Home India Ministry of Home Affairs Declaration of Census, NPR and CRS web portal, mobile applic...
Date: 2022-11-07 Category: Extra Ordinary State: Union Government Country: India

Declaration of Census, NPR and CRS web portal, mobile applications, databases and computer resources of the Office of the Registrar General and Census Commissioner, India as Protected Systems under Information Technology Act, 2000 being Critical Information Infrastructure (CII)

Issued by Ministry of Home Affairs · Office of the Registrar General, India

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task

Executive Summary & Key Takeaways

## Report on Declaration of Critical Information Infrastructure for Census and Related Systems **1. Executive Summary:** This report analyzes a notification from the Ministry of Home Affairs, Government of India, declaring specific computer resources related to Census, Civil Registration, and Population Register systems as Critical Information Infrastructure (CII). This declaration, made under the Information Technology Act, 2000, aims to protect these systems from unauthorized access, modification, use, disclosure, disruption, destruction, or denial of service, ensuring the integrity and availability of vital citizen data. The key finding is that the government is prioritizing the security and reliability of these essential data collection and management systems. **2. Introduction:** This report provides an overview and analysis of a notification (S.O. 5168E) issued by the Ministry of Home Affairs, Office of the Registrar General and Census Commissioner, India, concerning the designation of computer resources as Critical Information Infrastructure (CII). The analysis is based solely on the content of the provided notification text. **3. Policy Overview:** * This is a *new* policy declaration. * **Core Objective(s):** The primary objective is to declare specific computer resources as Critical Information Infrastructure (CII) under Section 70 of the Information Technology Act, 2000. This implies an objective to enhance the security and protection of these systems. The inferred objective is to safeguard sensitive citizen data and ensure the continuous operation of census, registration, and population management processes. **4. Background and Rationale:** As a new policy declaration, this likely addresses the growing threat landscape and the increasing reliance on digital infrastructure for critical government functions. The policy likely addresses the need to safeguard essential systems and data from cyberattacks or other disruptions, given that Census, Civil Registration, and Population Register systems hold highly sensitive citizen information and their disruption could have severe consequences. This is further supported by the mention of a Disaster Recovery Site (DRS), indicating a concern for business continuity and data resilience. **5. Key Provisions / Changes:** This is a new policy declaration, and therefore the following are the key provisions based on the text: * **Designation of CII:** The notification explicitly declares the following computer resources as Critical Information Infrastructure (CII): * Census Monitoring Management System (CMMS) Web Portal * Self Enumeration (SE) Web Portal * Civil Registration System (CRS) Web Portal * Mobile applications for House Listing (HL), Population Enumeration (PE) and National Population Register (NPR) Updation * Linked Databases (NPR Database, Census Database, and CRS Database) * Computer resources setup/installed at National Data Centre (NDC), ORGI, Delhi and Disaster Recovery Site (DRS) Data Centre (DC) at Bengaluru and Lucknow * **Protected Systems Status:** The computer resources and associated dependencies are declared to be Protected Systems for the purposes of the Information Technology Act, 2000. This gives the government legal authority to take measures to protect these systems. * **Enforcement Date:** The notification comes into force on the date of its publication in the Official Gazette (November 7, 2022). **6. Target Audience and Stakeholders:** The primary target audience includes: * **Office of the Registrar General and Census Commissioner, India (ORGI):** As the owner and operator of the declared CII, the ORGI is directly responsible for implementing and adhering to the security provisions related to protected systems. * **National Data Centre (NDC), ORGI, Delhi and Disaster Recovery Site (DRS) Data Centre (DC) at Bengaluru and Lucknow:** The operators and administrators of these data centers are responsible for implementing and maintaining the security measures required for CII protection. * **Information Security Professionals:** Those responsible for securing the Census, Civil Registration and NPR infrastructure. Indirectly, all citizens are stakeholders as the policy aims to protect their data and ensure the continuity of essential government services. **7. Implementation Aspects (Inferred):** * **Responsible Agency/Bodies:** The Office of the Registrar General and Census Commissioner, India (ORGI), and the National Critical Information Infrastructure Protection Centre (NCIIPC) are likely responsible for implementing and overseeing the protection of the declared CII. The Joint Secretary (ASHISH KUMAR) is the signing authority, indicating high-level oversight. * **Timelines or Procedures:** The notification takes effect immediately upon publication in the Official Gazette. No specific procedures are outlined in the text, but it can be inferred that the ORGI and NCIIPC will need to develop and implement security protocols and measures to comply with the IT Act, 2000. **8. Expected Outcomes / Impact of Changes:** The intended outcomes of this policy declaration include: * **Enhanced Security:** Increased protection against cyber threats and unauthorized access to sensitive citizen data. * **Improved Resilience:** Ensuring the continuous operation of Census, Civil Registration, and Population Register systems, even in the face of disruptions. * **Legal Framework:** Establishing a clear legal framework for protecting these critical systems, enabling the government to take necessary actions to mitigate risks. * **Increased confidence:** Increased citizen confidence in the protection and integrity of their data held by the government. **9. Conclusion:** The notification declaring specific computer resources related to Census, Civil Registration, and Population Register systems as Critical Information Infrastructure represents a significant step towards enhancing the security and resilience of vital citizen data and government services. By designating these systems as protected under the Information Technology Act, 2000, the government aims to safeguard against cyber threats and ensure the continued availability of these essential services. This policy underscores the importance of data protection and cybersecurity in the digital age, particularly for systems that manage sensitive citizen information. The ORGI and related stakeholders must prioritize implementing robust security measures to effectively protect these critical assets.

Key Entities Referenced

Information Technology Act, 2000: A law regarding information technology, specifically section 70, subsection 1. Census Monitoring Management System CMMS Web Portal: A computer resource related to census monitoring and management. Self Enumeration SE Web Portal: A computer resource related to self enumeration. Civil Registration System CRS Web Portal: A computer resource related to civil registration. Mobile applications for House Listing HL: A mobile application used for house listing during census or surveys. Population Enumeration PE: A process of enumeration of the population. National Population Register NPR Updation: The process of updating the National Population Register. NPR Database: Database of the National Population Register. Census Database: A database containing census information. CRS Database: A database containing civil registration system information. National Data Centre NDC, ORGI, Delhi: A data center located in Delhi, part of the Office of the Registrar General of India (ORGI). Disaster Recovery Site DRS Data Centre DC at Bengaluru, Karnataka: A disaster recovery site data center located in Bengaluru, Karnataka. Disaster Recovery Site DRS Data Centre DC at Lucknow, Uttar Pradesh: A disaster recovery site data center located in Lucknow, Uttar Pradesh. Critical Information Infrastructure CII: Designation given to the computer resources, classifying them as critical infrastructure. Office of the Registrar General Census Commissioner, India: The government office responsible for census and registration. ASHISH KUMAR: Joint Secretary, signatory of the notification. Ministry of Home Affairs: The ministry under which the Office of the Registrar General and Census Commissioner, India operates. New Delhi: Location of notification by Ministry of Home Affairs.
Official Source Record View Original Source →
See Full Document Text
रजिस्ट्री स.ं डी.एल.- 33004/99 REGD. No. D. L.-33004/99 सी.जी.-डी.एल.-अ.-07112022-240088 xxxGIDHxxx CG-DL-E-07112022-240088 xxxGIDExxx असाधारण EXTRAORDINARY भाग II—खण् ड 3—उप-खण्ड (ii) PART II—Section 3—Sub-section (ii) प्राजधकार स ेप्रकाजित PUBLISHED BY AUTHORITY स.ं 4949] नई दिल्ली, सोमवार, नवम्ब र 7, 2022/कार्तका 16, 1944 No. 4949] NEW DELHI, MONDAY, NOVEMBER 7, 2022/KARTIKA 16, 1944 गहृ मत्रं ालय (भारत के महा रजिस्ट्रार एव ंिनगणना आयक्तु का कायाला य) अजधसचू ना नई दिल् ली, 4 नवम् बर, 2022 का.आ. 5168(अ).—सूचना प्रौद्योजगकी अजधजनयम, 2000 (संिोजधत 2008) की धारा 70 की उप-धारा (1) द्वारा प्रित्त िजक्तयों का प्रयोग करत े हुए, केन्द्र सरकार एतद्द्वारा घोषणा करती ह ै दक िनगणना जनगरानी और प्रबधं न प्रणाली (सीएमएमएस) वबे पोर्ाल, स्ट्वगणना (एसई) वबे पोर्ाल, नागररक पिं ीकरण प्रणाली (सीआरएस) वबे पोर्ाल, और मकान सचू ीकरण (एचएल), िनसख्ं या गणना (पीई) तथा राष्ट्रीय िनसख्ं या रजिस्ट्र्र (एनपीआर) के अद्यतन स े सबं जं धत मोबाइल एजललकेिन, और एनपीआर डेर्ाबसे , िनगणना डेर्ाबेस तथा सीआरएस डेर्ाबसे सजहत िडु े (linked) डेर्ाबसे , और राष्ट्रीय डेर्ा केन्द्र (एनडीसी), ओआरिीआई, दिल्ली और आपिा ररकवरी साइर् (डीआरएस) एव ं डेर्ा केन्द्र (डीसी), बगें लरुु और लखनऊ म ें व्यवजस्ट्थत/ स्ट्थाजपत कंलयर्ू र ससं ाधन, भारत के महा रजिस्ट्रार एव ं िनगणना आयक्तु के कायाालय के महत्वपूण ा सूचना अवसंरचना (सीआईआई) ह ैं और उनकी संबद्ध जनभारता के कंलयूर्र संसाधन उक्त अजधजनयम के प्रयोिनों के जलए 'सरं जित प्रणाली' ह ैं । 2. यह अजधसूचना रािपत्र म ेंइसके प्रकािन की जतजथ स े प्रभावी होगी । [फा. स.ं 35314/2/2021-डीपीडी (एनसीआईआईपीसी)] आिीष कुमार, संयक्ु त सजचव 7370 GI/2022 (1)2 THE GAZETTE OF INDIA : EXTRAORDINARY [PART II—SEC. 3(ii)] MINISTRY OF HOME AFFAIRS (Office of the Registrar General and Census Commissioner, India) NOTIFICATION New Delhi, the 4th November, 2022 S.O. 5168(E).—In exercise of the powers conferred by sub-section (1) of section 70 of the Information Technology Act, 2000 (amended 2008), the Central Government hereby declares the computer resources relating to the Census Monitoring & Management System (CMMS) Web Portal, Self Enumeration (SE) Web Portal, Civil Registration System (CRS) Web Portal, Mobile applications for House Listing (HL), Population Enumeration (PE) and National Population Register (NPR) Updation, and linked Databases including NPR Database, Census Database and CRS Database, computer resources setup/installed at National Data Centre (NDC), ORGI, Delhi and Disaster Recovery Site (DRS) & Data Centre (DC) at Bengaluru and Lucknow, being Critical Information Infrastructure (CII) of the Office of the Registrar General & Census Commissioner, India, and the computer resources of their associated dependencies to be ‘Protected Systems’ for the purposes of the said Act. 2. This notification shall come into force on the date of its publication in the Official Gazette. [F. No. 35314/2/2021-DPD (NCIIPC)] ASHISH KUMAR, Jt. Secy. Uploaded by Dte. of Printing at Government of India Press, Ring Road, Mayapuri, New Delhi-110064 and Published by the Controller of Publications, Delhi-110054.

Continue your research