[TOPIC CLASSIFICATION]
- Topic type: Institutional Framework + Current Affairs
- PYQ frequency: High
- Exam stage: Prelims + Mains
- Primary GS paper: GS3 (Internal Security)
[EXAMINER REASONING]
- Trap: Confusing CII notification under IT Act with general cybersecurity guidelines - notification is statutory, guidelines are advisory
- Most confused: NCIIPC vs CERT-In mandates - NCIIPC protects CII, CERT-In is national incident response
- Key anchor: Section 70A IT Act = CII protection mandate, Section 70B = CERT-In
- Current affairs hook: Digital Personal Data Protection Act 2023 overlaps with CII protection
- Mains hinge: Private sector CII protection - regulatory capture vs national security balance
Core Concept
Critical Information Infrastructure (CII) forms the backbone of India's digital sovereignty. The Information Technology Act, 2000, amended in 2008, provides the statutory backbone through Section 70A which defines CII as "the computer resource, the incapacitation or destruction of which shall have debilitating impact on national security, economy, public health or safety." This definition is deliberately broad, covering sectors from power grids and banking systems to transportation networks and government databases.
The National Critical Information Infrastructure Protection Centre (NCIIPC), established under Section 70A(1), serves as the nodal agency for CII protection. Unlike CERT-In which functions as the national incident response agency under Section 70B, NCIIPC has a proactive mandate - threat assessment, vulnerability assessment, and protection of designated CII. This distinction is frequently tested: NCIIPC protects designated critical infrastructure proactively, while CERT-In responds to cyber incidents nationally.
The identification and notification process under Section 70A(2) involves sectoral ministries identifying CII in their domains, followed by NCIIPC validation and formal notification by the Central Government. Once notified, CII entities are legally bound to implement protection measures, conduct audits, and report incidents. As of 2024, sectors notified include power, banking, telecom, transport, government, and strategic enterprises. The Power Grid Corporation, NPCI, major stock exchanges, and Aadhaar infrastructure are among designated CIIs.
Sectoral Computer Emergency Response Teams (CERTs) operate under CERT-In's coordination framework. Sectoral CERTs for power (CERT-Thermal, CERT-Hydro, CERT-Transmission, CERT-Distribution), finance (CERT-Fin), and defence (CERT-Def) provide sector-specific threat intelligence and incident response. The Cyber Crisis Management Plan (CCMP) mandates sectoral crisis management plans, regular mock drills, and a four-tier response structure - organisational, sectoral, national (NCIIPC/CERT-In), and national crisis management committee (NCMC) level.
Ransomware preparedness has gained urgency post-2021 attacks on AIIMS Delhi, Oil India, and SpiceJet. The 2022 Cyber Crisis Management Plan revision mandated offline backups, network segmentation, privileged access management, and ransomware-specific playbooks. Supply chain security gained prominence post-SolarWinds (2020) and Log4j (2021) incidents, leading to Software Bill of Materials (SBOM) requirements for government procurement.