UPSC Margin
NotesTestsDaily CACSAT
UPSC Margin

Analytical concept notes, daily current affairs, and mock tests for serious UPSC aspirants.

Learn

  • Notes
  • Daily Current Affairs
  • Mock Tests
  • CSAT
  • Strategy Guide

Resources

  • About
  • Pricing
  • Blog
  • Contact
  • RSS Feed

Support

  • Help & FAQ
  • Privacy Policy
  • Terms of Use
  • Telegram Community

© 2026 UPSC Margin. All rights reserved.

Operated by Satyam Raj · hello@upscmargin.com

Back to Notes
Internal Security

Invalid Date
10 min read

[TOPIC CLASSIFICATION]

  • Topic type: Institutional Framework + Current Affairs
  • PYQ frequency: High
  • Exam stage: Prelims + Mains
  • Primary GS paper: GS3 (Internal Security)

[EXAMINER REASONING]

  1. Trap: Confusing CII notification under IT Act with general cybersecurity guidelines - notification is statutory, guidelines are advisory
  2. Most confused: NCIIPC vs CERT-In mandates - NCIIPC protects CII, CERT-In is national incident response
  3. Key anchor: Section 70A IT Act = CII protection mandate, Section 70B = CERT-In
  4. Current affairs hook: Digital Personal Data Protection Act 2023 overlaps with CII protection
  5. Mains hinge: Private sector CII protection - regulatory capture vs national security balance

Core Concept

Critical Information Infrastructure (CII) forms the backbone of India's digital sovereignty. The Information Technology Act, 2000, amended in 2008, provides the statutory backbone through Section 70A which defines CII as "the computer resource, the incapacitation or destruction of which shall have debilitating impact on national security, economy, public health or safety." This definition is deliberately broad, covering sectors from power grids and banking systems to transportation networks and government databases.

The National Critical Information Infrastructure Protection Centre (NCIIPC), established under Section 70A(1), serves as the nodal agency for CII protection. Unlike CERT-In which functions as the national incident response agency under Section 70B, NCIIPC has a proactive mandate - threat assessment, vulnerability assessment, and protection of designated CII. This distinction is frequently tested: NCIIPC protects designated critical infrastructure proactively, while CERT-In responds to cyber incidents nationally.

The identification and notification process under Section 70A(2) involves sectoral ministries identifying CII in their domains, followed by NCIIPC validation and formal notification by the Central Government. Once notified, CII entities are legally bound to implement protection measures, conduct audits, and report incidents. As of 2024, sectors notified include power, banking, telecom, transport, government, and strategic enterprises. The Power Grid Corporation, NPCI, major stock exchanges, and Aadhaar infrastructure are among designated CIIs.

Sectoral Computer Emergency Response Teams (CERTs) operate under CERT-In's coordination framework. Sectoral CERTs for power (CERT-Thermal, CERT-Hydro, CERT-Transmission, CERT-Distribution), finance (CERT-Fin), and defence (CERT-Def) provide sector-specific threat intelligence and incident response. The Cyber Crisis Management Plan (CCMP) mandates sectoral crisis management plans, regular mock drills, and a four-tier response structure - organisational, sectoral, national (NCIIPC/CERT-In), and national crisis management committee (NCMC) level.

Ransomware preparedness has gained urgency post-2021 attacks on AIIMS Delhi, Oil India, and SpiceJet. The 2022 Cyber Crisis Management Plan revision mandated offline backups, network segmentation, privileged access management, and ransomware-specific playbooks. Supply chain security gained prominence post-SolarWinds (2020) and Log4j (2021) incidents, leading to Software Bill of Materials (SBOM) requirements for government procurement.

Read Next

More in Internal Security

Right Wing Extremism in India: Ideology, Incidents, and State Response

Analysis of right-wing extremism in India - ideological roots, major terror incidents (Malegaon, Mecca Masjid, Samjhauta, Ajmer), investigation challenges, and the evolving legal and security response.

Border Security: Challenges and India's Approach

India shares 15,200 km of land border with seven countries - a unique geopolitical challenge with diverse threats from terrorism (Pakistan), infiltration (Bangladesh), and China's assertive posture. This note covers the Border Security Force (BSF), India-China border disputes (LAC), the India-Pakistan border (LC/IB), the India-Bangladesh border fencing, integrated border management, and the debate on 'One Border One Force'.

Coastal Security: Threats and Strengthening Measures

India has a 7,516 km coastline touching nine states and two UTs - a vast maritime frontier susceptible to terrorism, smuggling, and illegal fishing. This note covers the 26/11 attack lesson, the coastal security framework (ICG, Navy, Coastal Police), the Coastal Security Scheme, and the Coastal Surveillance Network.

Quantum threat preparedness represents the emerging frontier. The National Quantum Mission (2023) includes post-quantum cryptography migration as a strategic pillar. NCIIPC has initiated quantum risk assessment for CII, with migration timelines targeting 2030-2035 for critical systems. The challenge lies in cryptographic agility - designing systems that can transition algorithms without service disruption.

Private sector CII protection introduces regulatory tension. While CII operators bear primary protection responsibility, the regulatory framework straddles sectoral regulators (RBI, TRAI, CERC), NCIIPC, and CERT-In. Overlapping mandates create compliance duplication. The Digital Personal Data Protection Act, 2023 adds data protection obligations that overlap with CII protection obligations, creating potential regulatory arbitrage. The balance between private sector operational autonomy and national security oversight remains a live policy debate.


Key Facts

  • Section 70A IT Act 2000: CII definition and NCIIPC establishment
  • Section 70B IT Act 2000: CERT-In as national incident response agency
  • NCIIPC established 2014, operational 2015
  • Sectors notified as CII: Power, Banking, Telecom, Transport, Government, Strategic Enterprises
  • CERT-In: National incident response, Section 70B
  • NCIIPC: Proactive CII protection, Section 70A
  • Sectoral CERTs: Power (4), Finance, Defence
  • Cyber Crisis Management Plan: 4-tier response structure
  • National Quantum Mission 2023: Post-quantum cryptography pillar
  • DPDP Act 2023: Overlapping data protection obligations for CII

Previous Year Questions

YearStageWhat was tested
2023MainsCritical Information Infrastructure protection challenges
2022PrelimsSection 70A vs 70B IT Act distinction
2021MainsCyber security architecture - CERT-In vs NCIIPC roles
2020PrelimsCERT-In functions under IT Act
2019MainsCritical information infrastructure protection challenges

Statement Elimination Guide

  • "CERT-In is the nodal agency for Critical Information Infrastructure protection in India." - False. NCIIPC is nodal for CII protection under Section 70A; CERT-In is national incident response under Section 70B.
  • "All critical infrastructure in India is automatically designated as CII under IT Act." - False. CII designation requires formal identification by sectoral ministry, validation by NCIIPC, and notification by Central Government under Section 70A(2).
  • "CERT-In and NCIIPC have identical mandates for critical infrastructure protection." - False. NCIIPC has proactive protection mandate for designated CII; CERT-In has national incident response mandate for all cyber incidents.
  • "Sectoral CERTs operate independently of CERT-In." - False. Sectoral CERTs operate under CERT-In coordination framework per Cyber Crisis Management Plan.
  • "Digital Personal Data Protection Act 2023 replaces CII protection obligations under IT Act." - False. DPDP Act adds data protection obligations; IT Act CII protection obligations continue independently.

Current Affairs Hook

  • National Cyber Security Strategy 2023 (draft) proposes unified cyber command structure
  • AIIMS Delhi ransomware attack (Nov 2022) exposed healthcare CII vulnerabilities
  • Oil India ransomware attack (2022) highlighted energy sector vulnerabilities
  • National Quantum Mission (April 2023) includes post-quantum cryptography roadmap
  • Digital Personal Data Protection Act 2023 creates overlapping compliance for CII entities
  • CERT-In directions 2022: 6-hour incident reporting, 5-year log retention mandates

Interlinkages

  • Polity: Federalism tension - Centre designates CII, states implement protection in state sectors
  • Economy: Digital economy security - UPI, UPI Lite, CBDC infrastructure as CII
  • Science & Tech: Quantum computing threat, post-quantum cryptography migration
  • International Relations: Budapest Convention (India non-signatory), bilateral cyber dialogues
  • Governance: Regulatory overlap - sectoral regulators vs NCIIPC vs CERT-In vs DPDP Board

Common Mistakes

  1. Conflating CERT-In incident response role with NCIIPC proactive protection mandate - distinguish statutory mandates (Section 70A vs 70B)
  2. Assuming all critical infrastructure is automatically CII - designation requires formal notification process
  3. Confusing sectoral regulators' cybersecurity guidelines with NCIIPC's statutory CII protection mandate
  4. Overlooking DPDP Act 2023 overlap with CII obligations - dual compliance burden for CII entities
  5. Missing quantum threat timeline - 2030-2035 migration window for post-quantum cryptography

Revision Snapshot

Critical Information Infrastructure protection in India operates under a dual statutory framework: Section 70A (NCIIPC - proactive CII protection) and Section 70B (CERT-In - national incident response). CII designation requires formal notification under Section 70A(2) after sectoral identification and NCIIPC validation. Key sectors notified include power, banking, telecom, transport, government, and strategic enterprises. Sectoral CERTs operate under CERT-In coordination. Emerging challenges: ransomware resilience, supply chain security (SBOM), quantum threat migration (2030-2035), and regulatory overlap between NCIIPC, CERT-In, sectoral regulators, and DPDP Board. Key PYQ anchor: Section 70A vs 70B distinction is high-yield for both Prelims and Mains.


Source Notes

  • Information Technology Act, 2000 (Sections 70A, 70B)
  • NCIIPC Annual Reports (2020-2024)
  • CERT-In Annual Reports and Directions (2022, 2023)
  • National Cyber Security Strategy 2023 (Draft)
  • National Quantum Mission Document (April 2023)
  • Digital Personal Data Protection Act, 2023
  • Cyber Crisis Management Plan (Revised 2022)
  • CERT-In Directions 2022 (6-hour reporting, 5-year logs)