थाजपत करिा। [अिुिंजसत] 2. जिक्रेता द्वारा फमयिेयर कोड और उिके पास उपलब्लध दकसी भी लाइसेंस प्राि स्ट्थैजतक जिश्लेषण उपकरण के साथ मू्यांकि एिेंसी का दौरा करिा और मू्यांकि एिेंसी के प्रजतजिजधयों की उपजस्ट्थजत में कोड समीिा गजतजिजध का प्रदियि करिा। 3. मू्यांकि एिेंसी को उिके पास उपलब्लध लाइसेंस प्राि स्ट्थैजतक जिश्लेषण उपकरण स्ट्थाजपत करिे के जलए जिक्रेता साइट पर जसस्ट्टम की ठरमोट एक्ट्सेस प्रदाि करिा। 4. जिक्रेताओं के पास उपलब्लध लाइसेंस प्राि स्ट्थैजतक जिश्लेषण उपकरण के साथ फमयिेयर कोड िाले मू्यांकि एिेंसी को जिक्रेता साइट पर जसस्ट्टम की दूरस्ट्थ अजभगम प्रदाि करिा। 2.5 सत्याजपत करें दक प्रत्येक फमयिेयर तृतीय पि के घटकों, संस्ट्करण और प्रकाजित सुभेिताओं को सूचीबि करिे िाली सामग्री का एक सॉफ्टिेयर जबल रखता है। फमयिेयर पर एफएसीटी िैसे स्ट्िचाजलत उपकरण चलाकर तृतीय-पि घटकों की प्रस्ट्तुत सूची का सत्यापि करिा । साियिजिक रूप से उपलब्लध सुभेद्यता डेटाबेस के माध्यम से तीसरे पि के घटकों में सुभेिताओं की पहचाि करिा तृतीय पि के घटकों में दकसी भी ज्ञात सुभेिता को दूर करिे के जलए फमयिेयर के जलए जियजमत सुरिा अपडेट और पैच प्रदाि करिे के जलए जिक्रेता द्वारा पठरभाजषत प्रदक्रया का सत्यापि और िैधता। जिक्रेता द्वारा जिम्नजलजखत को प्रस्ट्तुत करिा होगा: 1. तृतीय पि के घटकों और संस्ट्करणों सजहत सामग्री के सॉफ़्टिेयर जबल की िािकारी के जलए दस्ट्तािेज़ीकरण करिा । 2. जिम्नजलजखत के जलए संगिि प्रदक्रया और िीजतयां: • तृतीय पि के घटकों में पहचािी गई दकसी भी सुभेिता को संबोजधत करिा और िीक करिा। • ग्राहकों को सुरिा मुद्दों या सुभेिताओं के बारे में सूजचत करिा और उसके जलए सुरिा अद्यति और पैच प्रदाि करिा। 3. उपकरणों के जलए िारी दकए गए पैच/दफक्ट्स के साथ फमयिेयर और तृतीय-पि बाइिरी, लाइब्रेरी और फ्रेमिकय को बिाए रखिे के जलए कॉजन्फगरेिि प्रबंधि प्रणाली और संबंजधत िीजतयां। 2.6 हाडयकोडेड क्रेडेंजिय्स (बैकडोर) के जलए तृतीय-पि बायिेठरज़, लाइब्रेरीज़, जिम्नजलजखत में से दकसी भी दृजिकोण के माध्यम से लाइसेंस प्राि स्ट्थैजतक जिश्लेषण उपकरण का उपयोग करके स्ट्ितंत्र सुरजित जिक्रेता द्वारा उपलब्लध करिा होगा: 1. कोड समीिा के जलए फमयिेयर बायिेठरज़। [भाग II—खण् ड 3(ii)] भारत का रािपत्र : असाधारण 9 फ्रेमिकय सजहत सभी कोड की समीिा की िाती है। कोड समीिा [स्ट्िचाजलत और मैन्युअल दोिों]: 1. फमयिेयर कोड के साथ जिक्रेता द्वारा मू्यांकि एिेंसी का दौरा करिा और मू्यांकि एिेंसी के पास उपलब्लध लाइसेंस प्राि स्ट्थैजतक जिश्लेषण उपकरण को अपिे जसस्ट्टम में स्ट्थाजपत करिा। [अिुिंजसत] 2. जिक्रेता द्वारा फमयिेयर कोड और उिके पास उपलब्लध दकसी भी लाइसेंस प्राि स्ट्थैजतक जिश्लेषण उपकरण के साथ मू्यांकि एिेंसी का दौरा करिा और मू्यांकि एिेंसी के प्रजतजिजधयों की उपजस्ट्थजत में कोड समीिा गजतजिजध का प्रदियि करिा। 3. मू्यांकि एिेंसी को उिके पास उपलब्लध लाइसेंस प्राि स्ट्थैजतक जिश्लेषण उपकरण स्ट्थाजपत करिे के जलए जिक्रेता साइट पर जसस्ट्टम की दूरस्ट्थ पहुंच प्रदाि करिा। 4. जिक्रेताओं के पास उपलब्लध लाइसेंस प्राि स्ट्थैजतक जिश्लेषण उपकरण के साथ फमयिेयर कोड िाले मू्यांकि एिेंसी को जिक्रेता साइट पर जसस्ट्टम की दूरस्ट्थ पहुंच प्रदाि करिा । 2. आंतठरक कोड समीिा ठरपोटय 2.7 सत्याजपत करें दक फमयिेयर ऐप्स जडजिटल हस्ट्तािर को दकसी जिश्वसिीय सियर पर जपि करते हैं। 1. उि पठरदृश्यों की पहचाि करिा िब जडिाइस बाहरी दुजिया के साथ सियर किेक्ट्िि स्ट्थाजपत करता है और जिम्नजलजखत की पुजि करता है: • सुरजित सियर किेक्ट्िि और जडजिटल हस्ट्तािर सत्यापि से संबंजधत सुरिा सुजिधाएँ, िैसे सुदृढ़ जसफर सुइट्स, सुरजित टीएलएस संस्ट्करण, एसएसएल जपबिंग आदद कोड िॉकथ्रू द्वारा समर्थयत हैं। • जडिाइस में उजचत प्रमाणपत्र सत्यापि, प्रमाणपत्र श्ृंखला सत्यापि और प्रमाणपत्र जिरस्ट्तीकरण िांच लागू की िाती हैं जिक्रेता को उपयोग के मामलों का उ्लेख करते हुए एक दस्ट्तािेज़ प्रस्ट्तुत करिा होगा िब जडिाइस बाहरी दुजिया के साथ सियर किेक्ट्िि स्ट्थाजपत करता है, जिसमें सियर किेक्ट्िि के जडजिटल हस्ट्तािरों को मान्य करते समय सुरिा उपायों के बारे में जिस्ट्तृत िािकारी होगी। 10 THE GAZETTE OF INDIA : EXTRAORDINARY [PART II—SEC. 3(ii)] 2.8 (िबोज़ जडबबगंग प्रतीकों को हटािे ) में बाधा डालिे के जलए सुरिा जियंत्रण मौिूद हैं । फमयिेयर ठरिसय इंिीजियररंग में बाधा डालिे के जलए जिक्रेता द्वारा प्रदाि दकए गए सुरिा जियंत्रणों को सत्याजपत करिे के जलए, ओईएम टीम की उपजस्ट्थजत में परीिण करिा । फमयिेयर ठरिसय इंिीजियररंग में बाधा डालिे के जलए जिक्रेता को सुरिा जियंत्रण के संबंध में दस्ट्तािेज़ प्रस्ट्तुत करिा होगा। 2.9 सत्याजपत करें दक फमयिेयर अपडेट प्रदक्रया समय िांच बिाम उपयोग के समय के हमलों के प्रजत संिेदििील िहीं है। जडिाइस में लागू दकए गए उपायों को सत्याजपत करिे के जलए ओईएम टीम की उपजस्ट्थजत में परीिण दकया गया, तादक इसे समय- समय पर उपयोग दकए िािे िाले हमलों के प्रजत प्रजतरोधी बिाया िा सके। जिक्रेता को जडिाइस में लागू दकए गए उपायों को प्रस्ट्तुत करिा होगा तादक इसे समय-िांच बिाम उपयोग के समय के हमलों के प्रजत प्रजतरोधी बिाया िा सके। 2.10 सत्याजपत करें दक जडिाइस इंस्ट्टॉल करिे से पहले कोड साइबिंग का उपयोग करता है और फमयिेयर अपग्रेड फाइलों को मान्य करता है। जिम्नजलजखत को सत्याजपत करिे के जलए ओईएम टीम की उपजस्ट्थजत में परीिण करिा : क. िैध अपडेट पैकेि उपलब्लध कराए िािे पर जडिाइस दस्ट्तािेज़ीकृत सुरजित अपग्रेड प्रदक्रया के साथ सफलतापूियक अपडेट हो िाता है। ख. छेडछाड दकए गए अपडेट पैकेि (िैसे जमबसंग हस्ट्तािर, अमान्य हस्ट्तािर) प्रदाि दकए िािे पर जडिाइस बूट िहीं होता है। जिक्रेता को सुरजित फमयिेयर अपग्रेड प्राि करिे की प्रदक्रया प्रस्ट्तुत करिी होगी जिसमें िाजमल कुंजियाँ और उिका प्रबंधि िीिि चक्र * , हस्ट्तािर सत्यापि प्रदक्रया और लागू होिे पर कोई अन्य सुरजित तंत्र िाजमल होिा चाजहए। 2.11 सत्याजपत करें दक जडिाइस को िैध फमयिेयर के पुरािे संस्ट्करण (एंटी- रोलबैक) में डाउिग्रेड िहीं दकया िा सकता है। यह सत्याजपत करिे के जलए दक जडिाइस को िैध फमयिेयर के पुरािे संस्ट्करणों (एंटी-रोलबैक) में डाउिग्रेड िहीं दकया िा सकता है, ओईएम टीम की उपजस्ट्थजत में परीिण दकया िा रहा है। जिक्रेता को सुरजित फमयिेयर अपग्रेड प्राि करिे की प्रदक्रया प्रस्ट्तुत करिी होगी जिसमें िाजमल कुंजियाँ और उिका प्रबंधि िीिि चक्र * , हस्ट्तािर सत्यापि प्रदक्रया और लागू होिे पर कोई अन्य सुरजित तंत्र िाजमल होिा चाजहए। 2.12 सत्याजपत करें दक फमयिेयर पूियजिधायठरत िेड्यूल पर स्ट्िचाजलत फमयिेयर अपडेट कर सकता है। सत्यापि लागू पठरदृश्य के अिुसार दकया िाएगा: जस्ट्थजत 1: स्ट्िचाजलत ओटीए अपडेट उपलब्लध हैं: इि-फी्ड उपकरणों को स्ट्िचाजलत अपडेट/अपग्रेड िारी करिे के जलए एक मािक संचालि प्रदक्रया जिक्रेता द्वारा प्रस्ट्तुत की िािी आिश्यक है जिसका मू्यांकि, मू्यांकि एिेंसी द्वारा सी20, सी21 और सी22 सुरिा आिश्यकता के अिुसार दकया िा सकता है। जिक्रेता जिम्नजलजखत प्रदाि करेगा: जिक्रेता द्वारा जिम्नजलजखत को प्रस्ट्तुत करािा होगा: 1. उपलब्लध अपडेट के तरीके यािी स्ट्िचाजलत, मैन्युअल या दोिों। 2. उपकरणों को अपडेट िारी करिे के संबंध में संगििात्मक प्रदक्रया और िीजतयां। [भाग II—खण् ड 3(ii)] भारत का रािपत्र : असाधारण 11 जस्ट्थजत 2: स्ट्िचाजलत ओटीए अपडेट उपलब्लध िहीं हैं और जिक्रेता मैन्युअल अपडेट प्रदाि करता है: इि-फी्ड जडिाइसों में मैन्युअल अपडेट/अपग्रेड िारी करिे के जलए जिक्रेता द्वारा एक मािक संचालि प्रदक्रया प्रस्ट्तुत की िािी आिश्यक है जिसका मू्यांकि, मू्यांकि एिेंसी द्वारा सी20, सी21 और सी22 सुरिा आिश्यकता के अिुसार दकया िा सकता है। 3. सुरजित प्रदक्रया अिुरूपता 3.1 सत्याजपत करें दक िायरलेस संचार परस्ट्पर प्रमाजणत हैं। जिक्रेता द्वारा दस्ट्तािेज़ में जिधायठरत आपसी प्रमाणीकरण की प्रदक्रया को सत्याजपत करिे के जलए, ओईएम टीम की उपजस्ट्थजत में परीिण करिा । जिक्रेताओं को िायरलेस संचार िुरू होिे पर जडिाइस में लागू पारस्ट्पठरक प्रमाणीकरण की प्रदक्रया के संबंध में दस्ट्तािेज़ प्रदाि करिा होगा। यदद जडिाइस िायरलेस संचार का समथयि िहीं करता है, तो जिक्रेता को इसके जलए एक घोषणा पत्र प्रदाि करिा होगा। 3.2 सत्याजपत करें दक िायरलेस संचार एक एजन्क्रप्टेड चैिल पर भेिा िाता है। संचार प्रदक्रया सत्यापि में उपयोग दकए िा रहे सभी सुरिा तंत्रों की पहचाि करिा: • ओईएम टीम की उपजस्ट्थजत में परीिण करिा • कोो़ड समीिा • कुंिी-िीिि चक्र प्रदक्रया संबंधी प्रदक्रया लेखा परीिा लेखा परीिा संचार के िायरलेस मोड के माध्यम से भेिे िािे िाले डेटा से छेडछाड को रोकिे के जलए जिक्रेताओं को जडिाइस में लागू सुरिा उपायों के संबंध में दस्ट्तािेि उपलब्लध करािे होंगे। यदद जडिाइस िायरलेस संचार का समथयि िहीं करता है, तो जिक्रेता को इसके जलए एक घोषणा पत्र प्रदाि करिा होगा। 3.3 सत्याजपत करें दक क्ट्या जडिाइस के घटकों की सोर्सिंग के जलए जिश्वसिीय स्रोतों का उपयोग दकया िा रहा है यािी महत्िपूणय हाडयिेयर घटकों (एसओसी िैसे सुरिा कायों से संबंजधत) के जलए सामजग्रयों के प्रबंजधत जबल के माध्यम से जिश्वसिीय आपूर्तय श्ृंखला का उपयोग दकया िा रहा है। जिक्रेता को महत्िपूणय हाडयिेयर घटकों (एसओसी िैसे सुरिा कायों से संबंजधत) के जलए सामग्री का जबल प्रस्ट्तुत करिा होगा। 3.4 आपूर्तय श्ृंखला िोजखम की पहचाि, जिक्रेता जिम्नजलजखत प्रस्ट्तुत करेगा: आपूर्तय श्ृंखला िोजखम की 12 THE GAZETTE OF INDIA : EXTRAORDINARY [PART II—SEC. 3(ii)] मू्यांकि, प्राथजमकता और िमि आयोजित दकया िाएगा। आपूर्तय िृंखला िोजखम/व्यिसाय जिरंतरता योििा िीजत दस्ट्तािेज़, आपूर्तय िृंखला व्यिधाि को संभालिे के तरीके को दिायिे िाली प्लेबुक, घटिा के बाद के सारांि दस्ट्तािेज़ प्रस्ट्तुत करिे और उन्हें प्रदर्ियत करिे की आिश्यकता है। पहचाि, मू्यांकि, प्राथजमकता और िमि दस्ट्तािेज़। आपूर्तय श्ृंखला िोजखम / व्यापार जिरंतरता योििा िीजत दस्ट्तािेि, प्लेबुक िो दिायती है दक आपूर्तय श्ृंखला व्यिधाि को कैसे संभालिा है, घटिा के बाद सारांि दस्ट्तािेिों को प्रस्ट्तुत करिा। 3.5 सत्याजपत करें दक जडिाइस में कोई प्रप्राइइटेरी िेटिकय प्रोटोकॉल का उपयोग िहीं दकया िा रहा है। यदद हाँ, तो संपूणय कायायन्ियि जििरण और उसके जलए स्रोत कोड प्रदाि दकया िाएगा। जडिाइस में प्रयुि िेटिकय प्रोटोकॉल के जलए दस्ट्तािेज़। 4. उत्पाद जिकास चरण में सुरिा अिुरूपता 4.1 िकली िमि और मैलिेयर का पता लगािे में सहायता के जलए पीसीबीए और एसओसी स्ट्तर तक जडिाइि और आर्कयटेक्ट्चर जििरण प्रदाि दकया िाएगा। पीसीबीए और एसओसी स्ट्तर तक जडज़ाइि और आर्कयटेक्ट्चर दस्ट्तािेज़। 4.2 उत्पाद जिकास के जहस्ट्से के रूप में खराब और िकली उत्पादों के जलए खतरा कम करिे की रणिीजतयों को लागू दकया िाएगा। प्रदक्रया और जिजध के जिरूपण साक्ष्य प्रस्ट्तुत करिे और उन्हें प्रदर्ियत करिे की आिश्यकता है। 4.3 कोड स्ट्िीकृजत और जिकास प्रदक्रयाओं के जहस्ट्से के रूप में एक या अजधक अद्यति मैलिेयर पहचाि उपकरण जियोजित दकए िाएंगे। अंजतम पैकेबिंग और प्रदायगी से पहले मैलिेयर पहचाि उि घटकों की सूची जििकी पहचाि टैबिंग/िालसािी, सीएम टूल के रैककंग लक्ष्यों की आिश्यकता के रूप में की गई है। गुणित्ता आश्वासि प्रदक्रया को प्रस्ट्तुत करिे और उसे प्रदर्ियत करिे की आिश्यकता है। [भाग II—खण् ड 3(ii)] भारत का रािपत्र : असाधारण 13 तकिीकों का उपयोग दकया िाएगा (उदाहरण के जलए, एक या अजधक अद्यति मैलिेयर पहचाि उपकरणों का उपयोग करके मैलिेयर के जलए तैयार उत्पादों और घटकों को स्ट्कैि करिा)। 4.4 आपूर्तय श्ृंखला िोजखम की पहचाि, मू्यांकि, प्राथजमकता और िमि आयोजित दकया िाएगा। आपूर्तय श्ृंखला िोजखम / व्यापार जिरंतरता योििा िीजत दस्ट्तािेि, प्लेबुक िो दिायती है दक आपूर्तय श्ृंखला व्यिधाि को कैसे संभालिा है, घटिा के बाद सारांि दस्ट्तािेिों को प्रस्ट्तुत करिे और उसी को प्रदर्ियत करिे की आिश्यकता है। MINISTRY OF ELECTRONICS AND INFORMATION TECHNOLOGY (IPHW Division) ORDER New Delhi, the 9th April, 2024 Subject: Amendment to the “Electronics and Information Technology Goods (Requirement of Compulsory Registration) Order, 2021” S.O. 1652(E).—In exercise of the powers conferred by sub-section (1) and (2) of section 16 read with sub section (3) of section 25 of the Bureau of Indian Standards Act, 2016, (11 of 2016), the Central Government is of the opinion that it is necessary or expedient so to do in the public interest, hereby makes the following amendments to the “Electronics and Information Technology Goods (Requirements for Compulsory Registration) Order, 2021”: 2. For CCTV Camera, the following entry of Column (5) be added at S. No. 41 in the Schedule of the “Electronics and Information Technology Goods (Requirements for Compulsory Registration) Order, 2021. Sr. No. (1) Goods or Articles (2) Indian Standard (3) Title of Indian Standard (4) Essential Requirement(s) (5) 41 CCTV Camera IS 13252: Part 1: 2010 Information Technology Equipment - Safety General Requirements-- Essential Requirement(s) for CCTV as per Annexure 3. The provisions of “Electronics and Information Technology Goods (Requirements for Compulsory Registration) Order, 2021” shall apply on the Goods or articles as specified in the column (2) added to the schedule of the said Order by virtue of this notification, for conforming to the corresponding Essential Requirement(s) as specified in the column (5), on the expiry of six months from the date of publication of this notification in the Official Gazette. As per Scheme II of BIS Conformity Assessment Regulations, 2018, submission of test reports from BIS recognized labs, shall form a pre -requisite for obtaining license to use Standard Mark. [F.No. W-43/11/2021-IPHW] ASHA NANGIA, Group Coordinator & Scientist 'G' 14 THE GAZETTE OF INDIA : EXTRAORDINARY [PART II—SEC. 3(ii)] Annexure Essential Requirement(s) for Security of CCTV Securing a CCTV (Closed-Circuit Television) system is crucial to protect sensitive information and ensure the system operates effectively. Key areas of testing include exposed network services, device communication protocols, physical access to the device’s UART, JTAG, SWD, etc., the ability to extract memory and firmware, firmware update process security and storage and encryption of data. Here are brief requirements for the security of a CCTV system: 1. Physical Security - Use tamper-resistant camera enclosures and locking mechanisms to deter physical tampering. 2. Access Control by Authentication, Role-Based Access Control (RBAC) and regularly review and update access permissions to reflect personnel changes. 3. Network Security by employing encryption of data transmission 4. Software Security by Regular Updates, Disable Unused Features and Strong Password Policies 5. Penetration Testing: Employ penetration testing to assess the system's resistance to cyberattacks and address vulnerabilities. Essential Security Requirements Sr. No. Category Testing Parameter What to be tested Documents Required 1. Hardware Level Security Parameter (supported by software) 1.1 Verify that application layer debugging interfaces such USB, UART, and other serial variants are disabled or protected by a complex password. 1. Identification of the availability of debugging interfaces such as USB, UART, and other serial variants through the Datasheet of the SoC being used in the device under test 2. Verification and validation of the ports/interfaces enabled in the production devices and the related access control mechanism for protection of the same as declared in the vendor documentation 3. Testing, in presence of OEM team, to verify the enabling/disabling of all the ports and debugging interfaces such as USB, UART, and other serial variants using their relevant hardware-based debuggers and access control mechanisms in case the interface is enabled. 4. Process verification of the manufacturing facility to validate the vendor's claim regarding the debugging interfaces which are closed/disabled during provisioning. [For instance, through Block connection diagram depicting pin connections between the host The vendor shall provide the following: a. Datasheet of the SoC being used in the device. b. Documentation related to ports/interfaces enabled in the production devices and the related access control mechanism for protection of the same. c. Process flow of the Manufacturing/Provisioning of the device [भाग II—खण् ड 3(ii)] भारत का रािपत्र : असाधारण 15 microcontroller and its interactions with various sub components/peripherals.] 1.2 Verify that cryptographic keys and certificates are unique to each individual device. Identifying all the keys and certificates being used in the device eco- system and verification through: • Testing, in presence of OEM team • Code review • Process audit of the key-life cycle process Vendor shall submit the following: 1. List of all keys and certificates being used in the device ecosystem 2. Key management life cycle (purpose, generation, storage, destruction/zeroization, validity, key changeover/rotation) 1.3 Verify that on-chip debugging interfaces such as JTAG or SWD are disabled or that available protection mechanism is enabled and configured appropriately. 1. Identification of the availability of debugging interfaces such as USB, UART, and other serial variants through the Datasheet of the SoC being used in the device under test 2. Verification and validation of the ports/interfaces enabled in the production devices and the related access control mechanism for protection of the same as declared in the vendor documentation 3. Testing, in presence of OEM team, to verify the enabling/disabling of all the ports and debugging interfaces such as USB, UART, and other serial variants using their relevant hardware based debuggers and access control mechanisms in case the interface is enabled. 4. Process audit of the manufacturing facility to validate the vendor's claim regarding the debugging interfaces which are closed/disabled during provisioning. [For instance, through Block connection diagram depicting pin connections between the host microcontroller and its interactions with various sub components/peripherals.] The vendor shall provide the following: a. Datasheet of the SoC being used in the device. b. Documentation related to ports/interfaces enabled in the production devices and the related access control mechanism for protection of the same. c. Process flow of the Manufacturing/Provisioning of the device 16 THE GAZETTE OF INDIA : EXTRAORDINARY [PART II—SEC. 3(ii)] 1.4 Verify that trusted execution is implemented and enabled, if available on the device SoC or CPU. Identifying whether TEE/SE/TPM is available or not in the device through the SoC datasheet and technical documentation submitted by the vendor. Further assessment is done on the basis of scenarios as applicable to device as defined below: CASE 1: TEE/SE/TPM is not available: No further assessment CASE 2: TEE/SE/TPM is available and enabled: Verification through code-review that crypto functions are called through TEE/SE/TPM APIs. CASE 3: TEE/SE/TPM is available but not enabled by the vendor: Termed as non- conformance to the requirement. OEM is required to enable and implement the TEE/SE/TPM. The vendor shall provide the following: 1. Datasheet of the SoC being used in the device. 2. User manual/ Technical specifications of the device 3. Code snippets of the TEE API call, wherever applicable 1.5 Verify that sensitive data, private keys and certificates are stored securely in a Secure Element, TPM, TEE (Trusted Execution Environment), or protected using strong cryptography. Identifying all the keys and certificates being used in the device eco- system, sensitive data and their storage mechanism(s); and verification through: • Testing, in presence of OEM team • Code review • Process audit of the key-life cycle process Vendor shall submit the following: 1. List of all keys and certificates being used in the device ecosystem 2. List of all the sensitive data with their intended usage and secure storage mechanism(s) as implemented along with secure configurations to be enabled in the device. 3. Key management life cycle (purpose, generation, storage, destruction/zeroization, validity, key changeover/rotation) private keys and certificates. 1.6Verify the presence of tamper resistance and/or tamper detection features. Testing, in presence of OEM team, to verify the measures implemented in the device to prevent software and hardware tampering. Vendor shall submit the following: 1. Measures available in the device to prevent software tampering. 2. Measures available in the device to prevent hardware tampering. 1.7 Verify that any available Intellectual Testing, in presence of OEM team, to verify the enabling of the Vendor shall submit the following: 1. Datasheet of the SoC [भाग II—खण् ड 3(ii)] भारत का रािपत्र : असाधारण 17 Property protection technologies provided by the chip manufacturer are enabled. Intellectual Property protection technologies provided by the chip manufacturer, if available. 2. Documentation regarding the Intellectual Property protection technologies provided by the chip manufacturer which have been enabled. 3. In case, no Intellectual Property protection technologies are being provided by the chip manufacturer, then a declaration stating the same. 1.8 Verify the device validates the boot image signature before loading. Testing, in presence of OEM team, to verify the following: 1. Device boots up successfully with the documented secure boot process when a valid boot image is provided. 2. Device does not boot up when a tampered boot image (like with missing signature, invalid signature) is provided. Vendor shall submit the following: 1. Datasheet of the SoC 2. Technical specifications of the device regarding secure boot (should consist of keys involved and their management life cycle*, signature validation process and any other secure mechanisms if implemented.) 1.9 Verify usage of cryptographically secure pseudo- random number generator on embedded device (e.g., using chip- provided random number generators). Verification of the documentation provided by the vendor regarding the random number generators being used in the device. Verification through code-review that random number generators or related libraries as applicable are being used in the device. Vendor shall submit the documentation regarding the random generators (either hardware based or software based or both) being used in the device with their intended usage. In case, hardware based random number generators are being used, vendors shall submit the following: 1. Datasheet of the SoC 2. Technical specifications of the device regarding random generators In case, software based random number generators are being used, vendors shall provide the libraries being used for the same. 2. Software/Firmware 2.1 Verify that memory protection controls such as ASLR and DEP are enabled by the embedded/IoT operating system, if applicable. Testing, in presence of OEM team, to verify the declared memory protection controls available and enabled in the device using command line-based tools/commands or any other open-source tool like DEP, EMET tool. Vendor shall submit the declaration of the memory protection controls available and enabled in the device. 2.2 Verify that the firmware apps protect data-in- transit using transport layer 1. Verifying that strong encryption algorithms and secure TLS version is supported by the device to establish secure The vendor shall submit the specifications and documentation related to the configurations available in the applications and 18 THE GAZETTE OF INDIA : EXTRAORDINARY [PART II—SEC. 3(ii)] security. communication. 2. Verifying that device properly validates the server's TLS certificate to ensure that it is trusted and has not been tampered with. 3. Testing for vulnerabilities which can affect the security of TLS connection such as padding oracle attacks, or weak cipher suites. 4. Using tools such as Nmap to identify open ports through which device can be accessed leading to unintended data retrieval. 5. Verifying that theTLS session(s) are resistant to attemptsof interception and decryption of network traffic using man-in-the- middle attacks using tools like Burpsuite. firmware related to transport layer security. 2.3 Verify that the firmware apps validate the digital signature of server connections. 1. Identifying the scenarios when the device establishes the server connections with the external world and verifying the following: • Security features, related to secure server connections and digital signature validation as implemented like strong cipher suites, secure TLS version, SSL pinning etc. supported by code walkthrough. • Proper certificate validation, certificate chain validation and certificate revocation checks are implemented in the device. 2. Testing for vulnerabilities which can affect the security of TLS connection such as padding oracle attacks, or weak cipher suites. Vendor shall submit a document mentioning the use-cases when the device establishes server connections with the external world, with detailed information about the security measures in place while validating the digital signatures of the server connections. [भाग II—खण् ड 3(ii)] भारत का रािपत्र : असाधारण 19 3. Using tools such as Nmap to identify open ports through which device can be accessed leading to unintended data retrieval. 4. Verifying that TLS session(s) are resistant to attemptsof interception and decryption of network traffic using man-in-the- middle attacks using tools like Burpsuite. 2.4 Verify that any use of banned C functions are replaced with the appropriate safe equivalent functions. Secure code review [both automated and manual], in presence of OEM team, using a licensed static analysis tool through any of the following approaches: 1. Visit to the evaluation agency by the vendor with the firmware code and installing the licensed static analysis tool available with the evaluation agency in their systems. [Recommended] 2. Visit to the evaluation agency by the vendor with the firmware code and any licensed static analysis tool available with them and demonstrating the code review activity in the presence of representatives of evaluation agency. 3. Giving a remote access of the systems at vendor site to the evaluation agency for installing their licensed static analysis tool available with them. 4. Giving a remote access of the systems at vendor site to the evaluation agency containing the firmware code along with the licensed static analysis tool available with the vendors. Vendor shall provide : 1. Firmware binaries for code review. 2. Internal code review reports 2.5 Verify that each firmware maintains a software bill of materials cataloging third party Verification of the submitted list of third- party components by running automated tools like FACT on the firmware. Identifying vulnerabilities Vendor shall submit the following: 1. Documentation for information on software bill of materials, including third- party components and versions. 20 THE GAZETTE OF INDIA : EXTRAORDINARY [PART II—SEC. 3(ii)] components, versioning, and published vulnerabilities. in the third-party component(s) through publically available vulnerability databases Verification and validation of the process defined by the vendor for providing regular security updates and patches for the firmware to address any known vulnerabilities in third-party components. 2. Organization process and policies for the following: • Addressing and patching any identified vulnerabilities in third-party components. • Informing the customers about the security issues or vulnerabilities and providing security updates and patches for the same. 3. Configuration management system and related policies for maintaining firmware and third-party binaries, libraries and frameworks along with the patches/fixes issued to the devices. 2.6 Verify all code including third-party binaries, libraries, frameworks are reviewed for hardcoded credentials (backdoors). Independent secure code review [both automated and manual] using a licensed static analysis tool through any of the following approaches: 1. Visit to the evaluation agency by the vendor with the firmware code and installing the licensed static analysis tool available with the evaluation agency in their systems. [Recommended] 2. Visit to the evaluation agency by the vendor with the firmware code and any licensed static analysis tool available with them and demonstrating the code review activity in the presence of representatives of evaluation agency. 3. Giving a remote access of the systems at vendor site to the evaluation agency for installing their licensed static analysis tool available with them. 4. Giving a remote access of the systems at vendor site to the evaluation agency containing the firmware code along with the licensed static analysis tool available with the vendors. Vendor shall provide: 1. Firmware binaries for code review. 2. Internal code review reports [भाग II—खण् ड 3(ii)] भारत का रािपत्र : असाधारण 21 2.7 Verify that the firmware apps pin the digital signature to a trusted server(s). 1. Identifying the scenarios when the device establishes the server connections with the external world and verifying the following: • Security features, related to secure server connections and digital signature validation as implemented like strong cipher suites, secure TLS version, SSL pinning etc. supported by code walkthrough. • Proper certificate validation, certificate chain validation and certificate revocation checks are implemented in the device. Vendor shall submit a document mentioning the use-cases when the device establishes server connections with the external world, with detailed information about the security measures in place while validating the digital signatures of the server connections. 2.7 Verify security controls are in place to hinder firmware reverse engineering (e.g.removal of verbose debugging symbols). Testing, in presence of OEM team, to verify the security controls as provided by the vendor to hinder firmware reverse engineering. Vendor shall submit the documentation regarding the security controls in place to hinder firmware reverse engineering. 2.8 Verify that the firmware update process is not vulnerable to time-of-check vs time-of-use attacks. Testing, in presence of OEM team, to verify the measures implemented in the device to make it resistant to time-of-check vs.time-of-use attacks. Vendor shall submit the measures implemented in the device to make it resistant to time-of-check vs. time-of- use attacks. 2.9 Verify the device uses code signing and validates firmware upgrade files before installing. Testing, in presence of OEM team, to verify the following: 1. Device gets successfully updated with the documented secure upgrade process when a valid update package is provided. 2. Device does not boot up when a tampered update package (like with missing signature, invalid signature) is provided. Vendor shall submit the process of achieving secure firmware upgrade which should consist of keys involved and their management life cycle*, signature validation process and any other secure mechanisms if implemented. 22 THE GAZETTE OF INDIA : EXTRAORDINARY [PART II—SEC. 3(ii)] 2.10 Verify that the device cannot be downgraded to old versions (anti- rollback) of valid firmware. Testing, in presence of OEM team, to verify that the device cannot be downgraded to old versions (anti-rollback) of valid firmware. Vendor shall submit the process of achieving secure firmware upgrade which should consist of keys involved and their management life cycle*, signature validation process and any other secure mechanisms if implemented. 2.11 Verify that firmware can perform automatic firmware updates upon a predefined schedule. Verification shall be done as per the applicable scenario: Case 1: Automatic OTA updates are available: A standard operating procedure for issuing automatic updates/upgrades to the in-field devices is required to be submitted by the vendor which can then be evaluated by the evaluation agency as per C20, C21 and C22 security requirement of OWASP open standard. Case 2: Automatic OTA updates are not available and vendor provides manual updates: A standard operating procedure for issuing manual updates/upgrades to the in-field devices is required to be submitted by the vendor which can then be evaluated by the evaluation agency as per C20, C21 and C22 security requirement of OWASP open standard. Vendor shall provide the following: 1. Modes of updates available i.e. automatic, manual or both. 2. Organizational process and policies regarding the issuing of updates to the devices. 3. Secure Process Conformance 3.1 Verify that wireless communications are mutually authenticated. Testing, in presence of OEM team, to verify the process of mutual authentication as laid down in the documentation by the vendor. Vendors shall provide the documentation regarding the process of mutual authentication as implemented in the device when wireless communications are initiated. In case, the device does not support wireless communications, the vendor shall provide a declaration for the same. 3.2 Verify that wireless communications are sent over an encrypted Identifying all the security mechanisms being used in the communication process verification through: Vendors shall provide the documentation regarding the security measures implemented in the device to prevent tampering of the data [भाग II—खण् ड 3(ii)] भारत का रािपत्र : असाधारण 23 channel. • Testing, in presence of OEM team • Code review • Process audit of the key-life cycle process being sent through wireless mode of communication. In case, the device does not support wireless communications, the vendor shall provide a declaration for the same. 3.3 Verify that whether trusted sources are being used for sourcing the components of the device i.e. trusted supply chain through a managed Bill of materials for critical hardware components (related to security functions like SoC) is in use. Vendor shall submit Bill of materials for critical hardware components (related to security functions like SoC). 3.4 Supply chain risk identification, assessment, prioritization, and mitigation shall be conducted. Supply chain risk/business continuity planning policy documents, playbooks reflecting how to handle supply chain disruption, post-incident summary documents need to be submitted and demonstrate the same. Vendor shall submit the following: Supply chain risk identification, assessment, prioritization, and mitigation documents. Supply chain risk/business continuity planning policy documents, playbooks reflecting how to handle supply chain disruption, post-incident summary documents. 3.5 Verify the no proprietary network protocols are being used in the device. If yes, then complete implementation details and the source code for the same shall be provided. Document for Network protocols used in the device. 4. Security Conformance at 4.1 Design and architecture details till the PCBA and SoC Design and architecture documents till the PCBA and SoC level. 24 THE GAZETTE OF INDIA : EXTRAORDINARY [PART II—SEC. 3(ii)] product development stage level to be provided to aid in counterfeit mitigation and malware detection. 4.2 Threat mitigation strategies for tainted and counterfeit products shall be implemented as part of product development. Process and method artifacts need to be submitted and demonstrate the same. 4.3 One or more up-to-date malware detection tools shall be deployed as part of the code acceptance and development processes. Malware detection techniques shall be used before final packaging and delivery (e.g., scanning finished products and components for malware using one or more up- to-date malware detection tools). List of components that have been identified as requiring tracking targets of tainting/counterfeiting, CM tool. Quality assurance process need to be submitted and demonstrate the same. 4.4 Supply chain risk identification, assessment, prioritization, and mitigation shall be conducted. Supply chain risk/business continuity planning policy documents, playbooks reflecting how to handle supply chain disruption, post-incident summary documents need to be submitted and demonstrate the same. Uploaded by Dte. of Printing at Government of India Press, Ring Road, Mayapuri, New Delhi-110064 and Published by the Controller of Publications, Delhi-110054. MANOJ KUMAR VERMA Digitally signed by MANOJ KUMAR VERMA Date: 2024.04.09 23:09:27 +05'30'
Research the source law
This record is not yet linked to a specific provision. Browse the law library, choose the affected provision and ask against the exact statutory text.
Browse source laws