Protected Systems and Critical Information Infrastructure
Chapter Seventy-Eight
Syllabus topic 3.3, "Cyber Security"
Pages 482 to 489 of 948
In one line
The Government may declare any computer resource affecting critical information infrastructure to be a protected system, unauthorised access to which carries ten years; and a separate agency under an intelligence organisation exists to protect that infrastructure nationally.
Section 70 before and after 2008
As enacted in 2000, section 70(1) let the appropriate Government declare any computer, computer system or computer network a protected system, by notification. There was no criterion at all. A State could notify anything.
The Amendment Act of 2008 replaced sub-section (1) and added the definition. It now reads:
(1) The appropriate Government may, by notification in the Official Gazette, declare any computer resource which directly or indirectly affects the facility of Critical Information Infrastructure, to be a protected system.
Explanation. For the purposes of this section, "Critical Information Infrastructure" means the computer resource, the incapacitation or destruction of which, shall have debilitating impact on national security, economy, public health or safety.
Three changes worth naming. The subject became a computer resource, a wider term than the original three. The power acquired a criterion: the resource must directly or indirectly affect the facility of critical information infrastructure. And critical information infrastructure got a statutory definition, in an Explanation rather than in section 2, which is why it is easy to miss.
Read the definition carefully. It has an effects test with a threshold: incapacitation or destruction must have a debilitating impact on one of four things, national security, economy, public health, or safety. Not any impact. Debilitating.
And note "directly or indirectly". A payroll server that would not itself debilitate anything, but whose compromise gives an attacker a route into a grid control system, is within the power.
The rest of section 70
Sub-section (2): the appropriate Government may by order in writing authorise the persons who may access a protected system. So a protected system has a closed list of authorised persons, and the list is an executive order.
Sub-section (3), the offence:
Any person who secures access or attempts to secure access to a protected system in contravention of the provisions of this section shall be punished with imprisonment of either description for a term which may extend to ten years and shall also be liable to fine.
Four points on the offence. It punishes securing access and attempting to secure access equally, so the inchoate form carries the full sentence and section 84C's halving does not apply. It requires no damage, no dishonesty and no intention beyond the access itself; the mental element is doing the act without authorisation. Ten years makes it the heaviest sentence in the Act other than cyber terrorism under section 66F, which carries life. And the fine is mandatory, "shall also be liable to fine", with no ceiling stated.
The rest of this chapter
Module one is free. The rest of this chapter comes with the LL.M. Intellectual Property and Information Technology Semester 3 notes.
You are reading a chapter from a later module. Everything in module one of every subject stays free, and so does every question paper and the syllabus.
Notes + Solved papers: ₹798 Already bought it? Sign in
Or notes only: ₹499
Or solved papers only: ₹499
Free either way: question papers, the syllabus, and module one of every subject.
The rest of this subject
These notes are cut from the University's printed syllabus. Open the syllabus itself, or the past papers, for the same subject.