Home India Ministry of Electronics and Information Technology Notification issued under Section 70 of IT ACT...
Date: 2022-06-17 Category: Extra Ordinary State: Union Government Country: India

Notification issued under Section 70 of IT ACT

Issued by Ministry of Electronics and Information Technology · Not Applicable

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task

Executive Summary & Key Takeaways

## Policy Analysis Report: Declaration of Critical Information Infrastructure for National Payments Corporation of India **1. Executive Summary:** This report analyzes a notification issued by the Ministry of Electronics and Information Technology, Government of India, declaring specific computer resources related to the National Payments Corporation of India (NPCI) as Critical Information Infrastructure (CII) under the Information Technology Act, 2000. This includes Unified Payments Interface (UPI), Immediate Payment Service (IMPS), and National Financial Switch (NFS). The notification also outlines authorized personnel allowed access to these protected systems. The core purpose is to enhance the security and protection of these vital payment systems. **2. Introduction:** This report provides an overview and analysis of a recent notification concerning the protection of computer resources related to the National Payments Corporation of India (NPCI). The analysis is based solely on the provided government policy text. **3. Policy Overview:** * This is a new policy declaration. * **Core Objective(s):** The core objective, as inferred from the text, is to protect the computer resources relating to the Unified Payments Interface, Immediate Payment Service and National Financial Switch, being Critical Information Infrastructure of the National Payments Corporation of India, and the computer resources of its associated dependencies. This is to ensure the security and integrity of India's critical payment infrastructure by designating it as a "protected system" under the Information Technology Act, 2000. **4. Background and Rationale:** As this is a new policy declaration, the likely problem it addresses is the increasing vulnerability of critical digital infrastructure to cyber threats. Given the importance of UPI, IMPS, and NFS to the Indian economy, their disruption could have severe consequences. This policy aims to mitigate those risks by providing a legal framework for their protection and restricting access to authorized personnel. **5. Key Provisions / Changes:** As this is a new policy declaration, the key provision of the policy is the declaration of the computer resources related to UPI, IMPS, and NFS, managed by the NPCI, as Critical Information Infrastructure and designating them as protected systems under the Information Technology Act, 2000. Additionally, the policy defines who is authorized to access the protected systems: * Any designated employee of the National Payments Corporation of India authorized by the National Payments Corporation of India to access the protected system * Any team member of contractual managed service provider or thirdparty vendor who have been authorised by the National Payments Corporation of India for needbased access * Any consultant, regulator, government official, auditor and stakeholder authorized by the National Payments Corporation of India on case to case basis **6. Target Audience and Stakeholders:** The target audience and stakeholders directly affected by this policy include: * The National Payments Corporation of India (NPCI) * Employees of NPCI with designated access to the protected systems * Managed service providers and third-party vendors working with NPCI * Consultants, regulators, government officials, auditors, and stakeholders interacting with NPCI's payment systems * Financial institutions using UPI, IMPS, and NFS. * Ultimately, all users of these payment systems are indirectly affected. **7. Implementation Aspects (Inferred):** * **Responsible agency/bodies:** The Ministry of Electronics and Information Technology (MeitY) is responsible for issuing the notification. The NPCI is responsible for authorizing access to the protected systems and ensuring compliance. * **Timelines or procedures:** The notification comes into force on the date of its publication in the Official Gazette (June 17, 2022). The NPCI needs to establish internal procedures for designating employees and authorizing access for external parties. **8. Expected Outcomes / Impact of Changes:** The likely intended outcomes of this policy are: * Enhanced security and resilience of UPI, IMPS, and NFS against cyberattacks. * Clearer accountability and access control mechanisms for these critical systems. * Increased confidence in the stability and reliability of India's digital payments infrastructure. * Improved regulatory oversight of NPCI's security practices. **9. Conclusion:** The notification declaring computer resources related to UPI, IMPS, and NFS as Critical Information Infrastructure is a significant step towards strengthening the security and stability of India's digital payments ecosystem. By designating these systems as "protected systems" and defining authorized access, the government aims to reduce the risk of disruption and enhance the overall resilience of the financial infrastructure. This policy underscores the growing importance of cybersecurity in the digital age and its impact on the national economy.

Key Entities Referenced

Information Technology Act, 2000: A law enacted by the Parliament of India. Unified Payments Interface: A real-time payment system in India. Immediate Payment Service: An instant real-time payment system in India. National Financial Switch: The largest network of shared automated teller machines (ATMs) in India. National Payments Corporation of India: An umbrella organisation for operating retail payments and settlement systems in India. Critical Information Infrastructure: Computer resources related to Unified Payments Interface, Immediate Payment Service and National Financial Switch belonging to National Payments Corporation of India Ministry of Electronics and Information Technology: A ministry in the Indian government. RAJENDRA KUMAR: Addl. Secy. of Ministry of Electronics and Information Technology
Official Source Record View Original Source →
See Full Document Text
रजिस्ट्री स.ं डी.एल.- 33004/99 REGD. No. D. L.-33004/99 सी.जी.-डी.एल.-अ.-17062022-236682 xxxGIDHxxx CG-DL-E-17062022-236682 xxxGIDExxx असाधारण EXTRAORDINARY भाग II—खण् ड 3—उप-खण्ड (ii) PART II—Section 3—Sub-section (ii) प्राजधकार स ेप्रकाजित PUBLISHED BY AUTHORITY स.ं 2670] नई ददल्ली, िुक्रवार, िनू 17, 2022/ज्य ष्े ठ 27, 1944 No. 2670] NEW DELHI, FRIDAY, JUNE 17, 2022/JYAISHTHA 27, 1944 इलक्ट्ै रॉजनकी और सूचना प्रौद्योजगकी मत्रं ालय अजधसचू ना नई ददल्ली, 16 िून, 2022 का.आ. 2807(अ).—केंद्रीय सरकार, सूचना प्रौद्योजगकी अजधजनयम, 2000 (2000 का 21) की धारा 70 की उपधारा (1) द्वारा प्रदत्त िजियों का प्रयोग करत े हुए, भारतीय राष्ट्रीय भुगतान जनगम और उस पर जनभरभ सहबद्धों के कंप्यूटर संसाधनों को महत्वपूण भ सूचना अवसंरचना होन े के नाते एकीकृत भुगतान इंटरफेस, तरु ंत भगु तान सेवा और राष्ट्रीय जवत्तीय जस्ट्वच स े संबंजधत कंप्यटू र संसाधनों को उि अजधजनयम के प्रयोिनों के जलए संरजित प्रणाजलयां घोजित करती ह ै और जनम्नजलजखत कार्ममकों को संरजित प्रणाजलयों तक पहुचं बनाने के जलए प्राजधकृत करती ह,ै अथाभत्:- (क) भारतीय राष्ट्रीय भुगतान जनगम द्वारा सरं जित प्रणाली तक पहुचं बनान े के जलए, भारतीय राष्ट्रीय भगु तान जनगम द्वारा प्राजधकृत कोई अजभजहत कमभचारी; (ख) संजवदा द्वारा प्रबंध की गई सेवा-प्रदाता के दल का कोई सदस्ट्य या तृतीय पिकार जवक्रेता जिस े आवश्यकता के आधार पर पहुचं बनान े के जलए भारतीय राष्ट्रीय भुगतान जनगम द्वारा प्राजधकृत दकया गया ह;ै और (ग) मामला दर मामला के आधार पर भारतीय राष्ट्रीय भगु तान जनगम द्वारा प्राजधकृत कोई परामिी, जवजनयामक, सरकारी कार्ममक, संपरीिक और पणधारी । 2. यह अजधसूचना रािपत्र म ें उसके प्रकािन की तारीख को प्रवृत्त होगी । [फा. स.ं एए-11018/2/2021-सीएल एंड ईएस] डा. रािेन्द्द्र कुमार, अपर सजचव 4135 GI/2022 (1)2 THE GAZETTE OF INDIA : EXTRAORDINARY [PART II—SEC. 3(ii)] MINISTRY OF ELECTRONICS AND INFORMATION TECHNOLOGY NOTIFICATION New Delhi, the 16th June, 2022 S.O. 2807(E).—In exercise of the powers conferred by sub-section (1) of section 70 of the Information Technology Act, 2000 (21 of 2000), the Central Government hereby declares the computer resources relating to the Unified Payments Interface, Immediate Payment Service and National Financial Switch, being Critical Information Infrastructure of the National Payments Corporation of India, and the computer resources of its associated dependencies to be protected systems for the purpose of the said Act and authorises the following personnel to access the protected systems, namely: - (a) any designated employee of the National Payments Corporation of India authorised by the National Payments Corporation of India to access the protected system; (b) any team member of contractual managed service provider or third-party vendor who have been authorised by the National Payments Corporation of India for need-based access; and (c) any consultant, regulator, government official, auditor and stakeholder authorised by the National Payments Corporation of India on case to case basis. 2. This notification shall come into force on the date of its publication in the Official Gazette. [F. No. AA-11018/2/2021-CL&ES] Dr. RAJENDRA KUMAR, Addl. Secy. Uploaded by Dte. of Printing at Government of India Press, Ring Road, Mayapuri, New Delhi-110064 and Published by the Controller of Publications, Delhi-110054.

Continue your research