Plans and Terms and Condition

1. Contingency Plan
1.1 Contingency Plan in the event of defacement
A.1.1 Defacement Protection Policy
  • Bank’s Corporate Website is security audited for application vulnerabilities and performance.
  • Any application-level modification on the UCO Bank Website implies re-audit of the website.
  • All the servers’ configuration and logs are monitored timely.
  • Only system administrator users are allowed to access the servers for doing administration and configuration tasks.
  • All servers are in lock and net secured.
  • Contents are updated through secured FTP using VPN.
A.1.2 Monitoring of defacement of UCO Bank Website
  • There are two ways of monitoring the defacement of UCO Bank Website.
  1. Cyber security division of M/s Planet e com Solutions is continuously monitoring by analyzing the log files at regular intervals for possible defacement or undesirable change.
  2. The Development team of M/s Planet e com Solutions also monitors the website regularly. In case of any eventuality, whoever notices it first shall inform the Technical Manager and Web Information Manager on phone as well as through email.
A.1.3 Actions to be taken after defacement
  1. Immediate Isolation
    • Temporarily take the affected web page or site offline to prevent further damage and protect users from malicious content.
    • Block external access if required, using firewall rules or CDN configurations.
  2. Notification and Escalation
    • Alert the incident response team and IT security personnel.
    • Notify management and stakeholders as per the incident response policy.
  3. Forensic Analysis
    • Review logs from web servers, WAF, and access controls to identify the entry point and nature of the breach.
    • Preserve evidence for investigation and possible legal or compliance reporting.
  4. Remove Malicious Content if any
    • Remove or restore defaced content using backups.
    • Revert website files to a known-good state from secure backups.
  5. Patch and Secure
    • Identify and patch the vulnerability. On regular intervals audit reports are shared by the bank and yearly CERT Security audit is conducted.
    • Change all admin and service passwords.
    • Re-validate file and directory permissions.
  6. Communication
    • Inform users (if necessary), particularly if data exposure or phishing was involved.
    • Provide an incident report to management and compliance teams.
  7. Resume Operations
    • After thorough validation and testing, restore the website to production.
    • Closely monitor traffic and content in the hours/days following recovery.
  8. Post-Incident Review
    • Document the incident, root cause, timeline of events, and corrective actions taken.
    • Update monitoring policies, patch schedules, and access control measures based on findings.
A.1.4 Time for Restoration

The time taken for restoration of the Bank’s Corporate Website depends on the degree of defacement and services affected.

1.2 Data Corruption

Regular back-ups of the website data are being taken at the Data Centre. These enable a fast recovery and uninterrupted availability of the information to the citizens in view of any data corruption.

1.3 Hardware/Software Crash

If the server crashes due to unforeseen reasons, the Data Centre has redundant infrastructure to restore the website quickly, usually within 24 hours.

1.4 Natural Disasters

In the event of a natural disaster affecting the primary data center, the service provider will start the website from the DR site after due approval. Storage-based replication takes place at the DR site.

2. Website Monitoring Plan
2.1 Frequency of monitoring

The UCO Bank Website undergoes 24x7 regular monitoring through manual methods as well as through web analyzer tools.

2.2 Monitored Parameters
  • Visitor’s dashboard
  • Usage Pattern (Geographic location of visitors)
  • Hits by hour of the day
  • Referring sites
  • Search Phrases
  • Top Pages
  • Browsers
  • Platforms
  • Weekly spelling checks and daily broken link monitoring
2.3 Utility of Monitored Parameters
  • Helps in personalization and user experience improvements.
  • Optimizes pages for search phrases used by visitors.
  • Optimizes website for most used browsers and platforms.
  • Ensures server performance during peak traffic times.
  • Facilitates link exchange with high-traffic referrers.
  • Quickly rectifies spelling errors and broken links.
3. Terms and Conditions
  • UCO Bank has rights to correct and update website content at any time.
  • The website is for general information to customers and the public.
  • Materials may be downloaded for personal, non-commercial use only.
  • No reproduction without prior written permission of UCO Bank.
  • If there is a discrepancy, printed information from UCO Bank is deemed correct.

top

bottomslider_wc