Which of the following sectors have been identified as 'critical sectors' by the National Critical Information Infrastructure Protection Centre? 1. Power and Energy 2. Industry 3. Banking and Financial services 4. Irrigation 5. Education Select the answer using the code given below:
- (a)3, 4 and 5
- (b)1 and 3 only
- (c)1, 2 and 4
- (d)1, 3 and 4
Correct — B, 1 and 3 only. The National Critical Information Infrastructure Protection Centre lists its critical sectors as Power and Energy; Banking, Financial Services and Insurance; Telecom; Transport; Government; and Strategic and Public Enterprises. Of the five items the paper offers, only Power and Energy and Banking and Financial services appear on that list. Industry, Irrigation and Education are not separately designated, whatever their importance in other contexts. The logic behind the list is the statutory definition of critical information infrastructure — a computer resource whose incapacitation would have a debilitating impact on national security, the economy, public health or public safety.
- (a)3, 4 and 5 — Irrigation and Education are not among the designated sectors, and this option leaves out Power and Energy, which is.
- (c)1, 2 and 4 — Industry and Irrigation are not on the list, and this option drops Banking and Financial services, which is.
- (d)1, 3 and 4 — The first two are right, but Irrigation is not separately designated. Water systems can fall inside other sectors without being named as one.
The NCIIPC was established under section 70A of the Information Technology Act, 2000, as inserted by the amendment of 2008, and was notified in January 2014 as the national nodal agency for the protection of critical information infrastructure. It functions as a unit of the National Technical Research Organisation. It is distinct from CERT-In, which is the national agency for computer security incidents generally and works under the Ministry of Electronics and Information Technology; the NCIIPC's remit is the narrower set of systems whose failure would be nationally debilitating.
Two things make this item answerable without memorising the notification. First, the sectors named are the ones where a computer failure would be felt within hours across the country — the grid, payments, telecommunications, transport and government systems. Second, the distractors work by offering sectors that matter for development rather than for immediate national resilience. Keeping the two agencies apart is worth the effort, since papers test both: CERT-In handles incident reporting by service providers, data centres and body corporates, while the NCIIPC protects designated critical information infrastructure.
- The NCIIPC was constituted under section 70A of the IT Act, 2000, and notified in January 2014.
- It is a unit of the National Technical Research Organisation and is the nodal agency for critical information infrastructure protection.
- Its critical sectors are Power and Energy; Banking, Financial Services and Insurance; Telecom; Transport; Government; and Strategic and Public Enterprises.
- Critical information infrastructure is defined as a computer resource whose incapacitation would have a debilitating impact on national security, the economy, public health or safety.
- CERT-In, under the Ministry of Electronics and Information Technology, is the separate national agency for computer security incidents.
The test is whether a failure would be debilitating for national security, the economy, public health or public safety.
- Assuming any sector important to development must be a designated critical sector.
- Confusing the NCIIPC's remit with CERT-In's wider incident-reporting role.
- Reading 'critical sectors' as a policy phrase rather than a statutory designation.
A current-affairs item on institutional detail, where the answer follows from understanding the definition even if the notified list is not memorised.
In India, it is legally mandatory for which of the following to report on cyber security incidents? 1. Service providers 2. Data centres 3. Body corporate — Select the correct answer using the code given below:
- (a) 1 only
- (b) 1 and 2 only
- (c) 3 only
- (d) 1, 2 and 3
Answer(d) 1, 2 and 3
The other half of India's cyber architecture. Reporting duties under the IT Act fall on service providers, data centres and body corporates alike, and they run to CERT-In, while designated critical infrastructure is the NCIIPC's charge.
Consider the following statements with reference to the latest guidelines issued by the Indian Computer Emergency Response Team (CERT-In): 1. Data centres and service providers shall compulsorily report cyber security breaches within 24 hours. 2. Virtual Private Network providers shall retain user data for at least five years and share records with authorities when required. Which of the statements given above is/are correct?
- (a) 1 only
- (b) 2 only
- (c) Both 1 and 2
- (d) Neither 1 nor 2
Answer(b) 2 only
CERT-In's directions on an earlier CAPF paper whose key UPSC published. Comparing the two shows how the examiners split the field: incident reporting and data retention sit with CERT-In, while sectoral designation sits with the centre named here.
- practice — not a real PYQ
The NCIIPC has been constituted under which one of the following?
- (a)The Information Technology Act, 2000
- (b)The Telegraph Act, 1885
- (c)The Disaster Management Act, 2005
- (d)The National Security Act, 1980
Answer(a) The Information Technology Act, 2000 — under section 70A, inserted by the 2008 amendment.
- practice — not a real PYQ
Which agency is India's national nodal body for responding to computer security incidents generally?
- (a)NCIIPC
- (b)CERT-In
- (c)NTRO
- (d)NIC
Answer(b) CERT-In — the Indian Computer Emergency Response Team, under the Ministry of Electronics and Information Technology.