(ii) “traffic data” means any data identifying or purporting to identify any person, computer
system or computer network or location to or from which the communication is or may be
transmitted and includes communications origin, destination, route, time, data, size, duration or
type of underlying service and any other information.]
70. Protected system.–1[(1) The appropriate Government may, by notification in the Official
Gazette, declare any computer resource which directly or indirectly affects the facility of Critical
Information Infrastructure, to be a protected system.
Explanation.–For the purposes of this section, “Critical Information Infrastructure” means the
computer resource, the incapacitation or destruction of which, shall have debilitating impact on national
security, economy, public health or safety.]
(2) The appropriate Government may, by order in writing, authorise the persons who are authorised to
access protected systems notified under sub-section (1).
(3) Any person who secures access or attempts to secure access to a protected system in contravention
of the provisions of this section shall be punished with imprisonment of either description for a term
which may extend to ten years and shall also be liable to fine.
2
[(4) The Central Government shall prescribe the information security practices and procedures for
such protected system.]
3
[70A. National nodal agency.–(1) The Central Government may, by notification published in the
Official Gazette, designate any organisation of the Government as the national nodal agency in respect of
Critical Information Infrastructure Protection.
(2) The national nodal agency designated under sub-section (1) shall be responsible for all measures
including Research and Development relating to protection of Critical Information Infrastructure.
(3) The manner of performing functions and duties of the agency referred to in sub-section (1) shall
be such as may be prescribed.
70B. Indian Computer Emergency Response Team to serve as national agency for incident
response.–(1) The Central Government shall, by notification in the Official Gazette, appoint an agency of
the Government to be called the Indian Computer Emergency Response Team.
(2) The Central Government shall provide the agency referred to in sub-section (1) with a Director
General and such other officers and employees as may be prescribed.
(3) The salary and allowances and terms and conditions of the Director-General and other officers and
employees shall be such as may be prescribed.
(4) The Indian Computer Emergency Response Team shall serve as the national agency for
performing the following functions in the area of cyber security,–
(a) collection, analysis and dissemination of information on cyber incidents;
(b) forecast and alerts of cyber security incidents;
(c) emergency measures for handling cyber security incidents;
(d) coordination of cyber incidents response activities;
(e) issue guidelines, advisories, vulnerability notes and white papers relating to information
security practices, procedures, preventation, response and reporting of cyber incidents;
(f) such other functions relating to cyber security as may be prescribed.
(5) The manner of performing functions and duties of the agency referred to in sub-section (1) shall
be such as may be prescribed.
(6) For carrying out the provisions of sub-section (4), the agency referred to in sub-section (1) may
call for information and give direction to the service providers, intermediaries, data centres, body
corporate and any other person.
1. Subs. by Act 10 of 2009, s. 35, for sub-section (1) (w.e.f. 27-10-2009).
2. Ins. by s. 35, ibid. (w.e.f. 27-10-2009).
3. Ins. by s. 36, ibid. (w.e.f. 27-10-2009).
29