preloader

Integrated Pharmaceutical Data Base Management System / Pharma Data Bank

● For IPDMS 2.0 Registration
● Visit Click Here
● For IPDMS 2.0 Registration Instructions
● Visit Click Here

Contingency Management Plan

1. Objective & Operational Scope

The primary objective of this Contingency Management Plan (CMP) is to establish an uncompromised structural framework for the National Pharmaceutical Pricing Authority (NPPA) web portal (nppa.gov.in). The portal hosts mission-critical statutory public records, including Drug Prices Control Orders (DPCO), the National List of Essential Medicines (NLEM), and active institutional pricing ceilings.

This policy defines definitive automated and manual operational strategies to minimize system downtime, protect immutable pricing configurations from defacement, block distributed exploits, and guarantee complete emergency information continuity during infrastructure collapse or high-impact cybersecurity incidents.

2. Contingency Classification Matrix

Incidents disrupting portal operations are categorized under distinct operational tracks to trigger appropriate response levels:

  • Track A: Complete Infrastructure Outage: Total failure of primary hosting servers at National Informatics Centre (NIC) data hubs due to electrical, hardware, or network termination.
  • Track B: Malicious Cyber Attack & Defacement: Unauthorized root-access, cross-site scripting (XSS), SQL Injection injections, or cosmetic defacement altering official price metrics.
  • Track C: Volumetric Exploits (DDoS): High-volume Distributed Denial of Service attacks choking state gateway interfaces and locking out domestic pharmaceutical manufacturers.
  • Track D: Data Degradation & Corruption: Unintended cryptographic database structural failures impacting historical price registries.

3. Incident Response Workflow & Escalation Protocols

Upon detection of any operational anomaly, the system automatically triggers the following response timeline:

Incident Class Initial Triage Time Primary Action Group Escalation Authority
Track A: Server Outage Within 15 Minutes NIC Cloud Infrastructure Team Director (IT), NPPA
Track B: Defacement / Breach Immediate (<5 Mins) Cyber Security & Incident Response Member Secretary, NPPA
Track C: Volumetric DDoS Within 10 Minutes Network Security Engineers Joint Director (IT)
Track D: Database Corruption Within 30 Minutes Database Administrators Adviser (Pricing), NPPA

4. Technical Failover & Data Redundancy Infrastructure

To ensure seamless state continuity, the portal relies on a geographic hot-standby architecture:

  • Near-Line Hot Swapping: Secondary mirror nodes located in a separate geographic NIC data center must automatically assume production load balancing within 20 minutes of main cluster termination.
  • Static Contingency Target (SCT): During extreme infrastructure failures, the DNS routes traffic to a lightweight, static version of the portal displaying pre-cached PDF orders of critical pharmaceutical ceiling prices.
  • Continuous Recovery Point Objectives (RPO): Databases handling IPDMS data and retail notifications must maintain a 4-hour RPO with incremental write-ahead transaction logging stored securely offsite.

5. Defacement Recovery & Integrity Rollbacks

In the event of unauthorized cosmetic or tabular modifications by bad actors:

  1. Automated Isolation: The host platform must immediately unpublish the altered node and sever network sockets to database layers to prevent secondary privilege escalation.
  2. Cryptographic Checksum Verification: The platform runs automated system integrity scans, comparing production file hashes against pre-calculated SHA-256 signatures.
  3. Gold-Image Rollback: The Portal Administrator reinstates the system to its last verified 'Gold Image' baseline exclusively through internal NIC secure staging pipelines.

6. Public Relations & Emergency Communications

During prolonged portal unavailability exceeding 4 hours:

  • Alternative Channels: Official press communiques and critical pricing decrees shall be disseminated via the Press Information Bureau (PIB) and validated alternate government social media handles.
  • Stakeholder Advisory: The NPPA Media Liaison officer will explicitly issue direct warnings to apex pharma trade bodies (IDMA, OPPI, BDMA) regarding interim offline operating systems.

7. Comprehensive Testing, Mock Drills & Audits

This plan is dynamic and requires mandatory periodic assessment to remain functional:

  • Bi-Annual Disaster Drills: Simulated server failures and defacement scenarios must be executed twice every calendar year to evaluate operational readiness.
  • Post-Incident Audit Reviews: Every active invocation of this plan requires a full forensic reporting structure to be submitted to CERT-In within 48 hours of baseline stabilization.