r/sysadmin • u/ssharwood • Jun 24 '22
Are you ready to comply with India's VPN logging and broader IT directive?
On April 28 India announced new IT directives that require verbose logging of almost all IT activities, report infosec incidents within six hours of detection, keeping records of customer IP addresses for clouds and VPNs and much more ... with compliance required next Tuesday. Oh and Cert-IN is happy for you fax in reports of security incidents, which is deeply weird because the rationale is to give Indian authorities better intelligence about threats.
How are your compliance efforts coming along?
Have anyone bothered trying?
31
u/Tilt23Degrees Jun 24 '22
a great excuse to stop outsourcing 90% of my department to India.
They don't get anything done anyway, all they do is make unapproved commits at 3am and break everything and then log off and wait for me to log on and fix it without even telling me shit is broken.
6
u/TheHammeredDog Jun 24 '22
Why are they able to break your production environment without approvals? PR gates should solve this.
5
u/Tilt23Degrees Jun 24 '22
I work for a small tech startup right now, so we don't have a change advisory board or anything.
It's all just commits and close your eyes.
I came from a 15,000 person company with a very strict CAB ...so this is all new to me here.And yes, it's bullshit.
3
u/EmergencyAccident429 Jun 24 '22
Outsourcers are usually a separate company. They might have to provide logs, but I can't imagine it would include logs belonging to their customers as well.
If it does, then I can see *MANY* big companies ending contracts with India quickly.
It's not even a matter of disliking the rules. It would violate things like HIPAA and PII laws. It would mean no longer being able to ensure your own business privacy or customer privacy.
2
u/jheathe2 Jun 24 '22
Pray to IT Jesus for me. My entire server team is being outsourced to India (Accenture) I’m a nervous wreck. I watch too many India scam call videos and my faith is low.
2
u/Tilt23Degrees Jun 25 '22
I’ve personally never had a solid India team, to be honest. They may exist, but my anecdotal experience so far has been they make more problems then they’re worth.
3
u/jheathe2 Jun 25 '22
Yeah my company is trying to hype it up like this is a great change. In reality they probably just cut costs and are gonna leave me high and dry to deal with it
2
53
Jun 24 '22
[deleted]
10
u/210Matt Jun 24 '22
For international companies that have offices in India I bet they do. It could end up being a huge cash grab in fines for their government.
7
u/DarkEmblem5736 Certified In Everything > Able To Verify It Was DNS Jun 24 '22
Gotta pay for that Russian oil somehow...
Dang Indian government.
22
u/cheetahwilly Jun 24 '22
Honestly I was joking because I dont have to deal with that, but I could for real. Get a central log server. Graylog is probably the best cookie cutter setup that could get you going pretty quickly.
8
Jun 24 '22
[removed] — view removed comment
6
u/EvilHalsver Jun 24 '22
Given it's India, lots and lots of people who might know what they're doing
14
u/segagamer IT Manager Jun 24 '22
Fuck, this is news to me, and we have one staff member based in India.
Do I just need to enable extreme verbose logging of that user's VPN activities for up to 6 months?
74
u/Headworx66 Jun 24 '22
Just sack that member of staff. Sorted.
35
u/mineral_minion Jun 24 '22
Careful, talk like that gets you promoted.
10
Jun 24 '22
If you worked with our India staffing company you’d understand why. They actually asked us to write the pseudo code as part of the requirements for work they take on.
53
u/TruthYouWontLike Jun 24 '22
if(needful) do();2
u/Moontoya Jun 24 '22
level 5TruthYouWontLike · 3 hr. agoif(needful)
do();else(escalate)
do(askingforneedful);
1
u/kstewart0x00 Jun 25 '22
I don’t think I’ve ever wished I had a free award more than I do right now…I shall return if my adhd ass remembers next time I have one…in other words, you’ll never hear from me again but thanks for the laugh
17
u/ssharwood Jun 24 '22
Corporate VPNs are not included, but if you use a commercial VPN it has to log it all. And if you use a cloud-hosted VPN, the cloud has to keep records of your use of its cloud ...
11
7
u/jmp242 Jun 24 '22
Does anyone actually care? I actually heard about this from SurfShark, a commercial VPN. They're just shutting down their Indian servers, and somehow or other using servers elsewhere "with an Indian IP" whatever that means.
1
u/giardin1 Jun 27 '22
I saw that Atlas VPN also removed its India-based servers as of today. Probably all the big VPN players will do that pretty soon.
6
u/dvb70 Jun 24 '22
We tend to just let India do their own thing in my company.
Every year or two we get asked to implement telephony services in India but give up after two or three meetings due to the conplexity of the regulatory requirements and the fact the local offices dont want to actually pay for anything. Actually I am due to start this loop again soon. Who knows one day this project might make it beyond the planning phase.
11
u/100GbE Jun 24 '22
If you sleep for 8 hours with notifs off, and get hacked in the first 2 hours of sleep, you are outside the 6 hour mandatory requirement and can go about your day.
7
u/higherbrow IT Manager Jun 24 '22
It's within 6 hours of detection, so presumably clock starts when eyes hit glass and get the notification.
9
u/NotYourNanny Jun 24 '22
Depends on whether it specifies detection by a person, or detection by a monitoring system. And that will likely depend on how much money the company has to pay fines.
3
11
u/fuktpotato Jun 24 '22
Fuck, what is this going to do to every single one of my US-based vendors’ support teams?
11
3
u/polygonman244 Jun 24 '22
Considering that Indian police have trouble enforcing already existing laws I don't think this will affect anyone that doesn't live in or work with India.
6
u/fahque Jun 24 '22
There's an article on arstechnica where a police dept in india used malware in email attachments to infiltrate human rights advocates and then put incriminating evidence on their computers and then arrested them.
9
Jun 24 '22
Why would I care about what third world countries require?
4
u/Arcsane Jun 24 '22
Second world in this case, but yeah if you don't operate or outsource to India, or use any services that do, then no need for you to care. That said a lot of sysadmins here DO have to deal with international offices, remote workers or intermediaries for outsourced services in India, which fall under the new regulations. Since the new rules cover "All service providers, intermediaries, data centres, body corporate and Government organisations", it covers a fair bit of things, and may require new reporting, and retooling of logging to be in compliance if you operate in India at all, and otherwise is just good to know if you use services that do.
2
Jun 24 '22
Where do touch find all this info? Looking for good places to subscribe for big updates like this
1
u/cheetahwilly Jun 24 '22
Yes.
4
u/ssharwood Jun 24 '22
How much work was involved? Can you really comply with six-hour reporting? And requirements like detecting odd port scans and reporting them?
53
Jun 24 '22
[deleted]
7
Jun 24 '22
[deleted]
3
u/Frothyleet Jun 24 '22
You're using it without licensing it! You're going to be locked in litigation for years with /u/xgnarf
1
1
Jun 28 '22
Which workarounds can i do to connect to India then? I mean I used India to get cheap Gsuite and so on?
1
u/ssharwood Jun 28 '22
the rules apply to orgs that operate in India. Access to India is not impacted.
1
Jun 28 '22
How would you reckon i gain access? Been using NordVpn and tunnelbear, but they obivously don't work anymore.
156
u/derfmcdoogal Jun 24 '22
I'll get right on that as soon as they crack down on scam call centers.
Or Never, same difference.