In India, it is legally mandatory for which of the following to report on cyber security incidents?
- 1.Service providers
- 2.Data centres
- 3.Body corporate
Select the correct answer using the code given below:
Answer & explanation
Answer: (d) 1, 2 and 3
All three are covered. Section 70B of the Information Technology Act, 2000 lets the Indian Computer Emergency Response Team (CERT-In) call for information and give directions to service providers, intermediaries, data centres, body corporate and any other person. Failing to comply is punishable, so reporting is a legal duty.
- ✓ 1. Service providers are named in Section 70B(6) as bound by CERT-In's calls for information and directions.
- ✓ 2. Data centres are also named in Section 70B(6).
- ✓ 3. A body corporate (a company or firm) is named too, and Section 70B(7) makes non-compliance punishable with up to one year's imprisonment, a fine of up to one lakh rupees, or both.
- • Since then CERT-In's directions of 28 April 2022 spell this out: any service provider, intermediary, data centre, body corporate and Government organisation must report specified cyber incidents to CERT-In within 6 hours of noticing them.
Remember · Under Section 70B of the IT Act, service providers, intermediaries, data centres and body corporate must give CERT-In the information it seeks; the 2022 directions set a 6-hour reporting window.
Sources
- Information Technology Act, 2000, Section 70B (India Code) ↗ “the agency referred to in sub-section (1) may call for information and give direction to the service providers, intermediaries, data centres, body corporate and any other person.”
- CERT-In Directions under Section 70B(6), 28 April 2022 ↗ · reference work “Any service provider, intermediary, data centre, body corporate and Government organisation shall mandatorily report cyber incidents as mentioned in Annexure I to CERT-In within 6 hours”
Question and answer: UPSC's official GS Paper I (2017, Series A) — paper ↗ · answer key ↗. Explanation: Minimalist IAS, checked 30 Sept 2026 (how we verify). ·