1. Executive Mandate & Purpose
The National Pharmaceutical Pricing Authority (NPPA), an attached office of the Department of Pharmaceuticals, Ministry of Chemicals and Fertilizers, Government of India, serves as the apex regulatory body for enforcing the Drugs (Prices Control) Order (DPCO). This Website Security Policy (WSP) establishes a robust, hardened cyber defence framework for the official NPPA web portal (nppa.gov.in) and its linked infrastructure components, including the Integrated Pharmaceutical Database Management System (IPDMS). The purpose of this document is to ensure absolute continuous availability, high structural data integrity, and strict confidentiality of statutory drug pricing schemas, ceiling price calculations, public notifications, and legal manufacturing compliance records. This framework strictly adheres to Section 70 of the Information Technology Act, 2000, and standard guidelines formulated under the Guidelines for Indian Government Websites (GIGW 3.0).
2. Scope & Applicable Infrastructures
This security framework applies universally across the following processing matrices:
- Public Front-End Interface: Static content delivery systems, price lookup tabs, and public grievance nodes hosted across National Informatics Centre (NIC) data centres.
- Integrated Pharmaceutical Database Management System (IPDMS): The secure application engine managing enterprise data submissions, product manufacturing updates, and bulk compliance records.
- Internal Administrative CMS Nodes: Backend access paths deployed for content upload, role-based database modifications, and mathematical price calculation processing.
3. Technical Security Controls & Encryption Standardisation
To mitigate common application-layer and network exploits, the following stateful protections are permanently implemented:
3.1 In-Transit and At-Rest Data Protection
All incoming and outgoing traffic must utilize Transport Layer Security (TLS 1.3) protocol configurations. Legacy encryption standards, including TLS 1.0, TLS 1.1, and SSLv3, are programmatically dropped at the load balancer level. Perfect Forward Secrecy (PFS) keys must be re-negotiated continuously. All production databases containing ceiling matrices or proprietary manufacturer filings must employ Advanced Encryption Standard (AES-256-GCM) column-level structures at rest.
3.2 Perimeter Defence & Application Layer Filtering
An enterprise-grade, stateful Web Application Firewall (WAF) must actively intercept all public HTTP/HTTPS vectors. The firewall must be mapped to automated OWASP Top 10 rule pools to block Cross-Site Scripting (XSS), SQL Injection (SQLi), Remote File Inclusion (RFI), and cross-site forgery attempts instantly. Volumetric Distributed Denial of Service (DDoS) requests must be routed dynamically through multi-tier cloud-scrubbing mitigation complexes.
4. User Access Management & Multi-Factor Protocols
Access to internal administration panels and the enterprise backend environment follows the principle of least privilege (PoLP) and strict Zero-Trust paradigms:
- Role-Based Access Control (RBAC): Logical database operations must be compartmentalized into rigid system categories: Content Contributors, Content Moderators, System Analysts, and Core Database Administrators.
- Multi-Factor Authentication (MFA): All system management sessions must require an encrypted hardware security token alongside strict time-based one-time password (TOTP) structures.
- Digital Signature Verification: Pharmaceutical manufacturers submitting mandatory pricing documentation or compliance reports must complete filing execution workflows using verified Class-3 Digital Signature Certificates (DSC).
5. Technical Audit Schedule & Compliance Parameters
To ensure an active 'Safe to Host' security baseline, the technical operations division must implement a continuous evaluation cycle under the guidance of empanelled agencies. The table below charts the mandatory technical verification lifecycle:
| Security Focus Category | Technical Safeguard Standard | Audit Interval | Target Metrics Baseline |
|---|---|---|---|
| Application Penetration Testing | Full black-box / white-box inspection by CERT-In empanelled auditors. | Bi-Annually / Post-Updates | Zero open critical vulnerabilities; formal Safe-to-Host certificate issue. |
| Vulnerability Assessment (VA) | Automated vulnerability scanning against known vulnerability databases. | Bi-Weekly | Immediate isolation and tracking of low/medium risk alerts. |
| Database Activity Audit | Comprehensive tracking of all database queries modifying ceiling rows. | Continuous / Automated | Immutable, cryptographically chained logs stored offsite. |
| Core Infrastructure Patching | Testing and staging of vendor operating system patches. | Within 48 Hours of Release | Elimination of outstanding zero-day infrastructure defects. |
6. Security Incident Escalation & Legal Recovery Rules
In the event of an infrastructure breach, network infiltration, or web application defacement, the system operator must immediately deploy the following triage mechanisms:
- System Isolation: The targeted application instance must be dynamically detached from public routing networks within 5 minutes of automated threshold alerts to prevent data leakage.
- CERT-In Notification: A formal, encrypted incident layout summary must be transmitted to the Indian Computer Emergency Response Team (CERT-In) within 6 hours of discovery, as legally required under federal advisory frameworks.
- Legal Enforcement Action: Any unauthorized configuration modification, data deletion, or attempt to disable security systems will be handled with severe legal escalation. The legal unit will initiate proceedings under Sections 43, 66, and 70 of the Information Technology Act, 2000, carrying mandatory prosecution pipelines and stringent statutory fines.