CERT-In and NCIIPC: India's Cyber Security Agencies
Two agencies, two adjacent sections, one easy mix-up: 70A is NCIIPC, 70B is CERT-In.
India has two national cyber security agencies created by the IT Act, and they divide the work by what is being protected. CERT-In (the Indian Computer Emergency Response Team, section 70B) is the national agency for responding to cyber incidents anywhere in the country. NCIIPC (the National Critical Information Infrastructure Protection Centre, section 70A) protects the small set of systems whose failure would cripple the nation, which now includes several banks' core systems.
For a bank, CERT-In is the agency you report to and take advisories from; NCIIPC matters if any of your systems have been notified as protected systems. Neither is a police force. Criminal complaints go to the police and the cybercrime portal.
You save ₹300
- Full 120-question mocks
- Cyber law coverage
- Module-wise practice
One payment, no subscription · Valid for 2 months
CERT-In and NCIIPC Side by Side
IT Act section
CERT-In
70B
NCIIPC
70A
Parent body
CERT-In
Ministry of Electronics and Information Technology (MeitY)
NCIIPC
National Technical Research Organisation (NTRO)
Scope
CERT-In
Cyber incidents across all sectors
NCIIPC
Critical Information Infrastructure only
Rules
CERT-In
CERT-In Rules, 2013 (notified January 2014)
NCIIPC
NCIIPC Rules, 2013 (notified January 2014)
Power over entities
CERT-In
Can call for information and give directions to service providers, intermediaries, data centres and body corporates (70B(6))
NCIIPC
Can call for information and give directions to critical sectors and those serving them
Penalty for non-compliance
CERT-In
Up to 1 year, or fine up to ₹1 crore, or both (70B(7))
NCIIPC
Unauthorised access to a protected system: up to 10 years and fine (70(3))
| Point | CERT-In | NCIIPC |
|---|---|---|
| IT Act section | 70B | 70A |
| Parent body | Ministry of Electronics and Information Technology (MeitY) | National Technical Research Organisation (NTRO) |
| Scope | Cyber incidents across all sectors | Critical Information Infrastructure only |
| Rules | CERT-In Rules, 2013 (notified January 2014) | NCIIPC Rules, 2013 (notified January 2014) |
| Power over entities | Can call for information and give directions to service providers, intermediaries, data centres and body corporates (70B(6)) | Can call for information and give directions to critical sectors and those serving them |
| Penalty for non-compliance | Up to 1 year, or fine up to ₹1 crore, or both (70B(7)) | Unauthorised access to a protected system: up to 10 years and fine (70(3)) |
What CERT-In Does
Section 70B(4) lists its functions in the area of cyber security.
- check_circleCollects, analyses and shares information on cyber incidents
- check_circleIssues forecasts and alerts of cyber security incidents
- check_circleTakes emergency measures to handle incidents and coordinates the response
- check_circleIssues guidelines, advisories, vulnerability notes and white papers on prevention, response and reporting
- check_circleHas been authorised, since 2016, to monitor and collect traffic data under section 69B for cyber security purposes
The 2022 CERT-In Directions in One Paragraph
On 28 April 2022 CERT-In used its section 70B(6) power to require service providers, intermediaries, data centres, body corporates and government organisations to report specified cyber incidents within 6 hours of noticing them, keep logs of all ICT systems for a rolling 180 days within India, synchronise system clocks with NIC or NPL time servers, and name a point of contact for CERT-In. Banks fall within 'body corporate'. How a bank meets these alongside RBI's own timelines is covered on the bank incident-reporting page.
Quick practice on banking operations. No signup.
The Critical Infrastructure Vocabulary
- Critical Information Infrastructure (CII)
- A computer resource whose incapacitation or destruction would have a debilitating impact on national security, the economy, public health or safety (section 70).
- Protected system
- A computer resource that affects CII and has been declared protected by a government notification. Only persons authorised in writing may access it.
- Critical sector
- In the NCIIPC Rules, a sector whose incapacitation would have that same debilitating impact on the nation. The protected-system notifications for banks and NPCI show that banking and payments are treated this way.
- Nodal officer
- An officer nominated by an organisation in a critical sector to cooperate with NCIIPC on protecting its CII.
Banks as Protected Systems
- check_circleSince 2022 the government has notified certain computer resources of a growing list of financial entities as protected systems under section 70, among them State Bank of India, HDFC Bank, ICICI Bank, Axis Bank, Bank of Baroda, Punjab National Bank, Canara Bank and the National Payments Corporation of India.
- check_circleFor a notified bank, unauthorised access or an attempt at it is a separate offence carrying up to ten years, heavier than the three-year ceiling of section 66.
- check_circleThe Information Security Practices and Procedures for Protected System Rules, 2018 set the security practices such organisations must follow.
How the IIBF Exam Tests This
- check_circleSection numbers: 70A is NCIIPC, 70B is CERT-In. They are adjacent and easy to swap.
- check_circleParent bodies: CERT-In sits under MeitY; NCIIPC is part of NTRO.
- check_circleScope: an incident at a branch's email server is a CERT-In matter; NCIIPC is only for CII.
- check_circleOlder material may quote the section 70B(7) fine as ₹1 lakh. Since 30 November 2023 it is up to ₹1 crore.
FAQs
What is CERT-In and under which section is it set up?expand_more
The Indian Computer Emergency Response Team, the national agency for cyber incident response. It works under section 70B of the IT Act, 2000 and sits within the Ministry of Electronics and Information Technology.
What is the difference between CERT-In and NCIIPC?expand_more
CERT-In handles cyber incidents across all sectors. NCIIPC, under section 70A and part of NTRO, protects only Critical Information Infrastructure such as notified banking, power and telecom systems.
What is the time limit for reporting a cyber incident to CERT-In?expand_more
Six hours from noticing the incident or being told about it, under CERT-In's directions of 28 April 2022.
What is the punishment for accessing a protected system?expand_more
Up to ten years' imprisonment and a fine, under section 70(3) of the IT Act.
Next steps
- Incident Reporting by Banksarrow_forward
- International Bodiesarrow_forward
- RBI Cyber Frameworkarrow_forward
120 questions, 2 hours, scored instantly.
