Security Policy
These provisions define controls to adopt and do not certify their current implementation.
Effective date: 29.09.2026 · Approved by: Joint Director (CC) · Last reviewed: 30.09.2026
Rajiv Gandhi University shall protect its website, supporting systems and information against unauthorised access, alteration, disclosure and disruption.
Access and authentication
Administrative access shall be assigned to identified, authorised individuals according to their responsibilities. Access shall be reviewed regularly and withdrawn when no longer required. Administrative accounts shall use strong authentication, including multi-factor authentication, secure recovery procedures and protection against repeated unsuccessful login attempts.
Application and information protection
The technical team shall maintain secure configurations, apply necessary updates and address identified vulnerabilities according to their severity. Application controls shall include server-side validation, permission checks, secure session handling and restrictions on file uploads.
Sensitive configuration, credentials and backups shall be protected from public access. Personal information shall be accessible only to authorised personnel for approved purposes and handled in accordance with the Privacy Policy.
Changes and security reviews
Changes shall be reviewed and tested before release, with a documented recovery or rollback procedure. Required security audits and reassessments shall be arranged, and findings shall be tracked through verified closure.
Logging and incident reporting
Security logs shall be protected against unauthorised access and alteration. Applicable CERT-In requirements shall be followed, including retention of ICT logs for a rolling period of 180 days within Indian jurisdiction. Passwords and authentication secrets shall not be recorded in logs.
Suspected security incidents shall be handled under the Contingency Management Plan. Users may report concerns through the University's Contact Us page without sending passwords or unnecessary personal information.
Policy review
This policy shall be reviewed annually and after significant incidents, system changes or changes in applicable requirements.