UPSC Prelims 2017 · Question 35 of 99

UPSC Prelims 2017 question on Cyber Security Incident Reporting

In India, it is legally mandatory for which of the following to report on cyber security incidents?

1. Service providers
2. Data centres
3. Body corporate

Select the correct answer using the code given below:

  1. 1 only
  2. 1 and 2 only
  3. 3 only
  4. 1, 2 and 3
Show answer

Answer: D. 1, 2 and 3

Verdict

The answer is 1, 2 and 3. Service providers, data centres and body corporates are all legally required to report cyber security incidents.

Analysis

Under the information technology framework, the Indian Computer Emergency Response Team serves as the national nodal agency for cyber security, collecting, analysing and disseminating information on cyber incidents, issuing forecasts and alerts, and coordinating incident response. The rules made under the Act make mandatory reporting of cyber security incidents applicable to service providers, intermediaries, data centres and body corporates alike, so all three categories in the question are covered.

Source

Press Information Bureau release and the Information Technology Act framework.

How to crack it

Reason from the purpose of a national incident response agency. Such a body can only function if it receives reports from every entity that holds or moves data, so a reporting duty confined to one category would defeat the design. Where a regulatory obligation exists to build a national picture, expect the obligation to be broad rather than narrow, and expect the inclusive option. Keep CERT-In tagged as the nodal agency, since that single fact anchors the whole topic.

Related current-affairs briefs

More questions on Information and Communication Technology

All 36 questions on Information and Communication Technology →

← Full 2017 question paper · All Science and Technology questions