Master10
Cybersecurity & Digital Safety Module

Cyber Laws & CERT-In Framework

India's statutory framework for digital governance is established under the Information Technology Act, 2000, as amended in 2008. The legislation defines criminal liability for unauthorized system access under Section 43, identity theft under Section 66C, and cyber terrorism under Section 66F, which carries potential life imprisonment. The Indian Computer Emergency Response Team (CERT-In), designated under Section 70B, functions as the national nodal agency for monitoring cyber incidents, issuing security advisories, and enforcing mandatory incident reporting within designated hourly windows for system intermediaries. Candidates preparing for general awareness and civil services papers must master these statutory penalties, critical information infrastructure protections under NCIIPC, and digital evidence handling under the Indian Evidence Act.

Key Concepts & Examination Highlights

  • The Information Technology Act was enacted in 2000 and substantially amended in 2008 to address cyber terrorism and electronic fraud.
  • Section 66F of the IT Act penalizes cyber terrorism with severe penalties, including imprisonment up to life.
  • CERT-In was established under Section 70B of the IT Act, 2000, operating under the Ministry of Electronics and Information Technology (MeitY).
  • The National Critical Information Infrastructure Protection Centre (NCIIPC) is designated under Section 70A to safeguard critical national assets.
  • Section 66C of the IT Act prescribes punishment of up to three years imprisonment and a fine for identity theft, including fraudulent use of another person's digital signature or password.
  • Section 66F of the IT Act provides stringent punishment, extending up to life imprisonment, for acts of cyber terrorism that threaten the unity, integrity, security, or sovereignty of India.
  • The Digital Personal Data Protection Act (DPDPA), 2023, establishes a comprehensive data governance framework in India, regulating the processing of digital personal data and establishing the Data Protection Board of India.
  • Under CERT-In cybersecurity directions issued in April 2022, all service providers, intermediaries, and corporate entities are mandated to report designated cybersecurity incidents to CERT-In within six hours of detection.
  • Virtual Private Network (VPN) service providers and cloud service providers operating in India are required under CERT-In guidelines to maintain verified customer registration records for a minimum duration of five years.
  • The National Cyber Security Coordinator (NCSC) under the National Security Council Secretariat coordinates cybersecurity policy and strategic initiatives across all Indian civil and military agencies.
  • The Indian Cyber Crime Coordination Centre (I4C), established under the Ministry of Home Affairs, operates the National Cyber Crime Reporting Portal (cybercrime.gov.in) and the 1930 emergency helpline.
  • The Information Technology (IT) Act, 2000 was enacted based on the United Nations Model Law on Electronic Commerce (UNCITRAL Model Law) adopted in 1996.
  • Section 43 of the IT Act imposes civil liability and compensation penalties for unauthorized damage, copying, extraction of data, or disruption of computer systems.
  • Section 65 of the IT Act penalizes intentional tampering with computer source code documents with imprisonment up to three years or a fine up to ₹2 lakh.
  • Section 66 of the IT Act criminalizes hacking and fraudulent computer-related offenses, prescribing imprisonment up to three years or a fine up to ₹5 lakh.
  • Section 66A of the IT Act, which penalized sending offensive messages through communication services, was struck down as unconstitutional by the Supreme Court of India in the landmark Shreya Singhal v. Union of India judgment (2015).
  • Section 66E of the IT Act prescribes punishment for violating privacy by intentionally capturing, publishing, or transmitting images of private body areas without consent.
  • Section 69 of the IT Act empowers the central and state governments to issue directions for the interception, monitoring, or decryption of any information generated through any computer resource for national security.
  • Section 69A of the IT Act empowers the central government to block public access to any information online in the interest of the sovereignty, integrity, and defense of India.
  • Section 79 of the IT Act provides an 'intermediary safe harbour' protection, exempting online intermediaries (such as social media platforms) from liability for third-party user content if they observe prescribed due diligence.
  • The Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 mandate significant social media intermediaries to appoint a Chief Compliance Officer, Nodal Contact Person, and Resident Grievance Officer in India.
  • Cyber Swachhta Kendra (Botnet Cleaning and Malware Analysis Centre), operated by CERT-In, provides free malware analysis tools and botnet removal solutions to citizens and organizations.
  • The Indian Computer Emergency Response Team (CERT-In) serves as the national nodal agency for responding to computer security incidents, issuing security advisories, vulnerability alerts, and incident response guidelines.
  • National Cyber Coordination Centre (NCCC) is an operational cybersecurity and surveillance agency in India designed to screen communication metadata and provide real-time situational awareness.
  • The Data Protection Board of India, established under the DPDPA 2023, is empowered to inquire into personal data breaches, adjudicate non-compliance, and impose monetary penalties up to ₹250 crore per violation.
  • The Information Technology Act, 2000 was enacted on June 9, 2000, and came into force on October 17, 2000, providing legal recognition to electronic records and digital signatures.
  • The IT (Amendment) Act, 2008 introduced comprehensive amendments addressing child pornography, identity theft, cyber stalking, cyber terrorism, and data protection.
  • Section 43A of the IT Act mandates that body corporates possessing sensitive personal data implement reasonable security practices, failure of which incurs compensation liability to affected persons.
  • Section 66B of the IT Act penalizes dishonestly receiving or retaining stolen computer resources or communication devices with imprisonment up to three years or a fine up to ₹1 lakh.
  • Section 66D of the IT Act punishes cheating by personation using computer resources with imprisonment up to three years and a fine up to ₹1 lakh.
  • Section 67 of the IT Act penalizes publishing or transmitting obscene material in electronic form with imprisonment up to three years (first conviction) or five years (subsequent).
  • Section 67A of the IT Act prescribes severe punishment of up to five years imprisonment and ₹10 lakh fine for publishing or transmitting sexually explicit material in electronic form.
  • Section 67B of the IT Act prescribes stringent punishment, extending up to five years imprisonment for first conviction and seven years for subsequent convictions, for child sexual abuse material (CSAM) online.
  • Section 70 of the IT Act empowers the appropriate Government to declare any computer system or network affecting national security, economy, or public health as a 'Protected System'.
  • Unauthorized access or attempt to access a designated Protected System under Section 70 of the IT Act is punishable with imprisonment for a term which may extend to ten years.
  • The National Critical Information Infrastructure Protection Centre (NCIIPC), created under Section 70A, operates under the NTRO to secure critical sectors: Power, Banking, Telecom, Transport, and Governance.
  • Section 72 of the IT Act imposes penalties for breach of confidentiality and privacy by any person having secured access to electronic records under the Act.
  • Section 72A of the IT Act punishes disclosure of information in breach of lawful contract with imprisonment up to three years or a fine up to ₹5 lakh.
  • The Cyber Appellate Tribunal (CyAT), established under the IT Act, was merged with the Telecom Disputes Settlement and Appellate Tribunal (TDSAT) under the Finance Act 2017.
  • Adjudicating Officers appointed under Section 46 of the IT Act (typically IT Secretaries of States) hold quasi-judicial powers to adjudicate claims for compensation up to ₹5 crore.
  • The Information Technology (Procedure and Safeguards for Interception, Monitoring and Decryption of Information) Rules, 2009 prescribe legal safeguards and mandatory approvals from the Union Home Secretary.
  • The Information Technology (Procedure and Safeguards for Blocking for Access of Information by Public) Rules, 2009 establish the statutory procedure for blocking orders under Section 69A.
  • The CERT-In Directions 2022 mandate data centers, VPS providers, and cloud service providers to register and maintain subscriber information, IP assignment logs, and email records for five years.
  • The CERT-In Directions 2022 require all organizations in India to synchronize their system clocks to the Network Time Protocol (NTP) servers of the National Physical Laboratory (NPL) or NIC.
  • The Digital Personal Data Protection Act (DPDPA), 2023 applies to the processing of digital personal data within India and processing outside India if offering goods or services to data principals in India.
  • The DPDPA 2023 defines the 'Data Principal' as the individual to whom personal data relates and the 'Data Fiduciary' as the entity that determines the purpose and means of data processing.
  • Significant Data Fiduciaries (SDFs) designated under the DPDPA 2023 must appoint a Data Protection Officer (DPO) based in India, engage independent data auditors, and conduct periodic Data Protection Impact Assessments (DPIAs).
  • The Budapest Convention on Cybercrime (2001), developed by the Council of Europe, is the first international treaty addressing Internet and computer crime by harmonizing national laws.
  • The United Nations Ad Hoc Committee on Cybercrime concluded negotiations on the UN Cybercrime Convention in August 2024 to strengthen international cooperation on combating cyber offenses.
  • The Ministry of Electronics and Information Technology (MeitY) is the nodal executive ministry responsible for formulating IT policy, digital governance frameworks, and cybersecurity regulations in India.
Curriculum & Reference Sources: Information Technology Act 2000 (Ministry of Law & Justice), CERT-In Cyber Security Directions, MeitY Annual Reports

Sample Solved Questions & Concept Explanations

8 Verified Concept Questions
Q1.HARD

Which statutory body established under Section 70B of the Information Technology Act, 2000 serves as the national nodal agency for responding to cybersecurity incidents in India?

Q2.EASY

In which year was India's primary legislation governing electronic commerce, cybercrimes, and digital signatures—the Information Technology Act—enacted?

Q3.EASY

What is the dedicated national cyber helpline telephone number established by the Ministry of Home Affairs (MHA) for citizens to report financial cyber fraud immediately?

Q4.EASY

Which section of the Information Technology Act, 2000 prescribes criminal punishment for cheating by personation using any computer resource?

Q5.EASY

What is the official name of the Botnet Cleaning and Malware Analysis Centre established under CERT-In to clean infected user devices across India?

Q6.EASY

Under Section 66E of the IT Act, 2000, capturing, publishing, or transmitting images of private body areas of any person without their consent is punishable as a violation of what?

Q7.EASY

What is the central government portal for citizens to lodge complaints regarding all forms of cyber crimes, especially crimes against women and children?

Q8.MEDIUM

In which landmark 2015 judgment did the Supreme Court of India strike down Section 66A of the IT Act, 2000 as unconstitutional for violating Freedom of Speech (Article 19(1)(a))?