In India, it is legally mandatory for which of the following to report on cyber security incidents? 1. Service providers 2. Data centres 3. Body corporate Select the correct answer using the code given below:
Contents12
- A1 only
- B1 and 2 only
- C3 only
- D1, 2 and 3
Show answer
Answer: (D) 1, 2 and 3
Under the Information Technology Act, 2000 (as amended in 2008), the Indian Computer Emergency Response Team (CERT-In) serves as the national agency for cyber security.
The Act mandates that any service provider, intermediary, data centre, or body corporate must report cyber security incidents to CERT-In.
Section 70B of the IT Act gives CERT-In the power to:
- collect, analyse, and disseminate information on cyber incidents
- issue forecasts and alerts
- coordinate response activities
- issue guidelines on information security practices
Failure to report cyber incidents or comply with CERT-In's directions is punishable with:
- imprisonment up to one year
- a fine up to one lakh rupees
- or both
The scope of mandatory reporting is deliberately broad — it covers:
- Service providers — companies that provide internet, telecom, or other digital services
- Data centres — facilities that store and process data
- Body corporate — any company, firm, or association engaged in commercial or professional activities using computer resources
Therefore, all three categories listed in the question are legally required to report cyber security incidents, making option (d) correct.
The IT Act 2008 amendment created CERT-In as India's national cybersecurity agency with power to mandate incident reporting from all major digital entities.
The Act deliberately uses broad categories like 'body corporate' to ensure no commercial entity using computers can escape reporting obligations to CERT-In.
UPSC is testing whether students know the comprehensive scope of mandatory cyber reporting - it covers service providers, data centres, and all companies, not just tech firms.
CERT-In: India's Cyber Security Agency
Science And Technology CERT-In cyber security incidents
CERT-In: Powers, Functions & Legal Framework
CERT-In is India's national agency for cyber security under Section 70B of IT Act 2000
All service providers, data centres, and body corporates must report cyber incidents to CERT-In
Non-compliance attracts imprisonment up to 1 year or fine up to ₹1 lakh or both
CERT-In can issue guidelines, alerts, and coordinate national cyber incident response
CERT-In (Indian Computer Emergency Response Team) is the nodal agency for cyber security in India, established under the Information Technology Act, 2000 (amended in 2008). It serves as the first line of defense against cyber threats and coordinates national incident response.
CERT-In Powers & Functions
Function | Legal Basis | Key Authority |
|---|---|---|
Collect & analyse cyber incident information | Section 70B | Mandatory reporting from entities |
Issue forecasts & alerts on cyber threats | Section 70B | Proactive threat intelligence |
Coordinate response to cyber incidents | Section 70B | National incident management |
Issue guidelines on information security | Section 70B | Binding security practices |
Emergency response to cyber attacks | Section 70B | Crisis management authority |
This question tests knowledge of mandatory cyber incident reporting under Indian law. The IT Act deliberately casts a wide net — covering all entities that use computer resources for business purposes, not just IT companies.
Trap: Students often think only IT companies need to report — but any body corporate using computer resources is covered
Trap: Data centres might seem exempt as infrastructure providers — but they're explicitly included in reporting requirements
Trap: The scope is broader than cyber security companies — includes telecom, internet, and any digital service providers
Mandatory Cyber Incident Reporting Entities
Science And Technology Service providers Data centres Body corporate
Who Must Report Cyber Incidents: Complete Coverage Under IT Act
Service providers, data centres, and body corporates all have mandatory reporting obligations
Reporting requirement applies to any entity using computer resources for business
No exemptions for size, sector, or type of business operations
Entities Required to Report Cyber Incidents
Entity Type | Definition | Examples | Why Covered |
|---|---|---|---|
Service Providers | Companies providing internet, telecom, or digital services | ISPs, telecom operators, cloud providers | Handle critical digital infrastructure |
Data Centres | Facilities that store, process, or manage data | Server farms, colocation facilities, cloud data centers | Store sensitive data for multiple clients |
Body Corporate | Any company, firm, or association in commercial/professional activities | Banks, e-commerce sites, software companies, hospitals with IT systems | Use computer resources for business operations |
Scope & Coverage
Broad definition ensures no digital entity escapes cyber security oversight
Body corporate includes non-IT companies if they use computer resources (banks, hospitals, retailers)
Small and large entities equally covered — no size-based exemptions
Government and private entities both subject to reporting requirements
Coverage extends to intermediaries like payment gateways and digital platforms
The 2017 UPSC question tested whether students understood that cyber security obligations extend beyond traditional IT companies to encompass India's entire digital ecosystem. The correct answer is D) 1, 2 and 3 because the IT Act deliberately uses broad categories.
Option A (1 only) trap: Assumes only service providers report — ignores data centres and corporates
Option B (1 and 2 only) trap: Excludes body corporates — but any business using IT systems must report
Option C (3 only) trap: Ignores that service providers and data centres have explicit obligations
Information Technology Act 2000 & Cyber Laws
Science And Technology Information Technology Act cyber security
IT Act 2000: India's Digital Legal Framework
IT Act 2000 (amended 2008) is India's primary law for digital transactions and cyber security
Section 70B establishes CERT-In and mandatory incident reporting
Covers electronic governance, cyber crimes, and digital signatures
2008 amendments added cyber terrorism provisions and stronger penalties
The Information Technology Act, 2000 provides India's legal foundation for digital governance, electronic transactions, and cyber security. The 2008 amendments significantly strengthened cyber security provisions and established institutional frameworks.
IT Act 2000: Key Provisions
# Information Technology Act 2000
## Digital Governance
- Electronic documents legal validity
- Digital signatures framework
- Electronic service delivery
- Government digital initiatives
## Cyber Security
- CERT-In establishment (Section 70B)
- Mandatory incident reporting
- Cyber security guidelines
- Critical infrastructure protection
## Cyber Crimes
- Hacking (Section 66)
- Identity theft (Section 66C)
- Cyber terrorism (Section 66F)
- Data theft & privacy violations
## Penalties & Enforcement
- Fines up to ₹1 crore
- Imprisonment up to life
- Adjudicating officers
- Appellate tribunalsKey Sections for UPSC
Section | Provision | Significance |
|---|---|---|
Section 43A | Data protection & compensation for negligence | Corporate data security obligations |
Section 66 | Computer-related offences (hacking) | Primary cyber crime provision |
Section 69 | Government power to intercept digital communications | National security & surveillance |
Section 70B | CERT-In establishment & incident reporting | National cyber security coordination |
Section 79 | Intermediary liability & safe harbour | Platform accountability framework |
Don't confuse IT Act 2000 with Digital India Programme — former is legislation, latter is policy initiative
2008 amendments added most cyber security provisions — original 2000 Act focused on electronic governance
Section 70B specifically creates CERT-In — not just a general cyber security provision
India's Cyber Security Institutional Framework
Science And Technology
India's Multi-Layered Cyber Security Architecture
CERT-In serves as national nodal agency under Ministry of Electronics & IT
National Cyber Security Strategy 2020 provides comprehensive policy framework
Critical Information Infrastructure protection under separate NCIIPC
Cyber Swachhta Kendra helps citizens clean infected systems
India has built a comprehensive cyber security ecosystem combining legal frameworks, institutional structures, and operational capabilities. This multi-tier approach addresses both national security threats and civilian cyber safety.
Cyber Security Governance Structure
%%{init: {"flowchart": {"wrappingWidth": 460}}}%%
flowchart TD
s1["`****National Security Council Secretariat****
Apex level policy coordination and strategic oversight`"]
s2["`****Ministry of Electronics & IT****
Policy formulation and administrative oversight`"]
s3["`****CERT-In (Operational Level)****
Incident response, threat analysis, and coordination`"]
s4["`****Sectoral CERTs****
Specialized teams for finance, telecom, power sectors`"]
s5["`****Organizational CERTs****
Internal cyber security teams in companies and institutions`"]
s1 --> s2
s2 --> s3
s3 --> s4
s4 --> s5Key Cyber Security Institutions
Institution | Role | Established | Key Focus |
|---|---|---|---|
CERT-In | National incident response & coordination | 2004 | Civilian cyber security |
NCIIPC | Critical infrastructure protection | 2014 | Power, telecom, finance, transport |
NTRO | Technical intelligence & cyber warfare | 2004 | National security & surveillance |
Cyber Swachhta Kendra | Malware detection & cleanup | 2017 | Citizen cyber hygiene |
National Cyber Coordination Centre | Real-time threat monitoring | 2017 | Situational awareness |
Institutional Structure

Source: MediaNama — The Architecture of Cybersecurity Institutions in India by ... · www.medianama.com