Cyber Laws & CERT-In Framework
India's statutory framework for digital governance is established under the Information Technology Act, 2000, as amended in 2008. The legislation defines criminal liability for unauthorized system access under Section 43, identity theft under Section 66C, and cyber terrorism under Section 66F, which carries potential life imprisonment. The Indian Computer Emergency Response Team (CERT-In), designated under Section 70B, functions as the national nodal agency for monitoring cyber incidents, issuing security advisories, and enforcing mandatory incident reporting within designated hourly windows for system intermediaries. Candidates preparing for general awareness and civil services papers must master these statutory penalties, critical information infrastructure protections under NCIIPC, and digital evidence handling under the Indian Evidence Act.
Key Concepts & Examination Highlights
- The Information Technology Act was enacted in 2000 and substantially amended in 2008 to address cyber terrorism and electronic fraud.
- Section 66F of the IT Act penalizes cyber terrorism with severe penalties, including imprisonment up to life.
- CERT-In was established under Section 70B of the IT Act, 2000, operating under the Ministry of Electronics and Information Technology (MeitY).
- The National Critical Information Infrastructure Protection Centre (NCIIPC) is designated under Section 70A to safeguard critical national assets.