Home India Ministry of Electronics and Information Technology Declaration of computer resources relating identified CII el...
Date: 2022-09-07 Category: Extra Ordinary State: Union Government Country: India

Declaration of computer resources relating identified CII elements of LIC as protected system under sub section 1 of Section 70 of IT act 2000

Issued by Ministry of Electronics and Information Technology · Not Applicable

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task

Executive Summary & Key Takeaways

## Report on Declaration of Critical Information Infrastructure for Life Insurance Corporation of India **1. Executive Summary:** This report analyzes a notification issued by the Ministry of Electronics and Information Technology (MeitY), Government of India, declaring specific computer resources of the Life Insurance Corporation of India (LIC) as Critical Information Infrastructure (CII) under Section 70 of the Information Technology Act, 2000. The notification designates the Electronic Front End Application Program, Business Application, Enterprise Document Management System, and Digitisation of Documents Application, along with their associated dependencies, as protected systems. It also authorizes specific personnel to access these protected systems. The primary purpose is to safeguard LIC's vital IT assets from unauthorized access and potential cyber threats, thereby ensuring the continuity of its services. **2. Introduction:** This report aims to provide a comprehensive overview of a notification published in the Gazette of India on September 7, 2022, by the Ministry of Electronics and Information Technology (MeitY). The notification pertains to the declaration of specific computer resources of the Life Insurance Corporation of India (LIC) as Critical Information Infrastructure (CII) under the Information Technology Act, 2000. The analysis is based solely on the information contained within the provided text. **3. Policy Overview:** * This is a *new* policy declaration. * **Core Objective(s):** Based on the text, the primary objective is to protect the computer resources relating to the Electronic Front End Application Program, Business Application and Enterprise Document Management System Digitisation of Documents Application of the Life Insurance Corporation of India (LIC), including associated dependencies, by designating them as Critical Information Infrastructure (CII) under Section 70 of the Information Technology Act, 2000. The policy also aims to control access to these protected systems by authorizing specific individuals and groups. **4. Background and Rationale:** The policy likely addresses the growing threat of cyberattacks targeting critical infrastructure, including financial institutions. By declaring specific LIC computer resources as CII, the government aims to enhance their security posture and prevent disruptions to essential services provided by LIC. The designation reflects a proactive approach to cybersecurity in the face of increasing digital threats to the insurance sector. **5. Key Provisions / Changes:** * The notification declares the computer resources related to the following LIC systems as protected systems: * Electronic Front End Application Program * Business Application * Enterprise Document Management System * Digitisation of Documents Application * Associated dependencies of the above. * The notification authorizes the following personnel to access the protected systems: * Any designated employee of LIC authorized in writing by LIC. * Any team member of contractual managed service providers or third-party vendors authorized in writing by LIC for need-based access. * Any consultant, regulator, Government official, auditor, and stakeholder authorized in writing by LIC on a case-to-case basis. **6. Target Audience and Stakeholders:** The primary target audience and stakeholders are: * The Life Insurance Corporation of India (LIC) and its employees. * Contractual managed service providers and third-party vendors working with LIC. * Consultants, regulators, government officials, auditors, and other stakeholders who require access to LIC's computer systems. * The Ministry of Electronics and Information Technology (MeitY). **7. Implementation Aspects (Inferred):** * **Responsible agency/bodies:** The Ministry of Electronics and Information Technology (MeitY) is the issuing authority. LIC is responsible for implementing the access control measures outlined in the notification. * **Timelines or procedures:** The notification is effective from the date of its publication in the Gazette of India (September 7, 2022). The procedures for authorizing access to the protected systems are to be determined and implemented by LIC. * The phrase "authorised in writing by the Life Insurance Corporation of India" suggests that LIC will need to create internal procedures for authorizing access to the protected systems. This likely involves documenting the authorization process and maintaining records of authorized personnel. **8. Expected Outcomes / Impact of Changes:** The expected outcomes and impact of this policy are: * Enhanced security of LIC's critical computer resources. * Reduced risk of cyberattacks and data breaches. * Improved business continuity for LIC's operations. * Increased confidence among policyholders and stakeholders in LIC's ability to protect sensitive information. * Greater regulatory oversight and accountability for LIC's cybersecurity practices. **9. Conclusion:** The declaration of specific LIC computer resources as Critical Information Infrastructure is a significant step towards strengthening the cybersecurity posture of a vital financial institution. By implementing the access control measures outlined in the notification, LIC can better protect its systems from unauthorized access and potential disruptions. This policy underscores the government's commitment to safeguarding critical infrastructure and ensuring the stability of the Indian financial sector.

Key Entities Referenced

Information Technology Act, 2000: A law that provides legal recognition for transactions carried out through electronic means and also deals with cybercrime and data protection. Central Government: The governing body of India. Electronic Front End Application Program: A computer resource related to the Life Insurance Corporation of India. Business Application: A computer resource related to the Life Insurance Corporation of India. Enterprise Document Management System: A computer resource related to the Life Insurance Corporation of India. Digitisation of Documents Application: A computer resource related to the Life Insurance Corporation of India. Life Insurance Corporation of India: An Indian statutory insurance and investment corporation. Dr. RAJENDRA KUMAR: Additional Secretary. Ministry of Electronics and Information Technology: A ministry of the Indian government.
Official Source Record View Original Source →
See Full Document Text
रजिस्ट्री स.ं डी.एल.- 33004/99 REGD. No. D. L.-33004/99 सी.जी.-डी.एल.-अ.-07092022-238639 xxxGIDHxxx CG-DL-E-07092022-238639 xxxGIDExxx असाधारण EXTRAORDINARY भाग II—खण् ड 3—उप-खण्ड (ii) PART II—Section 3—Sub-section (ii) प्राजधकार स ेप्रकाजित PUBLISHED BY AUTHORITY स.ं 3985] िई दिल्ली, बुधवार, जसतम्ब र 7, 2022/भाद्र 16, 1944 No. 3985] NEW DELHI, WEDNESDAY, SEPTEMBER 7, 2022/BHADRA 16, 1944 इलक्‍टे र ॉजिकी और सचू िा प्रौद्योजगकी मत्रं ालय अजधसचू िा िई दिल्ली, 29 vxLr, 2022 का.आ. 4166(अ)—केंद्रीय सरकार, सूचिा प्रौद्योजगकी अजधजियम, 2000 (2000 का 21) की धारा 70 द्वारा प्रित् त िजियों का प्रयोग करत े हुए, भारतीय िीवि बीमा जिगम और इसके सहयुक्‍टत अजितताओं के कंप् यटू र संसाधिों को क्ांजतक सूचिा अवसंरचिा होिे के िात े इलेक्‍टरॉजिक फ्रंट एडं एप् लीकेिि प्रोग्राम जबििेस एप् लीकेिि और एंटरप्राइज़ िस्ट् तावेि प्रबंधि प्रणाली, िस्ट्त ावेि आवेिि के जडजिटलीकरण स े संबंजधत कंप् यटू र संसाधिों को, उक्‍टत अजधजियम के प्रयोिि के जलए संरजित प्रणाली घोजित करती ह ै और जिम्ि जलजखत कार्मिकों को संरजित प्रणाजलयों तक पहुचं बिािे के जलए प्राजधकृत करती ह,ै अर्ाित:् - (क) सरं जित प्रणाजलयों तक पहुचं बिािे के जलए, भारतीय िीवि बीमा जिगम द्वारा जलजखत रूप म ें प्राजधकृत भारतीय िीवि बीमा जिगम का कोई अजभजहत कमिचारी; (ख) संजविात् मक प्रबंजधत सेवा-प्रिाता के िल का कोई सिस्ट्य या तृतीय पिकार जवक्ेता जिसे आवश् यकता के आधार पर पहुचं बिािे के जलए भारतीय िीवि बीमा जिगम द्वारा जलजखत रूप म ें प्राजधकृत दकया गया ह;ै और (ग) मामला िर मामला के आधार पर, भारतीय िीवि बीमा जिगम द्वारा जलजखत रूप म ें प्राजधकृत कोई परामिी, जवजियामक, सरकारी पिाजधकारी, संपरीिक और पणधारी । [फा. सं. 2(5)/2022-सीएल] डॉ. रािेन्द्द्र कुमार, अपर सजचव 5974 GI/2022 (1)2 THE GAZETTE OF INDIA : EXTRAORDINARY [PART II—SEC. 3(ii)] MINISTRY OF ELECTRONICS AND INFORMATION TECHNOLOGY NOTIFICATION New Delhi, the 29th August, 2022 S.O. 4166 (E).—In exercise of the powers conferred by section 70 of the Information Technology Act, 2000 (21 of 2000), the Central Government hereby declares the computer resources relating to the Electronic Front End Application Program Business Application and Enterprise Document Management System Digitisation of Documents Application, being Critical Information Infrastructure of the Life Insurance Corporation of India, and the computer resources of its associated dependencies to be protected systems for the purpose of the said Act and authorises the following personnel to access the protected systems, namely:- (a) any designated employee of the Life Insurance Corporation of India authorised in writing by the Life Insurance Corporation of India to access the protected system; (b) any team member of contractual managed service provider or third-party vendor who have been authorised in writing by the Life Insurance Corporation of India for need-based access; and (c) any consultant, regulator, Government official, auditor and stakeholder authorised in writing by the Life Insurance Corporation of India on case to case basis. [F. No. 2(5)/2022-CL] Dr. RAJENDRA KUMAR, Addl. Secy. Uploaded by Dte. of Printing at Government of India Press, Ring Road, Mayapuri, New Delhi-110064 and Published by the Controller of Publications, Delhi-110054.

Continue your research