Please use this identifier to cite or link to this item:
https://repository.iimb.ac.in/handle/123456789/9404
DC Field | Value | Language |
---|---|---|
dc.contributor.advisor | Venkatgiri, S. | |
dc.contributor.advisor | Mathur, S S | |
dc.contributor.author | Kumar, Anish | |
dc.date.accessioned | 2017-08-30T12:53:10Z | |
dc.date.accessioned | 2019-03-18T06:36:00Z | - |
dc.date.available | 2017-08-30T12:53:10Z | |
dc.date.available | 2019-03-18T06:36:00Z | - |
dc.date.issued | 2011 | |
dc.identifier.uri | http://repository.iimb.ac.in/handle/123456789/9404 | |
dc.description.abstract | Information Security is for sure, one of the most critical element in any information system and its management. Indian Railway has so far not adopted a very robust and comprehensive information security policy all across the country. Railway has created a dedicated organization called CRIS (Centre of Railway Information System), which mostly looks after Passenger Reservation System (PRS), Freight Operation Information System (FOIS), e-tendering/e-procurement related issues etc. etc. On top tier, Indian Railway has an IT Directorate at railway board level, which mainly looks after the policy issues. One of the major objective of carrying out this research is to analyze the different kind of vulnerabilities and attacks that can be mounted upon railways information assets and find out ways and means for its e-security, and also come up with a comprehensive frame work policy, technically and administratively suitable for Indian Railways. In this research, an effort has been made towards incorporating the best practices prevalent all over the world, related with data, network and web application securities. This policy includes how to deal with different type of attacks on network, data and web applications, and how to secure information/data flow. Special emphasis has been given on legal aspects arising out of adoption of electronic transactions (both data/message and monetary transaction), contract formulation and electronic archiving. Indian Railway doesn t have a well defined policy for establishing a full fledged etender/e-procurement cell at all its zonal and divisional level, which can take care of compliances issues related with ISO 17799 standards, impart in house training, increase awareness within and outside the organization (for more industrial participation) and can also conduct audit. IR also doesn t have any definite policy for digital archiving, well planned e-tender box opening strategy and payment gateway integration policy with different banks and revenue department. In this thesis, an attempt has been made towards addressing these issues. | |
dc.language.iso | en_US | |
dc.publisher | Indian Institute of Management Bangalore | |
dc.relation.ispartofseries | CPP_PGPPM_P11_15 | |
dc.subject | Security policy | |
dc.subject | Railways | |
dc.title | Towards an ungraded information security policy for Indian railways | |
dc.type | Policy Paper-PGPPM | |
dc.pages | 159p. | |
dc.identifier.accn | E35707 | |
Appears in Collections: | 2011 |
Files in This Item:
File | Size | Format | |
---|---|---|---|
DIS_PGPPM_P11_15_E35707.pdf | 2.46 MB | Adobe PDF | View/Open Request a copy |
Google ScholarTM
Check
Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.