munotes®

Protected Systems, the Nodal Agency and CERT-In

Chapter One Hundred Nineteen

Syllabus topic 4, "Cyber crimes under the Information Technology Act"

Pages 566 to 570 of 802

In one line

The Government may declare a computer resource affecting critical information infrastructure a protected system and authorise who may use it, unauthorised access or an attempt at it is ten years, a national nodal agency protects such infrastructure, and the Indian Computer Emergency Response Team is the national incident response agency with power to demand information.

In the wording a student can write in an exam: by section 70(3) of the Information Technology Act, 2000 any person who secures access or attempts to secure access to a protected system in contravention of the provisions of that section shall be punished with imprisonment of either description for a term which may extend to ten years and shall also be liable to fine.

Section 70, the protected system

Sub-section (1), the declaration. The appropriate Government may, by notification in the Official Gazette, declare any computer resource which directly or indirectly affects the facility of Critical Information Infrastructure to be a protected system.

The Explanation defines Critical Information Infrastructure as the computer resource the incapacitation or destruction of which shall have debilitating impact on national security, economy, public health or safety.

Sub-section (2), who may use it. The appropriate Government may, by order in writing, authorise the persons who are authorised to access protected systems so notified.

Sub-section (3), the offence. Any person who secures access or attempts to secure access to a protected system in contravention of the section shall be punished with imprisonment of either description which may extend to ten years and shall also be liable to fine.

Sub-section (4). The Central Government shall prescribe the information security practices and procedures for such protected systems.

Sub-section (1) and sub-section (4) were rewritten in 2009. Before that, sub-section (1) allowed the declaration of any computer resource without reference to critical information infrastructure. Act 10 of 2009 tied the declaration to that concept and added sub-section (4), both with effect from 27 October 2009.

Two features of section 70 to notice

The declaration is by the appropriate Government and the authorisation is by order. So a system is protected by a public notification, and the list of people who may touch it is a separate written order. Both are ingredients: the offence is access in contravention of the provisions of this section.

An attempt carries the same ten years as the act. That is unusual in this Act and it reflects the subject matter: an attempt on a power grid or a defence network is treated as gravely as success.

And note the link to section 66F. Adversely affecting the critical information infrastructure specified under section 70 is one of the consequences that turns an attack into cyber terrorism, punishable with imprisonment for life.

munotes.in566

The rest of this chapter

Module one is free. The rest of this chapter comes with the LL.M. Criminal Law and Criminal Administration Semester 1 notes.

You are reading a chapter from a later module. Everything in module one of every subject stays free, and so does every question paper and the syllabus.

Notes + Solved papers: ₹798 Already bought it? Sign in

Or notes only: ₹499
Or solved papers only: ₹499

Free either way: question papers, the syllabus, and module one of every subject.

The rest of this subject

These notes are cut from the University's printed syllabus. Open the syllabus itself, or the past papers, for the same subject.

Report or request
Done!