বাংলা E-Paper 📍 Dhaka 📅 Wednesday | 2 September 2026, 18 Bhadro 1433 PID registration number 06
HEADLINE
Advertisement

Ctg port declared Critical Information Infrastructure

Published : Tuesday, 1 September, 2026 at 9:41 PM
Observer Online Desk
X
Advertisement

The government has declared the Chittagong Port Authority (CPA) a 'Critical Information Infrastructure (CII)', bringing the key digital infrastructure of Chittagong Port under state cyber-security coverage.

The declaration was issued on Monday (August 31) through a gazette notification in accordance with Section 15 of the Cyber Protection (Amendment) Act, 2026.

The majority of Bangladesh's import-export trade is conducted through Chittagong Port. Digital systems connected to container management, ship movements, customs and revenue processing, and the supply chain are highly sensitive to national economy and security. Cyber-attacks or disruptions to this information infrastructure could directly affect trade, industrial production, and daily public life.

The CPA uses numerous digital systems to conduct its overall operations. To ensure enhanced protection for these systems and play a supporting role nationally, the CPA underwent a designated evaluation process. Upon passing the evaluation, the authority earned the CII certificate.

Receiving the certificate enables the CPA to prioritize the protection of its overall information infrastructure while giving significant weight to the data security of port-related stakeholders.

Previously, 36 organizations in Bangladesh were declared Critical Information Infrastructure (CII). Including the CPA in this list will ensure enhanced security across port systems.

This protection extends beyond basic cyber-security to cover the entire IT infrastructure, including data centers, communication systems, databases, application-level communications, and API hub communications.

Following the CII declaration, the CPA's critical information infrastructure falls under state protection, making compliance with advanced cyber-security standards mandatory for the port's priority systems.

Mandatory measures include operating an in-house Security Operations Center (SOC) and Cyber Incident Response Team (CIRT), maintaining 24/7 monitoring, conducting annual security audits of internal and external information infrastructures, sending regular reports and incident documentation, and performing risk assessments, vulnerability evaluations, and penetration testing.

Additionally, encrypted and offline backups of critical data, business continuity planning, disaster recovery setups, and regular testing of these mechanisms are required. The authority must also cooperate during inspections and audits conducted by relevant government bodies.

Violating CII security regulations or making unauthorized entry will be treated as a punishable offense under the law.

The CPA stated that necessary preventive measures have already been undertaken per guidelines from the Information and Communication Technology Division and the National Cyber Security Agency. Actions include forming a dedicated cyber-security team, preparing a comprehensive information infrastructure inventory, updating security policies, and conducting regular awareness training for officers and employees.

Commenting on the matter, CPA Chairman Rear Admiral S M Moniruzzaman said, "This decision of the government is a clear recognition of the strategic and national importance of Chittagong Port. As the primary gateway for Bangladesh's foreign trade and economic activity, ensuring safe, uninterrupted, and stable port operations is our national duty."

He added, "Alongside the port's growing digital transformation, cyber risks are also increasing. We therefore view cyber-security not merely as an IT issue, but as an integral part of operational continuity, national security, and economic stability."

Rear Admiral S M Moniruzzaman further noted, "To safeguard the critical information infrastructure and digital services of Chittagong Port, international standards will be followed, regular risk assessments conducted, and cyber threat response capabilities further strengthened. We will work in coordination with the Information and Communication Technology Division, the National Cyber Security Agency, and relevant stakeholders."

He stated, "Our goal is to build a secure, resilient, and future-ready digital port system that will play a vital role in protecting foreign trade, economic growth, and national interests."

According to the CPA, all relevant stakeholders - including port users, importers, exporters, shipping agents, and C&F agents - will benefit from receiving more secure and reliable digital services.

However, the CII designation does not mean the government assumes management of the institution's IT systems. The CPA will remain the owner and operator of its infrastructure, while operating under national-level cyber-security oversight and compliance standards.


-SA



Loading...
Loading...
Editor : Iqbal Sobhan Chowdhury
Published by the Editor on behalf of the Observer Ltd. from Globe Printers, 24/A, New Eskaton Road, Ramna, Dhaka.
Editorial, News and Commercial Offices : Aziz Bhaban (2nd floor), 93, Motijheel C/A, Dhaka-1000.

Phone: PABX- 41053001-06; Advertisement: 41053012; 01793317829, 01550707291, E-mail: [email protected], ‍[email protected] Online: email: [email protected] 41053014; 01550707297 Advertisement: 01550707296
🔝
Advertisement