logo

Rajiv Gandhi
University

Contingency Management Plan

Contingency Management Plan

Effective date: 29.09.2026 · Approved by: Joint Director (CC) · Last reviewed: 30.09.2026

Rajiv Gandhi University shall maintain procedures for responding to website outages, unauthorised changes, data loss, hosting failures and other disruptions.

The Web Information Manager shall coordinate the response. Authorised technical personnel and the hosting provider shall manage investigation and recovery, while the relevant departments shall verify restored content.

Response procedure

  1. Record and assess: Identify the affected services, time of detection and immediate risks. Preserve relevant logs and evidence.
  2. Contain: Restrict affected functions or place the website in maintenance mode where necessary to protect users and information.
  3. Communicate: Notify designated University officers and the hosting provider. Use an approved alternative communication channel if the website is unavailable.
  4. Investigate and correct: Identify the cause, address the weakness and replace compromised credentials where required.
  5. Restore: Recover from a verified, suitable backup and check the restored application, database and uploaded files.
  6. Validate and reopen: Confirm that essential functions, access controls and content operate correctly before restoring normal service.
  7. Review: Document the incident, recovery actions, remaining risks and measures to prevent recurrence.

Recovery arrangements

The approved recovery arrangements shall specify:

  • Maximum acceptable interruption: [approved recovery time]
  • Maximum acceptable loss of recent data: [approved recovery point]
  • Backup frequency and retention: [approved schedule]
  • Recovery responsibilities and alternate contacts: [controlled contact register]

Reporting and exercises

Reportable cyber incidents shall be notified to CERT-In within the applicable deadline, including the six-hour requirement where it applies. Reporting shall not wait for completion of the investigation.

Recovery procedures shall be exercised at least annually and after significant infrastructure changes. Detailed contact and recovery information shall be maintained in a controlled operational document.

You are leaving the RGU website

You are about to leave our website and visit . Do you want to continue?

Okay