## Policy Analysis Report: Declaration of UIDAI Computer Resources as Protected Systems
**1. Executive Summary:**
This report analyzes a notification issued by the Ministry of Electronics and Information Technology, Government of India, dated April 13, 2022. This notification declares specific computer resources of the Central Identities Data Repository of the Unique Identification Authority of India (UIDAI) and its associated facilities and information assets as "protected systems" under Section 70 of the Information Technology Act, 2000. The core purpose of this declaration is to enhance the security and protection of critical infrastructure and data related to the Aadhaar system. Key findings indicate a focus on securing data centers, security and network operation centers, cyber forensic capabilities, and logistical infrastructure associated with UIDAI. The report details the specifics of these protected resources, the likely rationale, and the expected impact of this declaration. The notification supersedes an earlier notification from 2015. Thus, this report is treating it as an amendment, even though it could be perceived as a "re-issuance."
**2. Introduction:**
This report aims to provide a comprehensive analysis of the notification issued by the Ministry of Electronics and Information Technology on April 13, 2022, regarding the declaration of specific UIDAI computer resources as protected systems. The analysis is based solely on the information provided in the given policy text.
**3. Policy Overview:**
* **Amendment:** This notification supersedes the previous notification G.S.R. 993E, dated December 11, 2015 (published December 21, 2015), issued by the Ministry of Communications and Information Technology.
* **Core Objective(s):** The core objective, inferred from the text, is to enhance the security of the Central Identities Data Repository of UIDAI by designating specific computer resources as "protected systems" under the Information Technology Act, 2000. This aims to prevent unauthorized access, use, modification, or disruption of these critical assets.
**4. Background and Rationale:**
This notification is effectively an amendment or re-issuance of a previous policy. The likely reason for superseding the 2015 notification, inferred from the text, is to update the list of protected systems and facilities to reflect changes in UIDAI's infrastructure, technology, or security needs since 2015. The original need likely stemmed from the requirement to provide a secure IT environment for Aadhaar data and operations under the IT Act, 2000. The update probably addresses evolving cyber threats and expands the scope of protection to cover more of UIDAI's critical assets.
**5. Key Provisions / Changes:**
This notification supersedes the 2015 notification. The main change is the updated list of UIDAI's computer resources now designated as protected systems. The changes are as follows:
* **What specific part of the original policy is being changed:** The entire list of "protected systems" is being updated.
* **What the *new* rule/provision *is*:** The *new* rule is the designation of the *following* specific computer resources of the Central Identities Data Repository of UIDAI as "protected systems" :
1. Bangalore Hebbal Data Centre HDC
2. Security Operations Centre of HDC
3. Network Operations Centre of HDC
4. Manesar Data Centre MDC
5. Security Operations Centre of MDC
6. Network Operations Centre of MDC
7. UIDAI Headquarters Security Operations Centre
8. Information Security Division and Enforcement Wings of UIDAI Head Quarter
9. Cyber Forensic Laboratory at UIDAI Head Quarter
10. Logistics Infrastructure and Dependencies installed at UIDAI
* **Explain the *difference* or the *effect* of this specific change:** The effect of this change is that the identified systems now fall under the enhanced protection measures provided for "protected systems" under the IT Act, 2000. The previous list, established in the 2015 notification, is no longer in effect, with these changes now superseding them. Although the original list is not provided, based on the updated list it is safe to say that there are new additions to the list of protected systems.
**6. Target Audience and Stakeholders:**
The primary target audience and stakeholders affected by this policy include:
* **UIDAI:** As the agency responsible for the Central Identities Data Repository.
* **Personnel responsible for managing and securing the listed computer resources:** This includes IT administrators, security professionals, and operations staff working at the data centers, security operation centers, and UIDAI headquarters.
* **Ministry of Electronics and Information Technology (MeitY):** As the issuing authority and regulator for cybersecurity.
* **Law enforcement agencies:** Responsible for investigating and prosecuting cybercrimes related to protected systems.
* **Aadhaar holders:** Whose data security is indirectly enhanced by this policy.
**7. Implementation Aspects (Inferred):**
Based on the text, the following can be inferred about implementation:
* **Responsible agency/bodies:** The UIDAI is responsible for implementing the measures to protect the designated systems. MeitY has oversight through its regulatory authority.
* **Timelines or procedures:** The notification is effective immediately upon publication. Further procedures for implementing security measures are not specified in the text but would likely be guided by existing cybersecurity frameworks and best practices.
* **(If Amendment):** The change (updating the list of protected systems) requires immediate action by UIDAI to implement necessary protection measures for the newly added facilities. This may involve updating security protocols, access controls, and incident response plans to specifically address the systems now designated as "protected." They also need to ensure compliance to the changed list, no longer being compliant to the previous list of protected systems.
**8. Expected Outcomes / Impact of Changes:**
The likely intended outcome of these changes is:
* Enhanced security posture for UIDAI's critical infrastructure.
* Reduced risk of cyberattacks and data breaches affecting Aadhaar data.
* Improved compliance with legal and regulatory requirements for data protection.
* Increased public trust in the security and reliability of the Aadhaar system.
* Strengthened cyber security posture of the nation's critical IT infrastructure.
**9. Conclusion:**
The notification declaring specific UIDAI computer resources as protected systems represents a significant step towards strengthening the security of the Aadhaar system. This action, by updating the list of protected systems, reinforces the government's commitment to safeguarding critical infrastructure and protecting citizen data. The enhanced security measures for these systems will likely contribute to a more resilient and secure digital ecosystem in India.
Key Entities Referenced
Information Technology Act, 2000: An act of the Indian Parliament
Central Government: The executive branch of the Union of India
Central Identities Data Repository: A computer resource maintained by UIDAI
Unique Identification Authority of India: Also known as UIDAI, is the authority responsible for implementing the Aadhaar Act
Bangalore Hebbal Data Centre: Also known as HDC, is a facility of UIDAI
Security Operations Centre of HDC: A security center of Bangalore Hebbal Data Centre HDC
Network Operations Centre of HDC: A network center of Bangalore Hebbal Data Centre HDC
Manesar Data Centre: Also known as MDC, is a facility of UIDAI
Security Operations Centre of MDC: A security center of Manesar Data Centre MDC
Network Operations Centre of MDC: A network center of Manesar Data Centre MDC
UIDAI Headquarters Security Operations Centre: A security center of UIDAI Headquarter
Information Security Division: A division of UIDAI Head Quarter
Enforcement Wings of UIDAI Head Quarter: A department of UIDAI Head Quarter
Cyber Forensic Laboratory at UIDAI Head Quarter: A laboratory located at UIDAI Head Quarter
Logistics Infrastructure and Dependencies installed at UIDAI: Infrastructure installed at UIDAI
Ministry of Electronics and Information Technology: The ministry responsible for IT policy in India.
New Delhi: Capital of India
रजिस्ट्री स.ं डी.एल.- 33004/99 REGD. No. D. L.-33004/99
सी.जी.-डी.एल.-अ.-13042022-235138
xxxGIDHxxx
CG-DL-E-13042022-235138
xxxGIDExxx
असाधारण
EXTRAORDINARY
भाग II—खण् ड 3—उप-खण्ड (ii)
PART II—Section 3—Sub-section (ii)
प्राजधकार स ेप्रकाजित
PUBLISHED BY AUTHORITY
स.ं 1726] नई ददल्ली, बवधंार, अप्रलै 13, 2022/पलै 23, 1944
No. 1726] NEW DELHI, WEDNESDAY, APRIL 13, 2022/CHAITRA 23, 1944
इलक्टे र ॉजनक ूर सप ना प्रोगिकीजगक मलं ालय
अजधसप ना
नई ददल् ली, 13 अप्रलै , 2022
का.आ. 1813(अ).—स पना प्रोगिकीजगक अजधजनयम, 2000 (2000 का 21) क धारा 70 क उप धारा (1) द्वारा
प्रदत् त िजतियय का प्रयीग करते ुएए ूर संपार एंं स पना प्रोगिकीजगक मंलालय म भारत सरकार क अजधस पना के
अजधक्रमण म िी ददनांक 11 ददसंबर, 2015 के िी.एस.आर. 993(अ) जिसे ददनांक 21 ददसंबर, 2015 की भारत के
रािपल, असाधारण, भाग-III, खंड-3, उप-खंड (i) म प्रकाजित दकया गया था, इस प्रकार के अजधक्रमण स े प ं व दकए गए
या छीडे गए कायों के अजतररक्टत क ्र सरकार एत्ारा भारतीय जं जिष ट पहपान प्राजधकरण (य आईडीएआई) क क ्र ीय
पहपान डाटा ररपीजिटरी के कम् ् य टर संसाधन एंं जनम्न जलजखत सवजंधां ूर स पना पररसंपजतियय की उक्टत अजधजनयम
के उद्देश् य से एक संरजषितत प्रणाली घीजषत करती ह ै नामत :-
(1) ब गलरुव हबे ल डाटा क ्र (एपडीसी)।
(2) सवरषिता संपालन क ्र , एपडीसी ।
(3) नेटंकव संपालन क ्र , एपडीसी ।
(4) मानेसर डेटा क ्र (एमडीसी)।
(5) सवरषिता संपालन क ्र , एमडीसी ।
(6) नेटंकव संपालन क ्र , एमडीसी ।
2672 GI/2022 (1)2 THE GAZETTE OF INDIA : EXTRAORDINARY [PART II—SEC. 3(ii)]
(7) सवरषिता संपालन क ्र , भा.जं.प.प्राजधकरण (मवख्य ालय)।
(8) स पना सवरषिता प्रभाग एंं प्रंतनव वंग, भा.जं.प.प्राजधकरण (मवख्य ालय) ।
(9) साइबर फीर जसक प्रयीगिाला, भा.जं.प.प्राजधकरण (मवख्य ालय) ।
(10) य आईडीएआई म संस्ट् थाजपत सभं ाररक अंसंरपना ूर जनभरव ताएं।
[फ. स.ं 10(13)/2017-ई.िी.-II (ंॉल्य म-I)]
डॉ. राि ्र कवमार, अपर सजपं
MINISTRY OF ELECTRONICS AND INFORMATION TECHNOLOGY
NOTIFICATION
New Delhi, the 13th April, 2022
S.O. 1813(E).—In exercise of the powers conferred by sub-section (1) of section 70 of the
Information Technology Act, 2000 (21 of 2000) and in supersession of the notification of the Government
of India in the Ministry of Communications and Information Technology published in the Gazette of India,
Extraordinary, Part II, Section3, Sub-section (i), vide G.S.R. 993(E), dated the 11th December, 2015, on the
21st December, 2015, except as respects things done or omitted to be done before such supersession, the
Central Government hereby declares the computer resource of the Central Identities Data Repository of the
Unique Identification Authority of India (UIDAI) and its following facilities and information assets to be a
protected system for the purposes of the said Act, namely:-
(1) Bangalore Hebbal Data Centre (HDC);
(2) Security Operations Centre of HDC;
(3) Network Operations Centre of HDC;
(4) Manesar Data Centre (MDC);
(5) Security Operations Centre of MDC;
(6) Network Operations Centre of MDC;
(7) UIDAI Headquarters Security Operations Centre;
(8) Information Security Division and Enforcement Wings of UIDAI Head Quarter;
(9) Cyber Forensic Laboratory at UIDAI Head Quarter
(10) Logistics Infrastructure and Dependencies installed at UIDAI.
[F. No. 10(13)/2017-EG-II (Vol-I)]
Dr. RAJENDRA KUMAR, Addl. Secy.
Uploaded by Dte. of Printing at Government of India Press, Ring Road, Mayapuri, New Delhi-110064
and Published by the Controller of Publications, Delhi-110054.