2017 · Q85
In India, it is legally mandatory for which of the following to report on cyber security incidents?
- 1.Service providers
- 2.Data centres
- 3.Body corporate.
Select the correct answer using the code given below:
- (a)1 only
- (b)1 and 2 only
- (c)3 only
- (d)1, 2 and 3
Show answer and explanationHide answer and explanation
All three are correct and the official answer (d) follows. Section 70B of the Information Technology Act, 2000 designates the Indian Computer Emergency Response Team, CERT-In, as the national nodal agency for incident response, and subsection (6) empowers it to call for information and give directions. The Information Technology (The Indian Computer Emergency Response Team and Manner of Performing Functions and Duties) Rules, 2013 make reporting mandatory, rule 12 requiring service providers, intermediaries, data centres and body corporate to report specified cyber security incidents to CERT-In within a reasonable time, and section 70B(7) attaches a penalty of imprisonment up to one year or a fine or both for failure to comply. Every category named in the question therefore appears expressly in the rule. The item is difficult because there is no elimination route: all three categories are plausible, none can be rejected on principle, and the answer depends on knowing the text of a subordinate rule that no standard preparation source reproduces. A candidate's best available reasoning is that a reporting regime designed to give a national agency visibility of the threat landscape would be defeated by exempting any major class of entity, which points towards the inclusive option. Teaching point for the subject: the reporting obligation is on the entity that suffers or observes the incident, and the categories are drawn to cover the whole chain, the network operator, the facility and the enterprise.
Difficult · Current Affairs Inspired · Science and Technology · Cybersecurity