Minimalist IAS
Prelims 2017 paper

UPSC CSE Prelims 2017 · Question 85 · IT, computing & emerging technologies

In India, it is legally mandatory for which of the following to report on cyber security incidents?

Prelims 2017 · Q85

IT, computing & emerging technologies Medium

In India, it is legally mandatory for which of the following to report on cyber security incidents?

  1. 1.Service providers
  2. 2.Data centres
  3. 3.Body corporate

Select the correct answer using the code given below:

Answer & explanation

Answer: (d) 1, 2 and 3

All three are covered. Section 70B of the Information Technology Act, 2000 lets the Indian Computer Emergency Response Team (CERT-In) call for information and give directions to service providers, intermediaries, data centres, body corporate and any other person. Failing to comply is punishable, so reporting is a legal duty.

  • ✓ 1. Service providers are named in Section 70B(6) as bound by CERT-In's calls for information and directions.
  • ✓ 2. Data centres are also named in Section 70B(6).
  • ✓ 3. A body corporate (a company or firm) is named too, and Section 70B(7) makes non-compliance punishable with up to one year's imprisonment, a fine of up to one lakh rupees, or both.
  • • Since then CERT-In's directions of 28 April 2022 spell this out: any service provider, intermediary, data centre, body corporate and Government organisation must report specified cyber incidents to CERT-In within 6 hours of noticing them.

Remember · Under Section 70B of the IT Act, service providers, intermediaries, data centres and body corporate must give CERT-In the information it seeks; the 2022 directions set a 6-hour reporting window.

Sources

Question and answer: UPSC's official GS Paper I (2017, Series A) — paper ↗ · answer key ↗. Explanation: Minimalist IAS, checked 30 Sept 2026 (how we verify). ·

More on IT, computing & emerging technologies

All IT, computing & emerging technologies questions →

Same topic in the Mains syllabus