All NotesCivil LawInformation Technology Act, 2000

Information Technology Act, 2000

Sections 70 and 70A IT Act: Protected Systems, CII and NCIIPC

Some computers can fail without consequence; others carry the grid, the banks, the trains and a billion identities. Sections 70 and 70A build a separate regime for the second kind: the concept of critical information infrastructure, the legal status of a protected system with a ten year offence guarding it, prescribed security discipline, and a national nodal agency, NCIIPC, to protect the critical sectors. This note covers the definitions, the notification mechanism and offence, the 2018 Rules, NCIIPC and its functions, the sectors, the CIDR as the leading example, and the comparisons and attack scenarios exams draw on.

1. Ordinary Roads and the Airport Road

Every road is protected by the ordinary traffic law, but the road to the airport, the power station and the cantonment gets more: a notified restricted status, a checkpost that lets only authorised vehicles through, and a special guard force. The Act works the same way. Sections 43 and 66 police every computer; Section 70 notifies the roads that matter as protected systems with a ten year offence at the checkpost; and Section 70A raises the guard force, NCIIPC, for the whole critical estate.

2. Section 70: Protected Systems

Section 70, Information Technology Act, 2000 (as substituted in 2008)

(1) The appropriate Government may, by notification in the Official Gazette, declare any computer resource which directly or indirectly affects the facility of Critical Information Infrastructure, to be a protected system. Explanation. For the purposes of this section, 'Critical Information Infrastructure' means the computer resource, the incapacitation or destruction of which, shall have debilitating impact on national security, economy, public health or safety.

(2) The appropriate Government may, by order in writing, authorise the persons who are authorised to access protected systems notified under sub-section (1).

(3) Any person who secures access or attempts to secure access to a protected system in contravention of the provisions of this section shall be punished with imprisonment of either description for a term which may extend to ten years and shall also be liable to fine.

(4) The Central Government shall prescribe the information security practices and procedures for such protected system.

From CII to the protected system offence

Figure 1: From CII to the protected system offence

  • Protected system: meaning. Not a description but a status: a computer resource becomes a protected system only when the appropriate Government notifies it in the Gazette. The 2008 substitution tied the power to CII, so only resources that directly or indirectly affect the facility of critical information infrastructure can be notified.
  • Critical computer resources. The Explanation supplies the test: a resource whose incapacitation or destruction would have a debilitating impact on national security, economy, public health or safety. The four heads make the concept wider than defence alone; a payments backbone or a hospital network qualifies.
  • Protected system notification. Made by the appropriate Government, Centre or State, and the practice is to notify the specific facilities and their dependencies. Notified examples include UIDAI's CIDR and its associated facilities and the national and regional load despatch centres that run the grid.
  • Unauthorised access to a protected system. Section 70(3) punishes securing access, and the mere attempt, in contravention, with up to ten years and fine: the harshest access offence in the Act, cognizable and non-bailable, and it needs no damage, dishonesty or loss; crossing the checkpost is the crime.
  • Authorised access. Section 70(2) makes authorisation a written, personal matter: employees and vendors access under written orders, and access beyond one's authorisation falls back into s.70(3)

Information security practices for protected systems

The 2018 Rules in outline

Figure 2: The 2018 Rules in outline

  • The 2018 Rules. The Information Technology (Information Security Practices and Procedures for Protected System) Rules, 2018 prescribe the discipline under s.70(4): every organisation with a protected system constitutes an Information Security Steering Committee chaired at the top level, appoints a Chief Information Security Officer, documents its information security policy, isolates and controls access to the protected system, runs vulnerability assessment, penetration testing and periodic audits, and maintains coordination with NCIIPC.

3. Section 70A: Critical Information Infrastructure and NCIIPC

Section 70A, Information Technology Act, 2000 (inserted in 2008)

(1) The Central Government may, by notification published in the Official Gazette, designate any organisation of the Government as the national nodal agency in respect of Critical Information Infrastructure Protection.

(2) The national nodal agency designated under sub-section (1) shall be responsible for all measures including Research and Development relating to protection of Critical Information Infrastructure.

(3) The manner of performing functions and duties of the agency referred to in sub-section (1) shall be such as may be prescribed.

  • NCIIPC. By notification of 16 January 2014, the Central Government designated the National Critical Information Infrastructure Protection Centre, an organisation under the National Technical Research Organisation, as the national nodal agency. The NCIIPC Rules, 2013 prescribe its manner of functioning.
  • Critical information infrastructure: meaning. The same Explanation to s.70 supplies the definition for the whole scheme, and s.66F borrows it for cyber terrorism: an attack adversely affecting CII, with terror intent and grave consequence, can carry life imprisonment (Topic 60)

Functions of NCIIPC

Figure 3: Functions of NCIIPC

  • Functions of NCIIPC. Advising on the identification of CII and its notification as protected systems; framing national CII protection guidelines and sector SOPs; threat assessment, situational awareness and early warning; audits and compliance checks of protected systems; a 24x7 helpdesk for critical sector entities; incident response in coordination with CERT-In; and training, exercises and R&D.
  • The critical sectors. NCIIPC organises its work around the critical sectors: power and energy; banking, financial services and insurance; telecommunications; transport; government; and strategic and public enterprises.

The critical sectors and what sits inside them

Figure 4: The critical sectors and what sits inside them

  • Banking critical infrastructure. Core banking systems, RTGS and NEFT, UPI switches and depositories: incapacitation would stall the economy within hours, the reason finance sits in every CII list.
  • Power sector cyber infrastructure. Generation control systems, SCADA networks and the load despatch centres; the notified load despatch centres are the standing example of protected systems, and the 2020 Mumbai grid disturbance investigations made the sector's exposure a public question.
  • Telecom and government systems. Backbone and signalling networks carry every other sector's traffic, and government data centres and e-governance platforms hold the records the State runs on, so both are treated as critical in their own right.

4. UIDAI and the CIDR

The CIDR inside the protected system regime

Figure 5: The CIDR inside the protected system regime

  • The best known protected system. In December 2015 the Central Government notified UIDAI's Central Identities Data Repository facilities as a protected system under Section 70, placing the Aadhaar database of identity and biometric records behind the ten year offence.
  • The double wall. The Aadhaar Act, 2016 adds its own offences: unauthorised access to the CIDR carries imprisonment up to ten years under s.38 (as strengthened by the 2019 amendment), with further offences for tampering and unauthorised use of identity information, alongside the security obligations in the Act and the Aadhaar (Data Security) Regulations.
  • Why it matters in answers. The CIDR joins the two halves of the syllabus: a s.70 protected system, defended in Puttaswamy on the strength of its security design, and the standing illustration for both CII and data protection questions.

5. Protected System vs CII, and the Attack Scenarios

The concept and the status compared

Figure 6: The concept and the status compared

  • Critical infrastructure cyber attacks. The framework answers real patterns: ransomware on hospital systems (the 2022 AIIMS incident), probes of grid control centres, attacks on banking and payment rails, and espionage against government networks. Charging stacks s.70(3) for the access, ss.43 and 66 for the damage, and s.66F where terror intent and debilitating consequence concur.
  • The institutional division. NCIIPC guards the critical estate; CERT-In answers incidents across the whole economy (Topic 64); sectoral regulators, RBI, CEA, TRAI, add their own cyber security directions on top.

⚠ Exam trap

Keep the concept and the status apart: CII is defined by the debilitating impact test, while a protected system exists only by Gazette notification, and the s.70(3) offence guards notified systems alone. Remember that the offence punishes access and even attempt, without any damage requirement, at ten years, and that NCIIPC (s.70A, under NTRO, for CII) must never be written where CERT-In (s.70B, under MeitY, for incident response) belongs.

6. Quick Revision and Memory Aids

  • 'Ordinary roads, airport road'. ss.43 and 66 against s.70.
  • 'Debilitating impact: security, economy, health, safety'. The CII definition.
  • 'Notify, authorise, punish, prescribe'. The four limbs of s.70.
  • 'Ten years for the attempt itself'. s.70(3)
  • 'NCIIPC: nodal, NTRO, 2014'. The s.70A agency.
  • 'Power, banks, telecom, transport, government, strategic'. The critical sectors.
  • 'CIDR: the flagship protected system'. UIDAI under s.70.

7. Frequently Asked Questions

What is a protected system and how is it different from critical information infrastructure?

Critical information infrastructure is a defined concept: a computer resource whose incapacitation or destruction would have a debilitating impact on national security, economy, public health or safety. A protected system is a legal status: a computer resource affecting the facility of CII that the appropriate Government has notified in the Gazette under Section 70(1). Only notified systems attract the Section 70(3) offence of up to ten years for unauthorised access or attempt.

What is NCIIPC and what are its functions?

The National Critical Information Infrastructure Protection Centre, an organisation under the NTRO, designated in January 2014 as the national nodal agency under Section 70A. It is responsible for all measures, including research and development, for protecting critical information infrastructure: identifying CII, framing guidelines and sector practices, threat assessment and early warning, audits of protected systems, a 24x7 helpdesk for critical sectors, and incident response in coordination with CERT-In.

8. Related Topics

  • Topic 64: Section 70B and CERT-In. The incident response half of the framework.
  • Topic 60: Section 66F. Cyber terrorism against critical infrastructure.