THE GAZETTE OF INDIA EXTRAORDINARY
Insertion, of
new sections
70A and 70B.
National nodal
agency,
_ [Parr ii—
(6) after sub-section (3), the following sub-section shall be inserted
, namely:—
“(4) The Central Government shall prescribe the informa
tion security
Practices and procedures for such protected system.”.
36. After section 70 of the principal Act, the following sections
shall be inserted,
namely:—
“TOA. (1) The Central Government may, by notification publi
shed
in the Officia
l
Gazette, designate any organisation of the Government as
the national nodal agency
in respect of Critical Information Infrastructure Protection,
(2) The national nodal agency designated under sub-section
(J) shall
be
responsible for all measures including Research and Development
relating to
protect
ion of Critical Information Infrastructure.
(3) The manner of performing functions and duties of the agency
referred to in
sub-section (/) shall be such as may be prescribed.
Indian
Computer
Emergency
Response
Team to
serve as
national
agency for
incident
response.
70B. (1) The Central Government shall,by notification in the
Official Gazette,
appoint an agency of the Government to be called the Indian
Computer Emergency
Response Team.
(2) The Central Government shall provide the agency referred to
in sub-section
(1) with a Director-General and such other officers and employee
as may s
be prescribed.
(3) The salary and allowances and terms and conditions oftheDirect
or-General
and other officers and employees shall be such as may be prescri
bed.
(#) The Indian Computer Emergency Response Team shall serve
as the national
agency for performing the following functions in the area
of. ‘cyber security,—
(a) collection, analysis and dissemination of information
on cyber
incidents;
4
(4) forecast and alerts of cyber security incidents;
(c) emergency measures for handling cyber security incident
s;
(d) coordination of cyber incidents response activities;
(€) issue guidelines, advisories, vulnerability notes and
whitepapers
relating to information security practices, procedures, preventation,
response
and reporting of cyber incidents;
(/ such other functions relating to cyber security as may
be prescribed.
(5) The manner of performing functions and duties of the agency
referred to in
sub-section (/) shall be such as may be prescribed.
(6) For carrying out the provisions of sub-section (9), the agency
referred to in
sub-section (/) may call for information and give direction
to the service providers,
intermediaries, data centrds, body corporate and any other
person.
(7) Any service provider, intermediaries, data centres, body corporate
or person
who fails to provide the information called for or comply with
the direction under subsection (6), shall be punishable with imprisonment fora term which
may extend to one
year or with fine which may extend to one lakh Tupees
or with both.
(8) No court shall take cognizance of any offence under this
section, except on
a complaint made by an officer authorised in this behalf by
the agency referred to in
et:
sub-section