5. Basic requirements of GoI e-mail Service
5.1 Security
(a) Considering the security concerns with regard to a sensitive deployment like e-mail, apart from the service provided by the IA, there would not be any other e-mail service under GoI.
(b) All organizations, except those exempted under clause 14 of this policy, should migrate their e-mail services to the centralized deployment of the IA for security reasons and uniform policy enforcement. For the purpose of continuity, the e-mail address of the organization migrating their service to the IA deployment shall be retained as part of the migration process. Wherever it is technically feasible, data migration shall also be done.
(c) Secure access to the GoI email service
(i) It is recommended for users working in sensitive offices to use VPN[7]/OTP[8] for secure authentication as deemed appropriate by the competent authority.
(ii) It is recommended that GoI officials on long deputation/stationed abroad and handling sensitive information should use (VPN)/(OTP) for accessing GoI e-mail services as deemed appropriate by the competent authority.
(iii) It is recommended that Embassies and missions abroad should use Static IP addresses for accessing the services of the IA as deemed appropriate by the competent authority.
(iv) More information is available under Guidelines for E-mail Management and Effective E-mail Usage at http://www.deity.gov.in/content/policiesguidelines under the caption E-mail Policy .
(d) From the perspective of security, the following shall be adhered to by all users of GoI email service:
(i) Relevant Policies framed by Ministry of Home Affairs, relating to classification, handling and security of information shall be followed.
(ii) Use of Digital Signature Certificate (DSC)[6] and encryption shall, be mandatory for sending e-mails deemed as classified and sensitive, in accordance with the relevant policies of Ministry of Home Affairs. Updation of current mobile numbers under the personal profile of users is mandatory for security reasons. The number would be used only for alerts and information regarding security sent by the IA. Updation of personal e-mail id (preferably from a service provider within India), in addition to the mobile number, shall also be mandatory in order to reach the user through an alternate means for sending alerts.
(iii) Users shall not download e-mails from their official e-mail account, configured on the GoI mail server, by configuring POP[9] or IMAP [10] on any other e-mail service provider. This implies that users should not provide their GoI e-mail account details (id and password) to their accounts on private e-mail service providers.
(iv) Any e-mail addressed to a user, whose account has been deactivated/deleted, shall not be redirected to another e-mail address. Such e-mails may contain contents that belong to the Government and hence no e-mails shall be redirected.
(v) The concerned nodal officer of the organization shall ensure that the latest operating system, anti-virus and application patches are available on all the devices, in coordination with the User.
(vi) In case a compromise of an e-mail id is detected by the IA, an SMS alert shall be sent to the user on the registered mobile number. In case an attempt to compromise the password of an account is detected, an e-mail alert shall be sent. Both the e-mail and the SMS shall contain details of the action to be taken by the user. In case a user does not take the required action even after five such alerts (indicating a compromise, the IA reserves the right to reset the password of that particular e-mail id under intimation to the nodal officer of that respective organization.
(vii) In case of a situation when a compromise of a user id impacts a large user base or the data security of the deployment, the IA shall reset the password of that user id. This action shall be taken on an immediate basis, and the information shall be provided to the user and the nodal officer subsequently. SMS shall be one of the prime channels to contact a user; hence all users should ensure that their mobile numbers are updated.
(viii) Forwarding of e-mail from the e-mail id provided by GoI to the Government official's personal id outside the GoI e-mail service is not allowed due to security reasons. Official e-mail id provided by the IA can be used to communicate with any other user, whether private or public. However, the user must exercise due discretion on the contents that are being sent as part of the e-mail.
(ix) Auto-save of password in the Government e-mail service shall not be permitted due to security reasons.
(x) More details regarding security measures are available in NIC Security Policy at http://www.deity.gov.in/content/policiesguidelines under the caption E-mail Policy .
(xi) The guidelines for effective e-mail usage have been described in Guidelines for Email Account Management and Effective E-mail Usage available at http://www.deity.gov.in/content/policiesguidelines under the caption Email Policy .
5.2 E-mail Account Management
(a) Based on the request of the respective organizations, IA will create two ids, one based on the designation and the other based on the name. Designation based id's are recommended for officers dealing with the public. Use of alphanumeric characters as part of the e-mail id is recommended for sensitive users as deemed appropriate by the competent authority.
(b) Government officers who resign or superannuate after rendering at least 20 years of service shall be allowed to retain the name based e-mail address i.e. userid@gov.in for one year post resignation or superannuation. Subsequently, a new e-mail address with the same user id but with a different domain address (for instance, userid@pension.gov.in), would be provided by the IA for their entire life.
More details pertaining to e-mail account management are provided in Guidelines for Email Account Management and Effective E-mail Usage available at http://www.deity.gov.in/content/policiesguidelines under the caption Email Policy . The document covers creation of E-mail addresses, process of account creation, process of handover of designation-based ids, status of account after resignation and superannuation, data retention & backup and deactivation of accounts.
5.3 Delegated Admin Console
Organizations can avail the Delegated Admin Console service from IA. Using the console the authorized person of an organization can create/delete/change the password of user ids under that respective domain as and when required without routing the request through IA. Organizations that do not opt for the admin console need to forward their requests with complete details to the IA's support cell (support@gov.in).
5.4 E-mail Domain & Virtual Hosting
(a) GoI provides virtual domain hosting for e-mail. If an organization so desires, the IA can offer a domain of e-mail addresses as required by them. This implies that if an organization requires an address resembling the website that they are operating, IA can provide the same.
(b) By default, the address userid@gov.in shall be assigned to the users. The user id shall be created as per the addressing policy available at http://www.deity.gov.in/content/policiesguidelines/ under E-mail Policy .
(c) Organizations desirous of an e-mail address belonging to other domains (e.g. xxxx@deity.gov.in, yyyy@tourism.gov.in) need to forward their requests to the IA
5.5 Use of Secure Passwords
All users accessing the e-mail services must use strong passwords for security of their e-mail accounts. More details about the password policy are available in Password Policy at http://www.deity.gov.in/content/policiesguidelines under the caption E-mail Policy .
5.6 Privacy
Users should ensure that e-mails are kept confidential. IA shall take all possible precautions on maintaining privacy. Users must ensure that information regarding their password or any other personal information is not shared with anyone.