CERT-In and Incident Reporting
Chapter Seventy-Six
Syllabus topic 3.3, "Cyber Security"
Pages 468 to 474 of 948
In one line
Section 70B creates one agency, gives it six functions, and gives it one hard power, namely to call for information and give directions, backed by an offence carrying a year and a crore.
The section, sub-section by sub-section
Section 70B(1): the Central Government shall appoint an agency called the Indian Computer Emergency Response Team. Not "may". The notification was made on 27 October 2009, and CERT-In had existed as an executive body since 2004; the section put it on a statutory footing.
Sub-sections (2) and (3): a Director General, other officers and employees, and their terms, all as prescribed.
Sub-section (4), the functions, all "in the area of cyber security":
(a) collection, analysis and dissemination of information on cyber incidents;
(b) forecast and alerts of cyber security incidents;
(c) emergency measures for handling cyber security incidents;
(d) coordination of cyber incidents response activities;
(e) issue guidelines, advisories, vulnerability notes and white papers relating to information security practices, procedures, prevention, response and reporting of cyber incidents;
(f) such other functions relating to cyber security as may be prescribed.
Note what is absent from the list: no power to investigate, no power to enter or search, no power to prosecute, and no power to fine. CERT-In collects, forecasts, responds, coordinates and advises.
Sub-section (5): the manner of performing functions and duties shall be as prescribed. That is the rule-making hook for the 2013 Rules.
Sub-section (6), the power that matters:
For carrying out the provisions of sub-section (4), the agency referred to in sub-section (1) may call for information and give direction to the service providers, intermediaries, data centres, body corporate and any other person.
Five classes of addressee, and the fifth swallows the other four. "Any other person" means the power reaches anybody at all, and the enumeration exists to make the reach obvious rather than to limit it.
Sub-section (7), the offence: failure to provide the information called for, or to comply with a direction under sub-section (6), is punishable with imprisonment up to one year or a fine up to one crore rupees or both. The fine was raised from one lakh to one crore by the Finance Act, 2017.
Sub-section (8), the gate: no court shall take cognizance except on a complaint made by an officer authorised by CERT-In. Nobody else can set the offence in motion, and that is the practical control on the section.
The Rules of 2013
Made under section 87(2)(zf) read with section 70B(5), notified on 16 January 2014, and formally called the Information Technology (The Indian Computer Emergency Response Team and Manner of Performing Functions and Duties) Rules, 2013. Twenty rules.
The rest of this chapter
Module one is free. The rest of this chapter comes with the LL.M. Intellectual Property and Information Technology Semester 3 notes.
You are reading a chapter from a later module. Everything in module one of every subject stays free, and so does every question paper and the syllabus.
Notes + Solved papers: ₹798 Already bought it? Sign in
Or notes only: ₹499
Or solved papers only: ₹499
Free either way: question papers, the syllabus, and module one of every subject.
The rest of this subject
These notes are cut from the University's printed syllabus. Open the syllabus itself, or the past papers, for the same subject.