Document 5 of 5

Minimum Baseline Security Standards (MBSS)

Ensure your ISP infrastructure meets all required checklists and frameworks under the DoT's Minimum Baseline Security Standards (MBSS).

Vulnerability Assessment and Penetration Testing (VAPT) Radar Network Scan

Understanding VAPT & MBSS Compliance

The DoT mandates that ISPs must regularly test their networks for vulnerabilities to ensure they meet the strict Minimum Baseline Security Standards (MBSS). This compliance is proven through a formal, comprehensive Vulnerability Assessment and Penetration Testing (VAPT) report conducted by certified security professionals. This goes beyond a simple automated scan; it's a deep dive into your infrastructure's resilience.

Why is it Important?

VAPT is the most technically scrutinized part of the DoT Security Audit. Its importance cannot be overstated:

  • Uncovering Hidden Risks: Identifies backdoors, unpatched firmware on core routers, and misconfigured firewalls before hackers exploit them.
  • MBSS Adherence: The DoT specifically checks if you are adhering to their predefined MBSS checklist. VAPT is the proof.
  • Protecting Subscriber Data: Ensures your billing and CRM portals (where Aadhaar/PAN data is often stored) are impenetrable.
  • Avoiding Penalties: Failure to provide a clean, recent VAPT report can lead to license suspension.

How It Works

Our testing methodology is rigorous but non-disruptive to your live traffic:

  1. Scoping & Planning: We define the scope, including your public IP ranges, web portals, and internal core network components.
  2. Vulnerability Assessment: Automated tools scan for known CVEs across your infrastructure.
  3. Manual Penetration Testing: Certified ethical hackers manually attempt to exploit found vulnerabilities to prove the risk level.
  4. Remediation & Re-testing: We provide a detailed report with fixes. Once you patch the issues, we re-test and issue the final compliance certificate.

How RT Internet Services Can Help

Our certified security engineers specialize in telecom infrastructure. We don't just run an automated scan and hand you a 500-page PDF of false positives. We provide actionable, prioritized remediation steps tailored for Mikrotik, Cisco, Juniper, and Huawei environments. Most importantly, we format the final VAPT report perfectly for immediate submission on the DoT Security Audit Portal.

Pricing

Comprehensive VAPT Services

Pricing is calculated based on the number of Live Public IPs, Web Applications, and Core Routers in scope. Contact us for a scoping questionnaire to get a precise quote.

Request a Scoping Document on WhatsApp

Frequently Asked Questions (FAQs)

Will the penetration testing cause network downtime? No. We design our tests to be strictly non-disruptive. We do not perform Denial of Service (DoS) attacks on your live infrastructure unless explicitly requested in a staging environment.
What is the difference between VA and PT? Vulnerability Assessment (VA) is the process of identifying potential weaknesses (often automated). Penetration Testing (PT) is the manual attempt to safely exploit those weaknesses to see how deep an attacker could actually get. DoT requires both.