Information Technology Act, 2000
National Cyber Security Policy 2013 and the National Cyber Security Strategy
A policy is not a statute, and that is the first thing to say about India's cyber security framework: the National Cyber Security Policy 2013 set a vision and objectives but created no enforceable duties, leaving the binding work to CERT-In's directions and the DPDP Act. A successor Strategy has been drafted but not formally released. Topics 63 and 64 cover the institutions; this note, as asked, covers the policy layer.
1. The 2013 Policy
Figure 1: Vision, objectives and the gap
- The vision. The National Cyber Security Policy 2013, released by the Department of Electronics and Information Technology, set the vision of building a secure and resilient cyberspace for citizens, businesses and government, framed in the wake of a period of high-profile breaches and global surveillance disclosures.
- The objectives. A 24x7 national nodal mechanism for crisis management, protection of critical information infrastructure, a cadre of five lakh skilled cyber professionals over five years, assurance frameworks and standards, incident response, and public-private partnership, a wide agenda of capability-building.
- The institutions it leaned on. The policy pointed to CERT-In as the national incident response hub and the then-nascent NCIIPC for critical infrastructure, the operational arms that carry the enforceable work (Topics 63, 64)
- The gap. Being a policy, not a law, the NCSP created no binding obligations and was criticised for weak implementation; the hard duties came later, from CERT-In's s.70B Directions, the protected-system regime and the DPDP Act (Topics 64, 87)
2. The Strategy and the Binding Law
Figure 2: Policy against enforceable law
- The National Cyber Security Strategy. A successor National Cyber Security Strategy was prepared under the National Cyber Security Coordinator in the National Security Council Secretariat, intended to update the 2013 policy for the data, cloud and 5G era; it has been drafted and awaited formal release, and should be described as such rather than as a notified instrument.
- What actually binds. The enforceable duties the policy could not impose live in binding law: CERT-In's six-hour reporting and logging Directions under s.70B, the protected-system obligations under ss.70 and 70A, and the DPDP Act's security and breach duties (Topics 63, 64, 87)
- Reading the layer. The policy and strategy set direction and ambition; the statute and rules set duties and penalties: an accurate answer keeps the aspirational layer and the binding layer apart.
⚠ Exam trap State the NCSP 2013 as a non-binding policy with a vision and objectives, not a source of enforceable duties, and name its headline targets, the 24x7 nodal mechanism, CII protection and the five-lakh workforce. Describe the Strategy as drafted under the National Cyber Security Coordinator and awaiting formal release, not as a notified instrument, with CERT-In's Directions, the protected-system regime and the DPDP Act as the law that binds. |
3. Frequently Asked Questions
What is the National Cyber Security Policy 2013?
A policy framework released in 2013 setting the vision of a secure and resilient cyberspace and objectives including a 24x7 national nodal mechanism, protection of critical information infrastructure, a skilled cyber workforce, assurance standards and public-private partnership. It is a policy rather than a law, so it created direction and ambition but no enforceable duties, relying on CERT-In and NCIIPC as its operational arms. A successor National Cyber Security Strategy has been drafted under the National Cyber Security Coordinator but awaits formal release, and the binding obligations come from CERT-In's directions, the protected-system regime and the DPDP Act.
4. Related Topics
- Topic 64: Section 70B CERT-In. The enforceable response regime.
- Topic 63: Protected systems and NCIIPC. Critical infrastructure protection.