This circular, issued by the Central Drugs Standard Control Organization (CDSCO) on October 27, 2021, addresses the high risk of virus attacks and data breaches affecting computer systems within CDSCO and its associated laboratories. Recent ransomware attacks resulting in data encryption prompted consultation with CERT-In (Ministry of Electronics and Information Technology). The circular outlines mandatory best practices for individual users to safeguard against data breaches, including: using strong, unique passwords and password managers; enabling two-factor authentication; regularly updating software and antivirus solutions; exercising caution with unsolicited links and email attachments; verifying HTTPS and valid certificates for online payment websites; avoiding sharing personal information or OTPs over phone calls; and refraining from installing apps at the request of unknown individuals. Users are directed to https://www.cyberswachhtakendra.gov.in for security best practices and bot removal tools. The circular was issued with the approval of the Competent Authority and is disseminated to all CDSCO officers, staff, labs, field offices, and the IT cell for website posting. Contact for further information: Amit Kumar, Dy. Director Admn.
Key Entities Referenced
DIRECTORATE GENERAL OF HEALTH SERVICES: A department under the Government of India responsible for public health.
CENTRAL DRUGS STANDARD CONTROL ORGANIZATION: National Regulatory Authority responsible for regulating drugs and cosmetics in India.
New Delhi: Capital of India, where the CDSCO headquarters is located.
VIRUS: Refers to computer viruses that pose a threat to CDSCO's computer systems.
Ransomware: A type of malicious software mentioned as a specific threat that encrypted sensitive data.
CERTIN: Computer Emergency Response Team of India, an office within the Ministry of Electronics and Information Technology.
Ministry of Electronics and Information Technology: A ministry of the Indian government.
Office of DCGI: Office of Drugs Controller General of India, head of CDSCO
File No.D.21013/116/2021-DC
F.No.D.21013/116/2021-DC
DIRECTORATE GENERAL OF HEALTH SERVICES
CENTRAL DRUGS STANDARD CONTROL ORGANIZATION
New Delhi
Date: - 27.10.2021
CIRCULAR
The computer systems installed in CDSCO and Laboratories under its control
are under high risk due to different types of VIRUS available over Internet,
which can crash/delete all the official data in computer systems. It may also be
noteworthy that that downloading of unnecessary files in some systems as well as
using of harmful applications may cause serious damage to the data of ‘computer
systems of CDSCO and Laboratories under its control.
2. Recently, we have come across a Ransomware (hoop virus) attack due to
which sensitive data has got encrypted. After due consultation with CERT-IN under
Ministry of Electronics and Information Technology for tackling such situations.
CERT-IN has apprised us about common causes of data breach/ data leak and best
practices for individual users to safeguard against data breaches and the same are
mentioned below for information and strict compliance.
Best practices for individual users to safeguard against data breaches: -
i. Use strong and unique passwords for all the online accounts. Use a password
manager software. Use different passwords for different online accounts.
ii. Enable two-factor authentication wherever available.
iii. Regularly update all the software on computers, smart phones and other
devices. Install a reputed anti-virus solution on systems, keep it updated and
configure it to run scans periodically.
iv. Be vary of clicking links received in unsolicited SMS messages or emails. Do not
open email attachments from unknown senders. Limit sharing personal information
on public online forums.
V. While making online payments, ensure that the merchant website as well as the
payment gateway websites are running on HTTPS and have a valid certificate (usually
shown as a "green lock" symbol near the address bar in most browsers).
vi. Do not share personal information, OTPs etc. over phone calls purporting to
come from customer service, bank etc. Refuse to install any apps on smartphone /
computer if asked to do so by an unknown person over phone call or in person.
vii. Refer to website https://www.cyberswachhtakendra.gov.in for security best
practices and free bot removal tools for computers and mobile devices.
This issue with the approval of Competent Authority.
2 the
(Amit Kumar) Y
Dy. Director Admn. (D)
Copy to:
1. Office of DCG(I).
2. All Officers/staff of CDSCO (HQ), Labs and field offices.
3. IT cell with the request to upload on the CDSCO website.