Home India Ministry of Electronics and Information Technology Notification issued under Section 70 of IT ACT...
Date: 2022-06-17 Category: Extra Ordinary State: Union Government Country: India

Notification issued under Section 70 of IT ACT

Issued by Ministry of Electronics and Information Technology · Not Applicable

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task

Executive Summary & Key Takeaways

## Policy Analysis Report: Declaration of Protected Systems for ICICI Bank's Critical Information Infrastructure **1. Executive Summary:** This report analyzes a notification issued by the Ministry of Electronics and Information Technology (MeitY), Government of India, declaring specific computer resources of ICICI Bank as "protected systems" under the Information Technology Act, 2000. The core purpose is to protect the Core Banking Solution, Real Time Gross Settlement, and National Electronic Fund Transfer systems (including the Structured Financial Messaging Server) from unauthorized access, considering them critical information infrastructure. Key findings include the designation of specific personnel authorized to access these protected systems. **2. Introduction:** This report provides an overview and analysis of Notification S.O. 2808(E), issued by the Ministry of Electronics and Information Technology on June 16, 2022. The report aims to inform stakeholders about the policy's objectives, key provisions, and potential implications, based solely on the provided text. **3. Policy Overview:** * This is a new policy declaration, not an amendment. * **Core Objective(s):** The core objective, inferred from the text, is to safeguard critical information infrastructure related to core banking and payment systems of ICICI Bank. This is achieved by declaring specific computer resources as "protected systems" under the Information Technology Act, 2000. **4. Background and Rationale:** As a new policy, this declaration likely addresses the growing need to protect critical banking infrastructure from cyber threats and unauthorized access. The designation of ICICI Bank's Core Banking Solution, Real Time Gross Settlement, and National Electronic Fund Transfer systems suggests a recognition of their importance to the financial stability and economic security of the nation. **5. Key Provisions:** The notification establishes the following key provisions: * **Designation of Protected Systems:** Declares the computer resources relating to the Core Banking Solution, Real Time Gross Settlement, and National Electronic Fund Transfer (including the Structured Financial Messaging Server) of ICICI Bank as "protected systems." It also includes the computer resources of its associated dependencies. * **Authorization of Access:** Authorizes specific categories of personnel to access the protected systems: * Any designated employee authorized by ICICI Bank. * Authorized team members of contractual managed service providers or third-party vendors authorized by ICICI Bank for need-based access. * Consultants, regulators, government officials, auditors, and stakeholders authorized by ICICI Bank on a case-by-case basis. * **Effective Date:** The notification comes into force on the date of its publication in the Official Gazette (June 17, 2022). **6. Target Audience and Stakeholders:** The primary target audience and stakeholders directly affected by this policy include: * ICICI Bank and its employees. * ICICI Bank's contractual managed service providers and third-party vendors. * Consultants, regulators, government officials, auditors, and other stakeholders who may require access to the designated protected systems. * The Reserve Bank of India (RBI) as the regulator of banking systems. **7. Implementation Aspects (Inferred):** * **Responsible Agency/Bodies:** The Ministry of Electronics and Information Technology (MeitY) is the responsible agency for issuing the notification. ICICI Bank is responsible for implementing the authorization controls regarding access to the protected systems. * **Timelines or Procedures:** The notification states that it comes into force on the date of publication in the Official Gazette. It does not specify detailed timelines or procedures for implementation beyond the need for ICICI Bank to authorize access based on the categories outlined in the notification. **8. Expected Outcomes / Impact:** The likely intended outcomes of this policy are: * Enhanced security and protection of ICICI Bank's critical information infrastructure. * Reduced risk of unauthorized access, cyberattacks, and data breaches affecting core banking and payment systems. * Increased confidence in the stability and reliability of ICICI Bank's services. * Compliance with the Information Technology Act, 2000. **9. Conclusion:** The notification declaring ICICI Bank's core banking and payment system infrastructure as "protected systems" is a significant step towards safeguarding critical financial infrastructure. By clearly defining the scope of protection and authorizing specific personnel for access, the policy aims to enhance the security and resilience of ICICI Bank's essential services. This declaration underscores the government's commitment to protecting critical information infrastructure and ensuring the stability of the financial sector.

Key Entities Referenced

NEW DELHI: Capital of India, place of notification. Information Technology Act, 2000: Indian Legislation referenced in the notification. Central Government: The governing body issuing the notification. Core Banking Solution: A computer resource declared as Critical Information Infrastructure. Real Time Gross Settlement: A computer resource declared as Critical Information Infrastructure. National Electronic Fund Transfer: A computer resource declared as Critical Information Infrastructure. Structured Financial Messaging Server: Component of the Critical Information Infrastructure. ICICI Bank: The bank whose computer resources are being declared as protected systems. Dr. RAJENDRA KUMAR: Addl. Secy., signatory of the notification. Official Gazette: The publication where the notification will be published.
Official Source Record View Original Source →
See Full Document Text
रजिस्ट्री स.ं डी.एल.- 33004/99 REGD. No. D. L.-33004/99 सी.जी.-डी.एल.-अ.-17062022-236681 xxxGIDHxxx CG-DL-E-17062022-236681 xxxGIDExxx असाधारण EXTRAORDINARY भाग II—खण् ड 3—उप-खण्ड (ii) PART II—Section 3—Sub-section (ii) प्राजधकार स ेप्रकाजित PUBLISHED BY AUTHORITY स.ं 2671] िई दिल्ली, िुक्रवार, ििू 17, 2022/ज्य ष्े ठ 27, 1944 No. 2671] NEW DELHI, FRIDAY, JUNE 17, 2022/JYAISHTHA 27, 1944 इलैक्ट्रॉजिकी और सचू िा प्रौद्योजगकी मंत्रालय अजधसचू िा िई दिल्ली, 16 िूि, 2022 का.आ. 2808(अ).— केंद्रीय सरकार, सूचिा प्रौद्योजगकी अजधजियम, 2000 (2000 का 21) की धारा 70 की उपधारा (1) द्वारा प्रित्त िजियों का प्रयोग करत े हुए, महत्वपूणण बैंककारी समाधाि वास्ट्तजवक समय समग्र जिपटाि (ररयल टाइम ग्रॉस सेटलमेंट) और राष्ट्रीय इलैक्ट्रोजिकी जिजध अंतरण, जिसमें ढांचागत जवत्तीय संिेि सवणर ह,ै िो आईसीआईसीआई बैंक की महत्वपूणण सूचिा अवसंरचिा ह ै और उस पर जिभणर सहबद्धों के कंप्यूटर संसाधिों को उि अजधजियम के प्रयोिि के जलए संरजित प्रणाजलयां घोजित करती ह ै और संरजित प्रणाजलयों तक पहुचं बिािे के जलए जिम्नजलजखत कार्मणकों को प्राजधकृत करती ह,ै अर्ाणत् :- (क) आईसीआईसीआई बैंक द्वारा प्राजधकृत कोई अजभजहत कमणचारी; (ख) संजविा द्वारा प्रबंध की गई सेवा के प्रिाता के िल का कोई सिस्ट्य या तृतीय पिकार जवक्रेता जिसे आवश्यकता के आधार पर पहुचं बिािे के जलए आईसीआईसीआई बैंक द्वारा प्राजधकृत दकया गया है; और (ग) मामला िर मामला के आधार पर आईसीआईसीआई बैंक द्वारा प्राजधकृत कोई सलाहकार, जवजियामक,सरकारी,कार्मणक,संपरीिक और पणधारी । 4136 GI/2022 (1)2 THE GAZETTE OF INDIA : EXTRAORDINARY [PART II—SEC. 3(ii)] 2. यह अजधसूचिा रािपत्र में उसके प्रकािि की तारीख को प्रवृत्त होगी । [फा. सं. एए-11018/2/2021-सीएल एंड ईएस] डा. रािेन्द्द्र कुमार, अपर सजचव MINISTRY OF ELECTRONICS AND INFORMATION TECHNOLOGY NOTIFICATION New Delhi, the 16th June, 2022 S.O. 2808(E).— In exercise of the powers conferred by sub-section (1) of section 70 of the Information Technology Act, 2000 (21 of 2000), the Central Government hereby declares the computer resources relating to the Core Banking Solution, Real Time Gross Settlement and National Electronic Fund Transfer comprising Structured Financial Messaging Server, being Critical Information Infrastructure of the ICICI Bank, and the computer resources of its associated dependencies to be protected systems for the purpose of the said Act and authorises the following personnel to access the protected systems, namely: - (a) any designated employee authorised by the ICICI Bank; (b) any authorised team members of contractual managed service provider or third-party vendor who have been authorised by the ICICI Bank for need-based access; and (c) any consultant, regulator, government official, auditor and stakeholder authorised by the ICICI Bank on case to case basis. 2. This notification shall come into force on the date of its publication in the Official Gazette. [F. No. AA-11018/2/2021-CL&ES] Dr. RAJENDRA KUMAR, Addl. Secy. Uploaded by Dte. of Printing at Government of India Press, Ring Road, Mayapuri, New Delhi-110064 and Published by the Controller of Publications, Delhi-110054.

Continue your research