The Information and Communication Technology (ICT) Department has identified technical weaknesses in the web application of a concerned organization as the primary cause of the massive leak of personal information belonging to millions of citizens from a government website.
The disclosure has raised serious concerns over data security, and prompted the ICT Department to issue a series of recommendations to prevent similar incidents in the future.
Investigations and reviews carried out by the concerned authorities and their technical teams revealed that the web applications lacked proper oversight due to a shortage of manpower with adequate technical knowledge. As a result, cybercriminals were able to exploit vulnerabilities within the system, leading to the unauthorized access and leak of sensitive personal data of Bangladeshi citizens.
The ICT Department has urged the concerned institutions to take immediate action to rectify the errors in their web applications. To ensure a comprehensive approach, the department emphasized the following key recommendations:
Comprehensive Vulnerability Assessment and Penetration Testing (VAPT): The concerned organizations are urged to conduct a complete VAPT of their web applications to identify and address potential weaknesses and security flaws.
Software Architecture Testing: Bangladesh Computer Council (BCC) Software Quality Testing and Certification Center, along with BNDA members of BCC, should conduct thorough testing of the software architecture of existing web applications to ensure robustness and security.
Technical Capacity Enhancement: The concerned organization should focus on increasing the number of technical team members to ensure adequate oversight and expertise in managing web applications.
Cyber security Measures: Forming Computer Incident Response Team (CIRT), Security Operations Center (SOC), and Network Operations Center (NOC) as per the guidelines of the Digital Security Agency is crucial to enhance cybersecurity and protect critical information infrastructure.
Reporting Cybersecurity Breaches: The concerned institutions must promptly report any signs of cybersecurity breaches to the Digital Security Agency, following Critical Information Infrastructure (CII) guidelines.
Adherence to BNDA Guidelines: All systems, software, and web applications should be developed and reviewed according to the Bangladesh National Digital Architecture (BNDA) guidelines and related standards.
Regular IT Audits: Regular IT audits should be conducted, and necessary actions should be taken based on the audit recommendations.
VAPT for Source Code Changes: In case of any changes, enhancements, or modifications in the source code of software/web applications, the concerned organization must initiate a VAPT process by CIRT (BGD E-Gov Cert) following the instructions of BCC SQTC Center and Agency.
Digital Security SOC and NOC: Ensuring the cybersecurity of critical information infrastructures requires the establishment of Digital Security SOC and NOC.
Recruitment and Training: Critical information infrastructure institutions and other government bodies should prioritize the recruitment of skilled manpower with ICT knowledge and provide regular training to enhance technical expertise.
The ICT Department stressed that implementing these recommendations is vital to safeguarding the personal information and privacy of millions of citizens. The government authorities and the concerned organization are expected to take prompt action to address the technical weaknesses and bolster their cybersecurity measures to prevent future data breaches.
It is hoped that these measures will fortify the security posture of government web applications and serve as a model for other organizations in Bangladesh to follow suit and strengthen their data protection practices.