Home India Ministry of Electronics and Information Technology Notification issued under Section 70 of IT ACT...
Date: 2022-06-17 Category: Extra Ordinary State: Union Government Country: India

Notification issued under Section 70 of IT ACT

Issued by Ministry of Electronics and Information Technology · Not Applicable

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task

Executive Summary & Key Takeaways

## Report on Notification Regarding Critical Information Infrastructure Protection for HDFC Bank **1. Executive Summary:** This report analyzes a notification issued by the Ministry of Electronics and Information Technology, Government of India, dated June 16, 2022. The notification declares specific computer resources of HDFC Bank, relating to Core Banking Solution, Real Time Gross Settlement, and National Electronic Fund Transfer, as Critical Information Infrastructure. It also authorizes specific personnel to access these protected systems. The core purpose is to enhance the security and resilience of critical banking infrastructure. Key findings include the designation of specific systems as protected and the authorization of access to these systems under controlled conditions. **2. Introduction:** This report provides an overview and analysis of the Ministry of Electronics and Information Technology notification, dated June 16, 2022, concerning the protection of critical information infrastructure related to HDFC Bank. The analysis is based solely on the content of the provided text. **3. Policy Overview:** * This is a new policy declaration, not an amendment. * **Core Objective(s):** Based on the text, the core objective is to protect the computer resources related to HDFC Bank's Core Banking Solution, Real Time Gross Settlement (RTGS), and National Electronic Fund Transfer (NEFT) systems, including the Structured Financial Messaging Server, by designating them as Critical Information Infrastructure. This implies a focus on ensuring the security and uninterrupted operation of these systems. **4. Background and Rationale:** The policy addresses the potential vulnerability of critical banking systems to cyber threats or other disruptions. By designating these systems as Critical Information Infrastructure, the government aims to enhance their protection against potential attacks that could destabilize the financial system. The Information Technology Act, 2000, provides the legal framework for this action, suggesting a pre-existing concern about the security of such infrastructure. **5. Key Provisions / Changes:** As this is a new policy declaration, the key provisions are as follows: * **Designation of Critical Information Infrastructure:** The computer resources pertaining to HDFC Bank's Core Banking Solution, Real Time Gross Settlement, and National Electronic Fund Transfer, including the Structured Financial Messaging Server, are officially declared as Critical Information Infrastructure. * **Protected Systems:** These designated computer resources and their associated dependencies are classified as "protected systems" under the Information Technology Act, 2000. * **Authorized Personnel:** The notification authorizes specific categories of personnel to access these protected systems: * Any designated employee authorized by HDFC Bank. * Authorized team members of contractual managed service providers or third-party vendors who have been authorized by HDFC Bank for need-based access. * Consultants, regulators, government officials, auditors, and stakeholders authorized by HDFC Bank on a case-by-case basis. **6. Target Audience and Stakeholders:** The directly affected stakeholders include: * **HDFC Bank:** As the owner of the critical infrastructure, HDFC Bank is directly responsible for implementing the security measures and managing access to the protected systems. * **Employees of HDFC Bank:** Designated employees require authorization protocols to access the protected systems. * **Managed Service Providers and Third-Party Vendors:** These entities, if contractually involved with HDFC Bank, will need authorization processes for their team members to access the protected systems. * **Regulators, Government Officials, Auditors:** These individuals require authorization by HDFC bank on a case-by-case basis for access. **7. Implementation Aspects (Inferred):** * **Responsible Agency:** The Ministry of Electronics and Information Technology (MeitY) is the responsible agency, as indicated by the notification's origin. HDFC Bank is responsible for implementing the policy's provisions within its organization. * **Timelines:** The notification came into force on the date of its publication in the Official Gazette (June 16, 2022). * **Procedures:** HDFC Bank is expected to establish procedures for authorizing personnel (employees, vendors, consultants, etc.) to access the protected systems. The degree to which this authorization is auditable by the government can not be determined from the text. **8. Expected Outcomes / Impact of Changes:** The likely intended outcomes include: * **Enhanced Security:** Strengthening the security of HDFC Bank's critical banking infrastructure against cyber threats and disruptions. * **Improved Resilience:** Ensuring the continued operation of essential banking services (Core Banking, RTGS, NEFT) even in the face of potential attacks. * **Increased Oversight:** Facilitating regulatory oversight of the bank's security measures by providing a framework for access by regulators and auditors. * **Controlled Access:** Regulating and limiting access to critical systems to only authorized personnel, thereby reducing the risk of insider threats or unauthorized modifications. **9. Conclusion:** The Ministry of Electronics and Information Technology notification designates HDFC Bank's critical banking infrastructure as "protected systems," aiming to enhance its security and resilience. This action underscores the government's commitment to safeguarding the nation's financial infrastructure. The implementation of this policy will require HDFC Bank to establish robust access control mechanisms and adhere to security best practices, contributing to the overall stability of the banking sector.

Key Entities Referenced

Information Technology Act, 2000: A law which empowers the Central Government to declare computer resources as protected systems. Central Government: The governing authority declaring the computer resources as protected systems. Core Banking Solution: A computer resource relating to banking operations that is declared as critical information infrastructure. Real Time Gross Settlement: A computer resource relating to financial transactions that is declared as critical information infrastructure. National Electronic Fund Transfer: A computer resource relating to financial transactions that is declared as critical information infrastructure. Structured Financial Messaging Server: A component of critical information infrastructure related to financial messaging. HDFC Bank: The bank whose computer resources are being declared as protected systems. New Delhi: The location where the notification was issued. It is the capital of India. RAJENDRA KUMAR: Addl. Secy. who signed the notification.
Official Source Record View Original Source →
See Full Document Text
रजिस्ट्री स.ं डी.एल.- 33004/99 REGD. No. D. L.-33004/99 सी.जी.-डी.एल.-अ.-17062022-236680 xxxGIDHxxx CG-DL-E-17062022-236680 xxxGIDExxx असाधारण EXTRAORDINARY भाग II—खण् ड 3—उप-खण्ड (ii) PART II—Section 3—Sub-section (ii) प्राजधकार स ेप्रकाजित PUBLISHED BY AUTHORITY स.ं 2669] नई ददल्ली, िुक्रवार, िनू 17, 2022/ज्य ष्े ठ 27, 1944 No. 2669] NEW DELHI, FRIDAY, JUNE 17, 2022/JYAISHTHA 27, 1944 इलक्ट्ै रॉजनकी और सूचना प्रौद्योजगकी मत्रं ालय अजधसचू ना नई ददल्ली, 16 िून, 2022 का.आ. 2806(अ).—केंद्रीय सरकार, सूचना प्रौद्योजगकी अजधजनयम, 2000 (2000 का 21) की धारा 70 की उपधारा (1) द्वारा प्रदत्त िजियों का प्रयोग करत े हुए, महत्वपूणण बैंककारी समाधान वास्ट्तजवक समय समग्र जनपटान (ररयल टाइम ग्रॉस सेटलमेंट) और राष्ट्रीय इलैक्ट्रोजनकी जनजध अंतरण, जिसमें ढांचागत जवत्तीय संदेि सवणर ह,ै िो एचडीएफसी बैंक की महत्वपूणण सूचना अवसंरचना ह ै और उस पर जनभणर सहबद्धों के कंप्यूटर संसाधनों को उि अजधजनयम के प्रयोिन के जलए संरजित प्रणाजलयां घोजित करती ह ै और संरजित प्रणाजलयों तक पहुचं बनान े के जलए जनम्नजलजखत कार्ममकों को प्राजधकृत करती ह,ै अथाणत:् - (क) एचडीएफसी बैंक द्वारा प्राजधकृत कोई अजभजहत कमणचारी; (ख) संजवदा द्वारा प्रबंध की गई सेवा के प्रदाता के दल का कोई सदस्ट्य या तृतीय पिकार जवक्रेता जिसे आवश्यकता के आधार पर पहुचं बनाने के जलए एचडीएफसी बैंक द्वारा प्राजधकृत दकया गया है; और (ग) मामला दर मामला के आधार पर एचडीएफसी बैंक द्वारा प्राजधकृत कोई सलाहकार, जवजनयामक, सरकारी, कार्ममक, संपरीिक और पणधारी । 2. यह अजधसूचना रािपत्र में उसके प्रकािन की तारीख को प्रवृत्त होगी । [फा. सं. एए-11018/2/2021-सीएल एंड ईएस] डा. रािेन्द्द्र कुमार, अपर सजचव 4134 GI/2022 (1)2 THE GAZETTE OF INDIA : EXTRAORDINARY [PART II—SEC. 3(ii)] MINISTRY OF ELECTRONICS AND INFORMATION TECHNOLOGY NOTIFICATION New Delhi, the 16th June, 2022 S.O. 2806(E).—In exercise of the powers conferred by sub-section (1) of section 70 of the Information Technology Act, 2000 (21 of 2000), the Central Government hereby declares the computer resources relating to the Core Banking Solution, Real Time Gross Settlement and National Electronic Fund Transfer comprising Structured Financial Messaging Server, being Critical Information Infrastructure of the HDFC Bank, and the computer resources of its associated dependencies to be protected systems for the purpose of the said Act and authorises the following personnel to access the protected systems, namely: - (a) any designated employee authorised by the HDFC Bank; (b) any authorised team members of contractual managed service provider or third-party vendor who have been authorised by the HDFC Bank for need-based access; and (c) any consultant, regulator, government official, auditor and stakeholder authorised by the HDFC Bank on case to case basis. 2. This notification shall come into force on the date of its publication in the Official Gazette. [F. No. AA-11018/2/2021-CL&ES] Dr. RAJENDRA KUMAR, Addl. Secy. Uploaded by Dte. of Printing at Government of India Press, Ring Road, Mayapuri, New Delhi-110064 and Published by the Controller of Publications, Delhi-110054.

Continue your research