CS Professional · Internal and Forensic Audit · Cyber Forensics
Sunrise Pharma Ltd, a company holding customers' sensitive personal data on servers it owns and operates, ignores basic access controls. A hacker exploits this and the data leak causes wrongful loss to several customers. Under Section 43A of the Information Technology Act, 2000, what is the primary consequence for the company?
The company must pay damages by way of compensation to the affected persons. Section 43A makes a body corporate liable when it is negligent in maintaining reasonable security practices for sensitive personal data and this causes wrongful loss or wrongful gain to anyone.
- AIt is liable to pay damages by way of compensation to the persons affectedCorrect
- BIt is liable only to imprisonment of its directors for life
- CIt escapes liability if the data was stored in a computer resource it controls
- DIt is liable only to a notice from the Indian Computer Emergency Response Team
Explanation
Section 43A applies where a body corporate handling sensitive personal data is negligent in implementing and maintaining reasonable security practices and thereby causes wrongful loss or gain. The remedy is damages by way of compensation to the affected person. Life imprisonment relates to cyber terrorism, not this section.
Did you get it right without looking?
One question tells you little. A timed set on Cyber Forensics shows your real accuracy, how long you take and where you lose marks.
More Cyber Forensics questions
- Kaveri Textiles has no written contract on security standards with a vendor and no law specifies any. Its auditor asks what 'reasonable secu…
- A forensic auditor at a Mumbai company records the SHA-256 hash of a disk image at acquisition and again before presenting the findings. The…
- In a fraud inquiry, an auditor must collect digital evidence from a running desktop and from the same machine's hard disk. According to the …
- During a suspected data-theft inquiry at a Pune firm, the forensic auditor must collect evidence from a seized employee laptop. Which step s…
- Narmada Data Centres Pvt Ltd receives a written direction from CERT-In to supply information needed to handle a cyber incident, and it delib…
- Ravi, an outsider with no authorisation, knowingly accesses a government database restricted for reasons of the security of the State and ob…