Home India Ministry of Electronics and Information Technology Office Memorandum - Delegation of power to Additional secret...
Date: 2023-03-22 Category: Not Applicable State: Union Government Country: India

Office Memorandum - Delegation of power to Additional secretary on behalf of Hon'ble Minister of Electronics and IT to approve notification for declaring any computer resource which directly or indirectly affects the facility of Critical Information Infrastructure

Issued by Ministry of Electronics and Information Technology · Not Applicable

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task

Executive Summary & Key Takeaways

## Report on Delegation of Power Regarding Protection of Critical Information Infrastructure **1. Executive Summary:** This report analyzes a Government of India Office Memorandum (O.M.) dated March 22, 2023, concerning the delegation of power to the Additional Secretary of the Ministry of Electronics and Information Technology (MeitY) to approve notifications for declaring computer resources affecting Critical Information Infrastructure (CII) as protected systems. The memorandum aims to streamline the process of designating and protecting CII by delegating approval authority. The key finding is that this amendment empowers the Additional Secretary, based on recommendations from relevant ministries/departments and evaluation by the National Critical Information Infrastructure Protection Centre (NCIIPC), to expedite the protection of vital digital assets. **2. Introduction:** The purpose of this report is to provide an informative overview of the Office Memorandum No. 252022CL, issued by the Ministry of Electronics and Information Technology on March 22, 2023. This report analyzes the policy as written, focusing on its objectives, key changes, affected stakeholders, and anticipated outcomes based solely on the provided text. This amendment focuses on delegation of power within the MeitY. **3. Policy Overview:** * **Core Objective(s) (Inferred):** The core objective is to delegate authority for approving notifications related to the protection of Critical Information Infrastructure (CII) to the Additional Secretary within MeitY. This is likely intended to improve the efficiency and responsiveness of the process for safeguarding vital computer resources. **4. Background and Rationale:** * **Rationale for Amendment (Inferred):** The amendment suggests a need to expedite the process of declaring computer resources affecting CII as protected systems. Delegating the approval authority to the Additional Secretary likely aims to reduce bureaucratic delays and ensure a more timely response to potential threats or vulnerabilities affecting CII. This delegation of power should streamline and accelerate the process **5. Key Provisions / Changes:** * **Specific Part of Original Policy Being Changed (Inferred):** The original policy likely involved a more cumbersome approval process for declaring computer resources as protected systems, potentially requiring approval from the Minister of Electronics and Information Technology directly. * **New Rule/Provision:** The primary change is the delegation of approval authority to the Additional Secretary in MeitY dealing with Cyber Laws, allowing them to approve notifications for declaring computer resources affecting CII as protected systems. This approval is contingent on recommendations from Central Ministries/Departments and evaluation by the NCIIPC. * **Difference/Effect of Change:** This delegation shifts the approval responsibility from the Minister to the Additional Secretary. This change is expected to reduce the time required to issue notifications, leading to faster protection of CII. The Additional Secretary is now the key decision-maker in this process, provided the recommendations and evaluations are positive. **6. Target Audience and Stakeholders:** The direct target audience and stakeholders include: * **Additional Secretary, MeitY (Cyber Laws):** The primary individual directly impacted by this delegation of power. * **Central Ministries/Departments:** These entities are responsible for providing recommendations for computer resources to be declared as protected systems. * **National Critical Information Infrastructure Protection Centre (NCIIPC):** The NCIIPC plays a crucial role in evaluating the computer resources and providing recommendations to the Additional Secretary. * **The Ministry of Electronics and Information Technology (MeitY) as a whole** benefits from the increased efficiency. * **Indirectly:** Organizations relying on Critical Information Infrastructure (e.g., financial institutions, energy providers, healthcare providers) are affected, as their systems will potentially receive enhanced protection more quickly. **7. Implementation Aspects (Inferred):** * **Responsible Agency/Bodies:** * Ministry of Electronics and Information Technology (MeitY). * National Critical Information Infrastructure Protection Centre (NCIIPC). * Relevant Central Ministries/Departments. * **Timelines/Procedures:** While the exact timelines are not specified, the amendment implies a faster approval process due to the delegation of authority. The procedure involves recommendations from Central Ministries/Departments, evaluation by the NCIIPC, and finally, approval and notification by the Additional Secretary. * **Implementation of Changes:** The change primarily affects the internal workflow within MeitY. The Additional Secretary, along with their office, will need to adapt to the new approval responsibilities. NCIIPC and Central Ministries/Departments must continue to provide timely and thorough assessments. **8. Expected Outcomes / Impact of Changes:** * **Likely Intended Outcome of Changes:** The primary intended outcome is a more efficient and timely process for declaring and protecting computer resources affecting CII. This should lead to enhanced security and resilience of critical infrastructure against cyber threats. This in turn improves protection for organizations using such resources. This delegation of power is expected to reduce bureaucratic bottlenecks and improve responsiveness to emerging threats. **9. Conclusion:** The delegation of power to the Additional Secretary within MeitY for approving notifications regarding the protection of Critical Information Infrastructure represents a strategic administrative adjustment. By streamlining the approval process, the amendment aims to improve the government's ability to safeguard vital computer resources against potential cyber threats. This change is significant for all stakeholders involved in the operation and protection of CII, as it promises a more agile and responsive approach to cybersecurity. This is expected to be an efficiency improvement.

Key Entities Referenced

eF. No. 252022CL: Reference number of the communication. Government of India: The governing body issuing the memorandum. Ministry of Electronics and Information Technology: The ministry responsible for electronics and information technology in India; also referred to as MeitY and Minister EIT. Electronics Niketan, 6, CG0 Complex, Lodhi Road, New Delhi 110 003: Address of the Ministry of Electronics and Information Technology. 22nd March 2023: Date of the Office Memorandum. OFFICE MEMORANDUM: Type of communication. Additional secretary: The position to which power is being delegated. Hon'ble Minister of Electronics and Information Technology: The Minister whose authority is being delegated. computer resource: A resource that is declared as protected if it affects Critical Information Infrastructure. Critical Information Infrastructure: Facility that can be declared as protected system; abbreviated as CII. protected system: A computer resource declared protected by the government. section 70 of the Information Technology Act, 2000: Legal basis for declaring computer resources as protected systems; also referred to as IT Act. Official Gazette: The official publication for government notifications. Cyber Laws: Laws related to cyber matters, dealt with by the Additional Secretary. Central MinistriesDepartments: Ministries and Departments which provide recommendations. National Critical Information Infrastructure Protection Centre: The agency responsible for evaluating recommendations related to CII. 01.03 .2023: Date of approval by the Minister of Electronics and Information Technology. Rckesh Mcheshwari: Name of the Scientist G and Group Coordinator. Scientist G: Designation of Rckesh Mcheshwari. Group Coordinator: Additional designation of Rckesh Mcheshwari. 01124301468: Telephone number of Rckesh Mcheshwari. gccvberlaw,meity. gov.in: Email address related to cyber law at MeitY. MoS EIT: Minister of State for Electronics and Information Technology MeitY website cell: Website cell of Ministry of Electronics and Information Technology IntraMeitY: Internal communication within MeitY
Official Source Record View Original Source →
See Full Document Text
eF. No. 2(5)/2022-CL Government of India Ministry of Electronics and Information Technology Electronics Niketan, 6, CG0 Complex, Lodhi Road, New Delhi -110 003 Dated the 22nd March 2023 OFFICE MEMORANDUM _ _ __ __ _ Subject: Delegation of power to Additional secretary on behalf ofHon'ble Minister of Electronics and Information Technology to approve notification for declaring any computer resource which directly or indirectly affects the facility of Critical Information Infrastructure, to be a protected system - reg. The sub-sections (1 ) and (2) of section 70 of the Information Technology Act, 2000 ("IT Act") empowers the appropriate Government for issuing notification in the Official Gazette, to declare any computer resource which directly or indirectly affects the facility of Critical Information Infrastructure (hereinafter referred to as CII), to be a protected system. Further, the appropriate Government may, by order in writing, authorise the persons who are authorised to access protected systems notified under sub-section (1) of section 70 of the IT Act. 2. In this connection, it has been decided that the Additional Secretary in this Ministry dealing with Cyber Laws related matters is now authorised for according approval to issue such notifications in the Official Gazette for declaring certain computer resources which directly or indirectly affects the facility of CII, to be a protected system, based on the recommendation received from the respective Central Ministries/Departments after the necessary evaluation made by the National Critical Information Infrastructure Protection Centre. 3. This issues with the approval of the Minister of Electronics and Information Technology dated 01.03 .2023 . f?ide.iLue`L --_- (Rckesh Mcheshwari) Scientist G and Group Coordinator Tel.: 011-24301468 Email : gccvberlaw@,meity. gov.in -__ Copy to: 1. Office of Hon'ble Minister (E&IT)/Office of MoS (E&IT) 2. Office of secretary, MeitY 3. Office of Additional secretary, MeitY 4. All Group Coordinators in MeitY 5. Intra-MeitY"eitY website cell

Continue your research