CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice
Cyber Crimes and Investigation Procedures for CS Professional
This chapter covers what counts as a cyber crime, the offences and penalties under the IT Act, 2000, security procedures (Section 16), CERT-In's role (Section 70B), and how police investigate and report under the BNSS, 2023. Solve case questions by stating the provision, applying the facts, and concluding.
What this chapter covers
This chapter joins two things: the substantive cyber law in the Information Technology Act, 2000, and the criminal procedure that puts it to work. You first learn what cyber crime means and how it is classified. Then you learn which acts are offences, who handles incidents, and how a police officer investigates and reports.
The IT Act portion is short but exact. Section 16 lets the Central Government prescribe security procedures and practices, and it must have regard to commercial circumstances, the nature of transactions and other related factors. Section 70B makes the Indian Computer Emergency Response Team (CERT-In) the national agency for incident response. Section 78 says a police officer not below the rank of Inspector investigates offences under the Act.
The procedure portion comes from the Bharatiya Nagarik Suraksha Sanhita, 2023. You read it with the IT Act, because a cyber crime case needs both. This chapter links to the rest of the paper through data protection, cyber security and compliance. A company that suffers a breach must know what it can be called upon to do and how a complaint turns into a police report.
The paper is written and case-based, so this chapter gives you scenarios in which you must name the provision, apply it to the facts and conclude. The sections are short and precise, so you can learn them fully and score by quoting them correctly. Questions on CERT-In's powers, the penalty for non-compliance with its directions, and the steps from investigation to police report are natural fits. Getting these right also builds confidence for the compliance and drafting parts of the paper.
Cyber Crimes and Investigation Procedures: topics in the order to study them
- 1Cyber Crimes: Meaning, Types and ClassificationStart here to get the vocabulary and the categories that every later topic builds on.
- 2Offences and Penalties under the IT Act, 2000Once you know the types, map them to the offences and punishments in the Act.
- 3Security Procedures and Practices (Section 16)A short provision on how the Central Government prescribes security practices, so you can finish it quickly.
- 4CERT-In: National Agency for Incident Response (Section 70B)It covers the agency, its functions, its powers to call for information and the penalty, which you need before looking at investigation.
- 5Investigation Procedure for Cyber CrimesWith the offences and agencies clear, you can follow how police investigate, including Section 78 of the IT Act and the BNSS steps.
- 6Report of Investigation by Subordinate Police Officer (Section 188 BNSS)Study it last as the closing step of the process: the subordinate officer reports to the officer in charge.
How to prepare Cyber Crimes and Investigation Procedures
Treat this chapter as a mix of definitions, short sections and a process. Learn the text precisely, then practise applying it to facts.
- Read each section in plain words and write a one-line summary of what it says and who it binds.
- Build a table by hand of cyber crime types with a one-line example for each, so you can classify a fact pattern fast.
- Learn Section 70B in parts: the appointment, the functions in sub-section (4), the power to call for information and give directions in (6), the penalty in (7) and the complaint requirement in (8).
- Draw the investigation flow: information, investigation by an officer of the right rank, report by a subordinate to the officer in charge, then the police report to the Magistrate.
- Write answers in three parts: the provision, the analysis of the facts, and the conclusion.
- Revise once a week with the quick points below and rewrite the exact conditions from memory.
Common mistakes in Cyber Crimes and Investigation Procedures
Quoting the old penalty of one lakh rupees for non-compliance with CERT-In directions.
Fix: Write that the fine may extend to one crore rupees, as amended by Act 18 of 2023 with effect from 30 November 2023.
Saying that any police officer can investigate an offence under the IT Act.
Fix: State that Section 78 requires an officer not below the rank of Inspector.
Treating Section 16 as a list of security rules in the Act.
Fix: Say that it empowers the Central Government to prescribe security procedures and practices, having regard to commercial circumstances and the nature of transactions.
Confusing Section 188 BNSS with Section 193 BNSS.
Fix: Remember that Section 188 is the subordinate officer's report to the officer in charge, and Section 193 is the report to the Magistrate after the investigation is complete.
Skipping the facts and writing only the law.
Fix: Always use the three-part format: provision, analysis of the facts, conclusion, and name the people and the steps in the scenario.
Ignoring who can start a prosecution under Section 70B.
Fix: Note that a court takes cognizance only on a complaint made by an officer authorised by CERT-In.
Last-day revision: Cyber Crimes and Investigation Procedures
- Section 16 of the IT Act: the Central Government may prescribe security procedures and practices for sections 14 and 15.
- In prescribing them, it must have regard to commercial circumstances, the nature of transactions and other related factors.
- Section 70B: CERT-In is appointed by the Central Government by notification in the Official Gazette.
- CERT-In is the national agency for incident response in cyber security.
- Its functions include collecting, analysing and disseminating information on cyber incidents, forecasts and alerts, emergency measures and coordination.
- It can issue guidelines, advisories, vulnerability notes and white papers.
- It may call for information and give directions to service providers, intermediaries, data centres, body corporate and any other person.
- Failing to comply is punishable with imprisonment up to one year, or fine up to one crore rupees, or both.
- No court takes cognizance of a Section 70B offence except on a complaint by an officer authorised by CERT-In.
- Section 78 of the IT Act: an officer not below the rank of Inspector investigates offences under the Act.
- Section 188 BNSS: a subordinate officer who investigates reports the result to the officer in charge of the police station.
- Section 193 BNSS: the investigation is completed without unnecessary delay, and the report goes to the Magistrate, which includes the sequence of custody of any electronic device.
Cyber Crimes and Investigation Procedures practice questions
- Nirmal Textiles Ltd. receives a written direction from CERT-In to supply system logs relating to a ransomware attack and ignores it. Which s…
- A data centre operator in Pune ignores a written direction from CERT-In, issued under Section 70B(6), to furnish logs relating to a cyber in…
- Which description best captures the meaning of a 'cyber crime' as generally taught in cyber law?
- CERT-In issues a direction to a body corporate under Section 70B(6) and the body fails to comply. Who may make a complaint so that a court c…
- Classifying cyber crimes by the target of the offence, which of the following is correctly matched with its category?
- Under Section 70B of the Information Technology Act, 2000, how does the Central Government establish the Indian Computer Emergency Response …
- Under Section 16 of the Information Technology Act, 2000, the Central Government may prescribe security procedures and practices for the pur…
- A bank was ordered to pay compensation to a customer under the IT Act, 2000 for a data breach. Can the same conduct also be punished under a…
Cyber Crimes and Investigation Procedures in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Cyber Crimes and Investigation Procedures: frequently asked questions
What is the role of CERT-In under the IT Act?
Under Section 70B, CERT-In is the national agency for incident response in cyber security. It collects and analyses information on incidents, issues alerts and advisories, handles emergencies and coordinates the response. It can also call for information and give directions to service providers, intermediaries, data centres and body corporate.
What is the penalty for not following CERT-In directions?
A person who fails to provide the information called for or to comply with a direction is punishable with imprisonment up to one year, or a fine up to one crore rupees, or both. A court takes cognizance only on a complaint by an officer authorised by CERT-In.
Who can investigate an offence under the IT Act?
Section 78 says a police officer not below the rank of Inspector shall investigate any offence under the Act. This applies notwithstanding the Code of Criminal Procedure, 1973.
What does Section 188 of the BNSS say?
When a subordinate police officer has made an investigation under the relevant Chapter, he must report the result to the officer in charge of the police station. It is a short section, so quote it precisely.
How should I answer a case question on a cyber incident?
Identify the offence or authority involved and state the provision. Apply it to the facts given, such as who failed to comply or who investigated. Then give a clear conclusion on liability or procedure.