Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Regulatory Framework on AI, Cyber Security and Cyberspace
Cyber Security Framework and Institutions in India
Updated 11 October 2026 · Fact-checked
India's cyber security framework rests on the IT Act, 2000. It lets the Government declare protected systems (s 70), designate a national nodal agency for critical information infrastructure (s 70A), and appoint CERT-In as national incident response agency (s 70B). Answer questions by naming the institution, its power, the duty on others and the penalty.
Understand Cyber Security Framework and Institutions in India
Cyber security law in India is not one rulebook. It is a set of institutions and powers created mainly by the Information Technology Act, 2000. Each does a different job: protect the most sensitive systems, respond to incidents, watch traffic, and punish attacks.
Critical Information Infrastructure (CII) is a computer resource whose incapacitation or destruction would have a debilitating impact on national security, economy, public health or safety. Think of a power grid control system or a core banking network. Under section 70, the appropriate Government may, by notification in the Official Gazette, declare any computer resource that directly or indirectly affects the facility of CII to be a protected system. Only persons authorised by written order may access it. Unauthorised access or attempt is punishable with imprisonment up to ten years and fine. The Central Government prescribes information security practices and procedures for such systems.
Section 70A deals with protection of CII as a whole. The Central Government may, by notification, designate a Government organisation as the national nodal agency for CII protection. That agency is responsible for all measures, including research and development, relating to CII protection. The manner of performing its functions is prescribed. In practice, this agency is known as NCIIPC. The section itself does not name it, so say 'designated agency' first and add the name as practice.
Section 70B creates the Indian Computer Emergency Response Team (CERT-In). The Central Government appoints it by notification and gives it a Director General and staff. It is the national agency for cyber security functions: collecting, analysing and spreading information on cyber incidents; forecasts and alerts; emergency measures; coordinating response; and issuing guidelines, advisories, vulnerability notes and white papers. It can call for information and give directions to service providers, intermediaries, data centres, body corporates and any other person.
These bodies work with other powers: section 69B (monitoring traffic data for cyber security), section 69 (interception, monitoring, decryption), section 69A (blocking), and section 66F (cyber terrorism, which covers attacks that adversely affect CII specified under section 70). Together they form prevention, detection, response and punishment.
Key rules to remember
- Protected system (s 70)
- Gazette notification by appropriate Government + computer resource that directly or indirectly affects CII = protected system
- Access only by persons authorised by written order. Unauthorised access or attempt: imprisonment up to 10 years and fine.
- CII definition (s 70 Explanation)
- CII = computer resource whose incapacitation or destruction has a debilitating impact on national security, economy, public health or safety
- Quote the four heads: national security, economy, public health, safety.
- National nodal agency (s 70A)
- Central Government notification designates a Government organisation for CII protection, including R&D
- Section is silent on the name. NCIIPC is the practice name.
- CERT-In functions (s 70B(4))
- Collect/analyse/disseminate incident information; forecast and alerts; emergency measures; coordinate response; issue guidelines and advisories; other prescribed functions
- Six functions: (a) to (f).
- CERT-In directions and penalty (s 70B(6), (7))
- Failure to provide information or comply with direction: imprisonment up to 1 year, or fine up to ₹1 crore, or both
- Fine limit raised from one lakh to one crore from 30-11-2023.
- Cognizance (s 70B(8))
- Court takes cognizance only on complaint by an officer authorised by CERT-In
- Frequently missed in case answers.
How to solve Cyber Security Framework and Institutions in India questions
Use this method for any case or theory question on cyber security institutions.
- 1Identify the institution or power in the facts: protected system, CII agency, CERT-In, or a related power (69, 69A, 69B, 66F).
- 2State the section and quote its trigger in plain words, for example 'Gazette notification declaring a system that affects CII'.
- 3Check each fact against the condition: who acted (appropriate or Central Government), how (notification or written order), and on whom.
- 4Identify the duty or breach: unauthorised access, failure to give information, or failure to follow a CERT-In direction.
- 5State the consequence: punishment with exact term and fine, plus any procedural bar such as the complaint requirement in s 70B(8).
- 6Conclude clearly: liable or not liable, and which authority acts.
- 7Add a practical compliance point: for a company, maintain an incident reporting process, a contact for CERT-In, and access controls on critical systems.
Quickest way: Institution-Power-Duty-Penalty grid
When to use it: Use when the question asks you to explain or compare institutions, or when time is short.
- Write the four labels: Institution, Power, Duty on others, Penalty.
- Fill s 70 (protected system), s 70A (nodal agency) and s 70B (CERT-In) one row each.
- Add one line linking to s 66F for attacks on CII.
- Finish with the facts-based conclusion in two lines.
Common mistakes in Cyber Security Framework and Institutions in India
Saying section 70A names NCIIPC.
Students mix practice with statute.
Fix: Write that the Central Government designates a Government organisation as national nodal agency; mention NCIIPC as the agency in practice.
Giving the wrong penalty for unauthorised access to a protected system.
Confusion with other offences.
Fix: Remember s 70(3): imprisonment up to ten years and fine, including attempts.
Quoting the old CERT-In fine of one lakh.
Old notes are still in circulation.
Fix: Under s 70B(7) as amended, fine may extend to ₹1 crore, imprisonment up to one year, or both.
Ignoring who can file the complaint for s 70B offences.
Students focus on the penalty only.
Fix: Add that cognizance needs a complaint by an officer authorised by CERT-In.
Treating every important system as a protected system.
Students skip the notification requirement.
Fix: A system is protected only if declared by Gazette notification and it affects CII.
Limiting CERT-In to incident response only.
The name suggests only emergency response.
Fix: List all functions: information collection, alerts, emergency measures, coordination, advisories and prescribed functions.
Worked examples
Example 1
Medha Power Grid Ltd runs the control system of a regional grid. The Central Government notifies it as a protected system. A contract IT vendor's employee, not authorised in writing, logs in to test it out of curiosity. Advise on liability.
Show the solution
- Section 70(1): the appropriate Government may notify a computer resource that directly or indirectly affects CII as a protected system. A grid control system fits the definition of CII, as its destruction would badly affect economy, public health and safety.
- The notification has been issued, so the system is a protected system.
- Section 70(2): access is limited to persons authorised by written order. The employee has no such order.
- Section 70(3): securing access or attempting to do so in contravention of the section is an offence. Curiosity is no defence under the text.
- Punishment: imprisonment of either description up to ten years and also fine.
Answer: The employee is liable under section 70(3) for unauthorised access to a protected system: imprisonment up to ten years and fine. Practically, the company should review access authorisations and vendor controls.
Example 2
A data centre operator receives a direction from CERT-In to supply logs about a ransomware incident and ignores it. Discuss consequences and procedure.
Show the solution
- Section 70B(4) makes CERT-In the national agency for collecting information on cyber incidents and coordinating response.
- Section 70B(6): for these functions, CERT-In may call for information and give directions to service providers, intermediaries, data centres, body corporate and any other person. A data centre is expressly covered.
- Section 70B(7): failure to provide information or comply is punishable with imprisonment up to one year, or fine up to ₹1 crore, or both.
- Section 70B(8): a court takes cognizance only on a complaint by an officer authorised by CERT-In.
Answer: The operator commits an offence under section 70B(7), punishable with imprisonment up to one year or fine up to ₹1 crore or both. Prosecution needs a complaint by a CERT-In authorised officer. The operator should comply at once and record the response.
Exam tips
- Answer in provision, analysis, conclusion order. Name the section, apply facts, then conclude.
- Memorise the four numbers: 10 years (s 70), 1 year and ₹1 crore (s 70B), and 7 years for s 69 and 69A offences.
- Spot the word 'notified' in facts. It decides whether a system is protected.
- Quote the CII definition with all four heads when a question asks for its meaning.
- Add a short compliance point for a company: incident reporting process, access control and a CERT-In contact.
Practice questions from Regulatory Framework on AI, Cyber Security and Cyberspace
- Under the Information Technology Act, 2000, a Central Government-authorised agency asks an intermediary to give technical assistance and onl…
- Under the Information Technology Act, 2000, which body is designated to serve as the national agency for incident response in the area of cy…
- Under Section 69B of the Information Technology Act, 2000, who may authorise an agency of the Government to monitor and collect traffic data…
- A person abroad, of foreign nationality, launches malware from a server outside India that disrupts a computer network located in India. Whi…
- Rohan, an employee of a Mumbai firm, is convicted under the IT Act, 2000 for an offence and also faces prosecution under another law for the…
Cyber Security Framework and Institutions in India in other exams
The same ground in other exams, if you are preparing for more than one or want another angle on it.
Cyber Security Framework and Institutions in India: frequently asked questions
What is critical information infrastructure under the IT Act?
It is a computer resource whose incapacitation or destruction would have a debilitating impact on national security, economy, public health or safety. The definition is in the Explanation to section 70.
What is a protected system?
It is a computer resource that directly or indirectly affects CII and has been declared protected by Gazette notification. Only persons authorised by written order may access it.
What does CERT-In do under the IT Act?
It is the national agency for cyber security functions such as collecting information on incidents, issuing alerts, handling emergencies, coordinating response and issuing advisories. It can direct intermediaries, data centres and body corporates under section 70B.
What is the penalty for not complying with a CERT-In direction?
Imprisonment up to one year, or fine up to ₹1 crore, or both, under section 70B(7). A court takes cognizance only on a complaint by an authorised CERT-In officer.