Plans & Terms and Condition

Plans & Terms and Condition

1. Contingency Plan
1.1 Contingency Plan in the event of defacement
A.1.1 Defacement Protection Policy
  • Security Audit of the Bank’s Corporate Website is carried out for mitigating application vulnerabilities and enhanced performance of the Website.
  • The configuration and logs of the servers are monitored regularly by the team managing the Bank’s Website.
  • The access to servers are limited to system administrator for doing administration and configuration tasks.
  • All servers are in lock and net secured.
  • Team uses secured FTP using VPN to update the contents of the Website.
A.1.2 Monitoring of defacement of UCO Bank Website
  • There are two ways of monitoring the defacement of UCO Bank Website.
  1. Cyber security division of Bank is continuously monitoring the Website by using various tools at regular intervals for possible defacement or undesirable change in UCO Bank Website.
  2. Also the team managing the Bank’s Website is monitoring the website regularly. In case of any eventuality, whoever notices it first shall inform the Technical Manager and Web Information Manager on Phone as well as through email.
A.1.3 Actions to be taken after defacement

If defacement is detected, the following steps should be promptly executed

  1. Immediate Isolation
    • In order to prevent further damage and protect users from malicious content, the website is temporarily taken the affected web page or site offline.
    • Block external access if required, using firewall rules or CDN configurations.
  2. Notification and Escalation
    • On detection of any notification, the Incident Response Team and CISO team of the Bank is alerted.
    • Team managing the Website shall notify Bank on detection of any incident.
  3. Forensic Analysis
    • For Forensic Analysis the logs from web servers, WAF, and access controls shall be reviewed to identify the entry point and nature of the breach.
    • The evidences shall be preserved for further investigation and possible legal or compliance reporting.
  4. Remove Malicious Content if any
    • The backups shall be used to restore defaced content.
    • In case impact is more, the website files shall be restored to a known-good state from secure backups .
  5. Patch and Secure
    • Identify and patch the vulnerability -on regular intervals audit report shared by bank are also complied and yearly CERT Security audit is conducted.
    • Change all admin and service passwords.
    • Re-validate file and directory permissions.
  6. Communication
    • The users shall be informed, if there is any data exposure or phishing was involved.
    • The incident report shall be shared with regulatory authorities and Bank Team.
  7. Resume Operations
    • After thorough validation and testing, the website shall be restored and make live.
    • The traffic and content in the Website shall be monitored closely in the hours/days following recovery.
  8. Post-Incident Review
    • The incident, root cause, timeline of events, and corrective actions taken shall be properly documented.
    • The policies, patch schedules, and access control measures shall be monitored based on Findings
A.1.4 Time for Restoration

The restoration timeline for UCO Bank’s Corporate Website is determined by the extent of defacement and the specific services affected. Restoration efforts are prioritized based on the severity and scope of the incident, with critical services receiving immediate attention to minimize disruption and ensure continuity of operations.

 

UCO Bank follows a structured incident response and recovery protocol, which includes assessment of damage, containment of the issue, and phased restoration of affected components. This approach ensures that the website is restored efficiently and securely, in alignment with internal service level objectives and regulatory expectations.

1.2 Data Corruption

To ensure data integrity and uninterrupted service availability, regular backups of the UCO Bank website are systematically performed by the hosting team at the designated Data Centre. These backups are part of the Bank’s business continuity and disaster recovery strategy, enabling swift restoration of website functionality in the event of data corruption, system failure, or other unforeseen disruptions.

1.3 Hardware/Software Crash

Although hardware or software failures are infrequent, UCO Bank has established a robust infrastructure and contingency framework to address such events effectively. In the event of a crash affecting the server hosting the Bank’s Corporate Website, the designated Data Centre—managed by the web hosting service provider—leverages High Availability (HA) architecture to ensure minimal disruption. This includes redundant systems, failover mechanisms, and load balancing to maintain service continuity.

As part of the Bank’s Business Continuity Planning (BCP), regular backups and disaster recovery protocols are in place to facilitate rapid restoration. The recovery process is governed by defined Recovery Time Objectives (RTO), which specify the maximum acceptable downtime for restoring website functionality. These objectives are aligned with internal service level agreements and regulatory expectations to ensure timely and secure resumption of services.

1.4 Natural Disasters

In a eventuality of any disaster arising due to natural calamity, which are beyond the control of any person, the entire data center gets destroyed, service provider will start the Website from the DR site after due approval. Disasters Recovery (DR): The data at Data center gets replicated at DR site.

2. Website Monitoring Plan
2.1 Frequency of monitoring

UCO Bank Website undergoes 24x7 regular monitoring through manual methods as well as through web analyzer tools.

2.2 Monitored Parameters

The UCO Bank website is also monitored for quality issues like spelling errors and broken links. Spelling checks are done on a weekly basis and broken links are monitored daily.

  • Though reports can be obtained on virtually every aspect of the UCO Bank website, for regular analysis, the quality manger is responsible for analyzing and generating the following reports;
  • Visitor’s dashboard: This report presents an overview of the Visitors Pattern to the Portal.
  • Usage Pattern: Geographic location of visitors i.e., from which cities and countries, visitors are visiting the website
  • Hits by hour of the day: This report shows the most and the least active hour of the day for the report period. If there are several days in the report period, the value presented is the sum of all hits during that period of time for all days.
  • Referring sites: This report identifies the domain names and IP addresses that refer visitors to the portal.
  • Search Phrases: This report identifies Phrases that led the most visitors to the site and for each phrase, which search engine led visitors to the site.
  • Top Pages: List of the most popular web pages on the portal and the number of visits for each.
  • Browsers: Browsers used for accessing the Website by visitors.
  • Platforms: Operating systems mostly used by visitors to access the UCO Bank website.
2.3 Utility of Monitored Parameters

UCO Bank employs a comprehensive set of monitored parameters to enhance website performance, user experience, and strategic decision-making. These analytics serve as valuable inputs for ongoing optimization and future enhancements:

  • Visitor Behaviour & Usage Patterns: Reports on user demographics and navigation trends provide actionable insights for tailoring personalization features in upcoming website upgrades.
  • Search Phrase Analysis: Monitoring the keywords used to locate the website enables targeted search engine optimization (SEO), ensuring that high-demand content is easily discoverable.
  • Top & Entry Page Metrics:Identification of the most frequently accessed pages and entry points (excluding the homepage) allows for prioritized SEO efforts, improving visibility and engagement.
  • Browser & Platform Compatibility:Usage statistics across browsers and operating systems guide technical adjustments to ensure seamless performance across the most commonly used platforms.
  • Hourly Traffic Distribution:Analysis of peak traffic hours informs server load management strategies, ensuring optimal performance during high-demand periods.
  • Referring Site Tracking: Reports on inbound traffic sources support link exchange initiatives and strategic partnerships with high-traffic referral domains.
  • Content Accuracy Monitoring: Spelling errors are promptly corrected upon detection to maintain content quality and professionalism.
  • Broken Link ResolutionRegular scans for broken links are conducted, with immediate corrective actions taken to preserve site integrity and user trust.
3. Terms and Conditions
  • UCO Bank has rights to correct and update website content at any time.
  • The website is for general information to customers and the public.
  • Materials may be downloaded for personal, non-commercial use only.
  • No reproduction without prior written permission of UCO Bank.
  • If there is a discrepancy, printed information from UCO Bank is deemed correct.

top

bottomslider_wc

footer_common_wc