Loading Vaultize
Skip to main content

Union Government, states, and public sector undertakings

Custody does not have to travel

Public records move between ministries, directorates, field and district offices, PSUs, bidders, contractors, consultants, auditors, and inquiry teams. A download or an email attachment can become a copy outside the departmental system.

Vaultize supports on-premises, private cloud, sovereign cloud, hosted, hybrid and air-gapped deployment designs with customer-controlled keys and data, so the record can move while custody stays with the institution. Deployment fit and references are confirmed during solution design.

Where risk concentrates: citizen and beneficiary records, tender and procurement files, inter-department files, PSU operations, and audit and vigilance records enter sovereign custody, and a download or forward creates an uncontrolled copy leading to citizen harm, sovereign exposure, and evidence gaps
government recordsPublic sector undertakingsRegulated workflowsSovereign deployment

Exposure signal

Where Public Record Risk Concentrates

Document exposure changes as citizen, tender, inter-department, PSU, and audit files move between offices, field units, bidders, contractors, and reviewers. Select a column to inspect the handoff risk it represents.

Illustrative exposure pattern, not live security telemetry

Selected threat

Citizen Records

Beneficiary lists, applications, and verification documents are exported for field checks and can outlive the task.

Protected and controlledElevated or exposed risk

The file is often the last mile

A Released Record Is A Separate Risk Decision

Identity, network, and application controls govern the systems that hold a public record. The exposure changes when a citizen file, tender document, note, or audit export is downloaded, forwarded, or retained outside that system.

This is a practical risk view. It is not a determination of regulatory applicability or compliance.

View the risk routeExpand full screen

Union and state government

Scope depends on the department and the processing

DPDP safeguards

Section 8(5) of the Digital Personal Data Protection Act, 2023 requires a Data Fiduciary to protect personal data in its possession or under its control, including processing carried out on its behalf by a Data Processor, by taking reasonable security safeguards. Section 2 defines "person" to include the State, so a department can itself be a Data Fiduciary. The Schedule provides a penalty that may extend to two hundred and fifty crore rupees for breach of that obligation, as determined by the Board.

State exemptions are not general

Section 17(2)(a) disapplies the Act to processing by such instrumentality of the State as the Central Government may notify, on the grounds listed there. That is a notified carve-out rather than a blanket exemption for government bodies, and the Section 17(1) exemptions expressly preserve sub-sections (1) and (5) of Section 8. Applicability should be assessed department by department.

CERT-In reporting

The CERT-In Directions of 28 April 2022 name Government organisations alongside service providers, intermediaries, data centres, and body corporate, and require the cyber incidents listed in Annexure I to be reported within six hours of noticing them or being brought to notice about them.

Official email is a policy question

The E-mail Policy of Government of India provides that only the e-mail services provided by NIC shall be used for official communications by all organizations except those exempted under its clause 14, and that services provided by other providers shall not be used for any official communication. It applies to employees of the Government of India and to State and Union Territory governments that use or adopt it.

GIGW security attributes

The Guidelines for Indian Government Websites require a security audit clearance certificate from NIC, STQC, an STQC-empanelled laboratory, or a CERT-In empanelled laboratory before a government website, web application, portal, or mobile app is hosted in production, and require a Security Policy, Privacy Policy, and Contingency Management Plan approved by the department.

Public Sector Undertakings

Scope depends on the enterprise, the procurement, and the audit

Mandatory e-procurement

Rule 160 of the General Financial Rules, 2017 makes it mandatory for Ministries and Departments to receive all bids through e-procurement portals in respect of all procurements, and Rule 159 makes e-publishing of tender enquiries, corrigenda, and bid awards mandatory for the Central Government, its attached and subordinate offices, and autonomous and statutory bodies, with narrow national-security exemptions.

GeM for common use goods

Rule 149 of the General Financial Rules, 2017 records that the Government of India has established the Government e-Marketplace for common use goods and services, and that procurement by Ministries or Departments will be mandatory for goods or services available on GeM. The rules should be read with the current amendments for the entity concerned.

Bid evaluation confidentiality

The Manual for Procurement of Goods, 2024, published by the Department of Expenditure and listed by the Central Vigilance Commission, states that the technical evaluation report is a confidential document whose contents shall not be disclosed, that all records relating to the evaluation shall be retained until completion of the project and its audit, and that the contractor shall maintain confidentiality and secrecy of the procuring entity's information.

CPSE governance duties

The Department of Public Enterprises Guidelines on Corporate Governance for Central Public Sector Enterprises, continued on a mandatory basis, require board members and senior management to respect the confidentiality of information relating to the affairs of the company and to maintain the confidentiality of unpublished information about its business and affairs, and require the board to integrate risk management into normal business practice. These are governance duties rather than technical security standards.

What audit has found

The Comptroller and Auditor General's Report No. 15 of 2022 on Union Government compliance audit records that unauthorised use of user IDs and passwords by other postal staff or outsiders led to fraudulent withdrawal in four Circles, and recommends that an effective password policy be put in practice as part of an IT security policy to prevent unauthorised usage or login by staff.

Critical Information Infrastructure

Scope depends on notification as a protected system

NCIIPC as nodal agency

By notification S.O. 18(E) of 16 January 2014, made under sub-section (1) of Section 70A of the Information Technology Act, 2000, the Central Government designated the National Critical Information Infrastructure Protection Centre as the national nodal agency in respect of Critical Information Infrastructure Protection.

Protected system obligations

The Information Technology (Information Security Practices and Procedures for Protected System) Rules, 2018 apply to organisations whose systems are notified under Section 70. They require the Chief Information Security Officer to share information security audit reports, post-audit compliance reports, and IT security service level agreements with NCIIPC, and to establish a process for sharing logs of the protected system.

Information in process and transit

The National Cyber Security Policy, 2013 states an objective to enable protection of information while in process, handling, storage, and transit, so as to safeguard privacy of citizen's data and reduce economic losses due to cyber crime or data theft. It is a policy statement, not a directly enforceable rule.

Logs within Indian jurisdiction

The CERT-In Directions of 28 April 2022 also require Government organisations to enable logs of all their ICT systems and maintain them securely for a rolling period of 180 days within the Indian jurisdiction, and to synchronise system clocks with the NTP servers of NIC or NPL, or servers traceable to them.

Cloud residency

MeitY has been empanelling cloud services of Cloud Service Providers since 2015 across public cloud, virtual private cloud, and government community cloud deployment models. The empanelment document requires that cloud services be hosted within India, that data residency be limited to the boundaries of India, and that no data, whether as backups or otherwise, be transmitted outside the boundaries and legal jurisdiction of India.

Ranked by public exposure

Priority Public Records

Swipe the wheel or tap a record class.

Swipe or tap01 / 05
Citizen
Tender
Notes
PSU
Audit

Citizen And Beneficiary Records

01

Privacy · entitlement integrity · public trust

Citizen And Beneficiary Records
01

Leak scenario

A beneficiary list, application pack, verification document, or grievance file is exported for a field check, an implementing agency, or a district office, and is retained after the underlying task is complete.

02

Common stopping point

Departmental applications, portals, and email gateways can control entry and transfer. An exported attachment becomes a separate copy with different storage, forwarding, and retention conditions.

03

Stronger practice

Classify the record, release it to a named recipient, set the permitted use and period, record activity, and withdraw access when the officer is transferred or the purpose closes.

04

Cost of inaction

Where the DPDP Act applies, Section 8(5) requires reasonable security safeguards and the Schedule provides a penalty that may extend to two hundred and fifty crore rupees for breach of that obligation. The CERT-In Directions of 28 April 2022 require Government organisations to report the listed incidents within six hours. In a reply laid before the Rajya Sabha on 31 March 2023, the Ministry of Electronics and Information Technology tabled CERT-In figures of 50 website hacking incidents of Central Ministries, Departments, and State Governments in 2022.

Scope note

Operational risk map only. Regulatory scope depends on the department, entity, activity, record, and current instrument, and certain exemptions apply to the State and its instrumentalities. Linked government sources are authoritative. File controls support a wider governance, security, resilience, and response program; they do not establish compliance by themselves.

Documented Indian public sector incidents

The Record Is Already Public

Public-sector cyber incidents in India have already been placed on the record in written replies to Parliament, Press Information Bureau releases, and a listed PSU's own disclosure to the stock exchanges. In each case the Government or the entity itself put the facts in writing.

Two weeks

of manual working before restoration

Case 01

Operations Went Back To Paper

Case date
Cyber-attack in November 2022; answered in the Lok Sabha on 16 December 2022
Case location
AIIMS, New Delhi
Director of AIIMS, New Delhi at the time
Dr. M. Srinivas

What Happened

The Ministry of Health and Family Welfare told the Lok Sabha that five physical servers of AIIMS, New Delhi, on which the e-Hospital application of NIC was hosted, were affected, and that a First Information Report numbered 349/22 had been registered by the institute with the Special Cell of Delhi Police. The reply records that no specific amount of ransom was demanded, though a message was discovered on the server suggesting that it was a cyber-attack.

What AIIMS New Delhi Faced

The same reply records that day-to-day operations, surgeries, associated activities, and record keeping were done in a manual mode. All e-Hospital data was retrieved from a backup server that was unaffected and restored on new servers, and most functions such as patient registration, appointment, admission, and discharge were restored after two weeks. A later reply of 21 July 2023 repeats those findings and records that a Security Command Centre was established at the institute.

Publicly documented incidents drawn from written replies to Parliament, Press Information Bureau releases, and the company's own stock-exchange filing. The organisations named are not represented as Vaultize customers, and no claim is made that Vaultize would have prevented these events. Dates, locations, leadership roles, figures, and consequences follow the linked primary sources; undisclosed locations are identified as not disclosed. Figures reported only in the press and not confirmed by a primary source are not stated here as fact, and matters recorded by different authorities are stated separately and are not combined.

A deliberate control trail

Make The Release Decision Reviewable

Use the file-level route as part of a broader departmental program. The objective is a clear answer to what was released, to whom, under what conditions, and what activity followed inside a deployment the institution controls.

Controlled record route

A concise record around a high-risk public exchange

ContextRecipientUseExpiryEventsCustody
01

Choose The Deployment First

Decide where the platform and the keys sit before the first file moves. Vaultize runs on-premises, in private cloud, sovereign cloud, hosted, hybrid, or air-gapped environments, with customer-controlled keys and data.

02

Define Priority Records

Start with the citizen, tender, inter-department, PSU contract, and audit files that leave the departmental system most often or create the largest confidentiality, integrity, or availability exposure.

03

Classify By Public Context

Connect the file to its sensitivity, custodian department, purpose, and route so the release decision reflects more than a generic document type.

04

Release To A Known Recipient

Apply the organisation's approved identity, access, and approval process before a high-risk record is shared with another office, a PSU, a bidder, a contractor, or a reviewer, with source-side encryption applied before the file leaves.

05

Bound Permitted Use

Set the relevant access, forwarding, printing, copying, and time conditions for the record and workflow, and withdraw access on transfer, superannuation, or closure of the purpose, subject to the organisation's policy and technical environment.

06

Retain Evidence For Review

Keep release, access, policy-change, revocation, and recovery evidence available to the responsible security, records, vigilance, audit, and incident teams.

Common public sector routes

Start Where Public Files Change Hands

Public records move from scheme intake through procurement, inter-department approval, PSU operations, audit and vigilance, and retention. The map shows where file-level control must remain connected as documents cross each handoff.

Government and PSU record lifecycleFour priority control points
01

Citizen And Scheme Records

Control beneficiary lists, applications, verification documents, and grievance files as they move between headquarters, field and district offices, and implementing agencies.

Purpose-bound citizen exchange

02

Tender And Procurement

Apply a bounded release route to estimates, bid documents, evaluation notes, and award files so confidentiality holds through the period when it matters most.

Accountable bidder access

03

Inter-Department Correspondence

Keep notes, references, and committee papers attributable while they move between ministries, departments, and attached and subordinate offices.

Traceable official routing

04

PSU Contractor And Audit Exchange

Define a controlled file route for vendors, project management consultants, site teams, statutory and internal auditors, and vigilance or inquiry officers handling PSU operating records.

Governed external handoff

Bring one record route

Make One Release Decision Reviewable

Walk through the records, recipients, permitted use, evidence, and deployment model a responsible department or PSU team can verify.

Discuss A Workflow