In India, it is legally mandatory for which of the following to report on cyber security incidents? 1. Service providers 2. Data centres 3. Body corporate Select the correct answer using the code given below:

Updated 11 Apr 2026 · From UPSC Prelims GS Paper I 2017, Q88

Contents12
UPSC Prelims GS2017Science and Technology
  1. A1 only
  2. B1 and 2 only
  3. C3 only
  4. D1, 2 and 3
Show answer

Answer: (D) 1, 2 and 3

Under the Information Technology Act, 2000 (as amended in 2008), the Indian Computer Emergency Response Team (CERT-In) serves as the national agency for cyber security.

The Act mandates that any service provider, intermediary, data centre, or body corporate must report cyber security incidents to CERT-In.

Section 70B of the IT Act gives CERT-In the power to:

  • collect, analyse, and disseminate information on cyber incidents
  • issue forecasts and alerts
  • coordinate response activities
  • issue guidelines on information security practices

Failure to report cyber incidents or comply with CERT-In's directions is punishable with:

  • imprisonment up to one year
  • a fine up to one lakh rupees
  • or both

The scope of mandatory reporting is deliberately broad — it covers:

  1. Service providers — companies that provide internet, telecom, or other digital services
  2. Data centres — facilities that store and process data
  3. Body corporate — any company, firm, or association engaged in commercial or professional activities using computer resources

Therefore, all three categories listed in the question are legally required to report cyber security incidents, making option (d) correct.

Why this was asked

The IT Act 2008 amendment created CERT-In as India's national cybersecurity agency with power to mandate incident reporting from all major digital entities.

The Act deliberately uses broad categories like 'body corporate' to ensure no commercial entity using computers can escape reporting obligations to CERT-In.

UPSC is testing whether students know the comprehensive scope of mandatory cyber reporting - it covers service providers, data centres, and all companies, not just tech firms.

CERT-In: India's Cyber Security Agency

Science And Technology CERT-In cyber security incidents

CERT-In: Powers, Functions & Legal Framework

Must know

CERT-In is India's national agency for cyber security under Section 70B of IT Act 2000

All service providers, data centres, and body corporates must report cyber incidents to CERT-In

Non-compliance attracts imprisonment up to 1 year or fine up to ₹1 lakh or both

Good to know

CERT-In can issue guidelines, alerts, and coordinate national cyber incident response

CERT-In (Indian Computer Emergency Response Team) is the nodal agency for cyber security in India, established under the Information Technology Act, 2000 (amended in 2008). It serves as the first line of defense against cyber threats and coordinates national incident response.

CERT-In Powers & Functions

Function

Legal Basis

Key Authority

Collect & analyse cyber incident information

Section 70B

Mandatory reporting from entities

Issue forecasts & alerts on cyber threats

Section 70B

Proactive threat intelligence

Coordinate response to cyber incidents

Section 70B

National incident management

Issue guidelines on information security

Section 70B

Binding security practices

Emergency response to cyber attacks

Section 70B

Crisis management authority

This question tests knowledge of mandatory cyber incident reporting under Indian law. The IT Act deliberately casts a wide net — covering all entities that use computer resources for business purposes, not just IT companies.

Exam traps

Trap: Students often think only IT companies need to report — but any body corporate using computer resources is covered

Trap: Data centres might seem exempt as infrastructure providers — but they're explicitly included in reporting requirements

Trap: The scope is broader than cyber security companies — includes telecom, internet, and any digital service providers

Mandatory Cyber Incident Reporting Entities

Science And Technology Service providers Data centres Body corporate

Who Must Report Cyber Incidents: Complete Coverage Under IT Act

Must know

Service providers, data centres, and body corporates all have mandatory reporting obligations

Reporting requirement applies to any entity using computer resources for business

No exemptions for size, sector, or type of business operations

Entities Required to Report Cyber Incidents

Entity Type

Definition

Examples

Why Covered

Service Providers

Companies providing internet, telecom, or digital services

ISPs, telecom operators, cloud providers

Handle critical digital infrastructure

Data Centres

Facilities that store, process, or manage data

Server farms, colocation facilities, cloud data centers

Store sensitive data for multiple clients

Body Corporate

Any company, firm, or association in commercial/professional activities

Banks, e-commerce sites, software companies, hospitals with IT systems

Use computer resources for business operations

Scope & Coverage

Broad definition ensures no digital entity escapes cyber security oversight

Body corporate includes non-IT companies if they use computer resources (banks, hospitals, retailers)

Small and large entities equally covered — no size-based exemptions

Government and private entities both subject to reporting requirements

Coverage extends to intermediaries like payment gateways and digital platforms

The 2017 UPSC question tested whether students understood that cyber security obligations extend beyond traditional IT companies to encompass India's entire digital ecosystem. The correct answer is D) 1, 2 and 3 because the IT Act deliberately uses broad categories.

Exam traps

Option A (1 only) trap: Assumes only service providers report — ignores data centres and corporates

Option B (1 and 2 only) trap: Excludes body corporates — but any business using IT systems must report

Option C (3 only) trap: Ignores that service providers and data centres have explicit obligations

Information Technology Act 2000 & Cyber Laws

Science And Technology Information Technology Act cyber security

IT Act 2000: India's Digital Legal Framework

Must know

IT Act 2000 (amended 2008) is India's primary law for digital transactions and cyber security

Section 70B establishes CERT-In and mandatory incident reporting

Good to know

Covers electronic governance, cyber crimes, and digital signatures

2008 amendments added cyber terrorism provisions and stronger penalties

The Information Technology Act, 2000 provides India's legal foundation for digital governance, electronic transactions, and cyber security. The 2008 amendments significantly strengthened cyber security provisions and established institutional frameworks.

IT Act 2000: Key Provisions

# Information Technology Act 2000
## Digital Governance
- Electronic documents legal validity
- Digital signatures framework
- Electronic service delivery
- Government digital initiatives
## Cyber Security
- CERT-In establishment (Section 70B)
- Mandatory incident reporting
- Cyber security guidelines
- Critical infrastructure protection
## Cyber Crimes
- Hacking (Section 66)
- Identity theft (Section 66C)
- Cyber terrorism (Section 66F)
- Data theft & privacy violations
## Penalties & Enforcement
- Fines up to ₹1 crore
- Imprisonment up to life
- Adjudicating officers
- Appellate tribunals

Key Sections for UPSC

Section

Provision

Significance

Section 43A

Data protection & compensation for negligence

Corporate data security obligations

Section 66

Computer-related offences (hacking)

Primary cyber crime provision

Section 69

Government power to intercept digital communications

National security & surveillance

Section 70B

CERT-In establishment & incident reporting

National cyber security coordination

Section 79

Intermediary liability & safe harbour

Platform accountability framework

Exam traps

Don't confuse IT Act 2000 with Digital India Programme — former is legislation, latter is policy initiative

2008 amendments added most cyber security provisions — original 2000 Act focused on electronic governance

Section 70B specifically creates CERT-In — not just a general cyber security provision

India's Cyber Security Institutional Framework

Science And Technology

India's Multi-Layered Cyber Security Architecture

Must know

CERT-In serves as national nodal agency under Ministry of Electronics & IT

Good to know

National Cyber Security Strategy 2020 provides comprehensive policy framework

Critical Information Infrastructure protection under separate NCIIPC

Cyber Swachhta Kendra helps citizens clean infected systems

India has built a comprehensive cyber security ecosystem combining legal frameworks, institutional structures, and operational capabilities. This multi-tier approach addresses both national security threats and civilian cyber safety.

Cyber Security Governance Structure

%%{init: {"flowchart": {"wrappingWidth": 460}}}%%
flowchart TD
  s1["`****National Security Council Secretariat****
Apex level policy coordination and strategic oversight`"]
  s2["`****Ministry of Electronics & IT****
Policy formulation and administrative oversight`"]
  s3["`****CERT-In (Operational Level)****
Incident response, threat analysis, and coordination`"]
  s4["`****Sectoral CERTs****
Specialized teams for finance, telecom, power sectors`"]
  s5["`****Organizational CERTs****
Internal cyber security teams in companies and institutions`"]
  s1 --> s2
  s2 --> s3
  s3 --> s4
  s4 --> s5

Key Cyber Security Institutions

Institution

Role

Established

Key Focus

CERT-In

National incident response & coordination

2004

Civilian cyber security

NCIIPC

Critical infrastructure protection

2014

Power, telecom, finance, transport

NTRO

Technical intelligence & cyber warfare

2004

National security & surveillance

Cyber Swachhta Kendra

Malware detection & cleanup

2017

Citizen cyber hygiene

National Cyber Coordination Centre

Real-time threat monitoring

2017

Situational awareness

Institutional Structure

India's layered approach ensures both strategic oversight and operational response capabilities
India's layered approach ensures both strategic oversight and operational response capabilities

Source: MediaNama — The Architecture of Cybersecurity Institutions in India by ... · www.medianama.com