All officials must use NIC-provided email Id’s, departments to do census; audit of infrastructure
WAJAHAT SHABIR
SRINAGAR: In view of the growing risks associated with unauthorized digital platforms, outdated hardware/software infrastructure, and increasing incidents of data compromise and phishing, a set of instructions has been issued to all departments by the administration on Wednesday.
The instructions comes after a meeting was conveyed under the chairmanship of the Chief Secretary, Jammu & Kashmir, wherein the need for enforcing a secure, standardized, and policy- compliant digital and IT environment across Government establishments was extensively deliberated.
In this regard, a circular has been issued by the General Administration Department.
It has come to notice that various departments are operating official websites using private domains such as “-com”, L”.org”, or l’.net”, which are not aligned with Government of India guidelines on official domain usage, the circular.
Accordingly, all such privately hosted/unauthorized departmental websites shall be deactivated forthwith. NIC, J&K Centre shall assist departments in migrating all existing websites to secure and authenticated government domains, preferably under or “.jk.gov.in”. No future departmental websites shall be developed or hosted on non-government domains. All proposals for new websites must be routed through NIC and approved by the IT Department, the instructions read.
Further to maintain data confidentiality and prevent leakage of sensitive information, No official communication shall be made or responded to, if transmitted from non-government email accounts such as Gmail, Yahoo, Rediffmail, etc. All officers/officials shall mandatorily use NIC-provided email Ids (…@jk.gov.in / [email protected]) for all forms of official correspondence.
HoDs shall ensure immediate issuance and activation of official NIC email IDs for all staff involved in administrative or public-facing roles. Any emails received from non-NIC domains shall be treated as unofficial and may not be acted upon.
All departments shall ensure that procurement of IT hardware (laptops, desktops, printers, routers, etc.) conform to the minimum technical specifications notified by the Information Technology Department. Departments must discontinue usage of pirated or obsolete software, including unlicensed office suites, design tools, or database applications. Software currently in use shall be regularly updated, and upgrades shall be planned for systems approaching end-of-support dates.
Each department shall submit a detailed compliance report to the Information Technology Department through their respective Administrative Departments within 15 days of issuance of this circular.
The report shall specifically indicate: Domain name status of departmental websites; Compliance with government email usage; Audit findings from IT infrastructure census and List of pirated/outdated software, if any, and proposed rectification plan.
All Chief Information Security Officers (CISOs) / Information Security Officers (ISOs) designated in each department shall conduct a detailed census and audit of infrastructure, which shall include: Number and specifications of desktop/laptop systems; Status of operating systems (licensed / unlicensed, updated / outdated); Inventory of installed software (genuine vs pirated); and Antivirus/firewall status and last update logs.
