Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Cyber Response Framework. Show all posts

India Considers Separate AI Regulatory Framework as Government Signals Policy Shift

 

The Indian government is considering a law to govern artificial intelligence (AI) systems, signaling a shift from its previous approach of relying solely on existing information technology laws. Senior officials from the Ministry of Electronics and Information Technology (MeitY) stated that the current developments in this space are so significant that they require legislation. 

Speaking at an industry event this week, MeitY Secretary S. Krishnan said that consultations on laws governing AI had already begun. Both Krishnan and Union IT minister Ashwini Vaishnaw had previously stated that the government would consider separately legislating for AI at an appropriate time, and he added that the moment appeared to be now. 

Existing laws were largely sufficient to address deepfakes or AI-manipulated media, as well as misinformation, fraud, and other issues, he argued, but this was no longer the case as AI became more sophisticated and started to be integrated into critical industries. The new framework would provide guidance on the development of these systems while also protecting citizens, businesses, and critical infrastructure. 

While the government did not set a deadline for legislation, Krishnan noted that MeitY could begin drafting proposals for approval, with the framework then being debated and approved by Parliament. India is not alone in this endeavor as policymakers globally are considering steps to govern AI. A growing number of countries have been looking at laws and policies that seek to address potential risks to privacy, national security, intellectual property, and more while also encouraging innovation. 

The move also marks a notable shift in approach for India, which has largely promoted a lax regulatory environment for technology and adopted a voluntary approach to AI governance, with laws and policies focusing on promoting innovation and adopting existing frameworks for oversight. 

A separate law could add another layer of oversight while also supporting India’s broader ambitions in this space, including IndiaAI Mission, as it looks to promote and bolster its AI ecosystem alongside its digital transformation initiatives. 

Industry stakeholders will also be able to contribute to the process as the government considers its proposals. The law would promote responsible innovation and address risks posed by increasingly ubiquitous and sophisticated AI systems, officials added.

AIIMS Ransomware Attack Leads to a New Cyber Response Framework


On November 23, 2022, the All India Institute of Medical Science, Delhi (AIIMS), suffered a cyber attack  that was labeled by police as “cyber terrorism.” As a result of the cyberattack, offline patient services like appointment booking, billing, and diagnostic reporting of the country’s principal government hospital were halted. 

Since the attack targeted the hospital’s primary and backup servers, patients and the workforce were left with no access to records or test reports for a brief time. In response to the ransomware attack on AIIMS, the government was prompted to create a cyber response mechanism, according to former cybersecurity chief Lt Gen Rajesh Pant.

National Cybersecurity Response Framework

The ransomware attack impelled the government into establishing a national cybersecurity response framework (NCRF). According to Pant, the attack has shone a spotlight on the need to protect “critical infrastructure.” “It was realized that critical sectors need to have a uniform framework to respond to cybersecurity[…]So, the NCRF was conceptualised. It will be put in the public domain for critical infrastructure, such as those in the power and health sectors to implement,” said Pant.

The framework, according to the former NCRF chief, establishes dependable businesses and supply chain procedures and outlines the design of a cyber defense system.

While the National Informatics Centre and Computer Emergency Response Team (CERT-In) teams began working on an investigation into the incident, the Intelligence Fusion and Strategic Operations (IFSO) cell of the Delhi Police filed an FIR against unidentified individuals alleging violations of the cyber terrorism act.

As per Pant, the AIIMS attacks presented certain loopholes in the present cyber defenses, serving as a lesson to be better prepared with critical information infrastructure and address vulnerabilities. “The manner in which the network was architected, was not done by professionals but by a team of doctors. There were too many loopholes in the network, and it was easy to get into the network[…]A lot of lessons have come out from the incident from a government point of view, and these will, hopefully be implemented,” he said. Moreover, he noted that this framework would address some significant gaps in the response mechanisms. “There is a need for standard operating procedures to handle such incidents to that steps for mitigation are taken with immediate effect.”

Adding to this, he addressed a need for inter-ministerial cooperation and the setting up of a nodal ministry to address cybersecurity threats since cybersecurity is constantly evolving. “According to the business allocation rules, no ministry is solely dedicated to addressing such incidents. The concept of peace has changed today, there is no peace in cyberspace,” he added.