Centre declares ICICI, HDFC, NPCI's IT resources as critical information infrastructure

The MeitY declared the IT resources of ICICI Bank as critical infrastructure under Section 70 of the IT Act, 2000
Last Updated 18 June 2022, 15:13 IST

The government has declared the IT resources of ICICI Bank, HDFC Bank and UPI managing entity NPCI as 'critical information infrastructure', implying any harm to them can have an impact on national security and any unauthorised person accessing these resources may be jailed for up to 10 years, according to an official notification.

The Ministry of Electronics and IT (MeitY), in the notification dated June 16, declared the IT resources of ICICI Bank as critical infrastructure under Section 70 of the IT Act, 2000.

"The central government hereby declares the computer resources relating to the Core Banking Solution, Real Time Gross Settlement and National Electronic Fund Transfer comprising Structured Financial Messaging Server, being critical information infrastructure of the ICICI Bank, and the computer resources of its associated dependencies to be protected systems for the purpose of the said Act," the notification said.

In a similar worded two other notifications, Meity declared IT resources of HDFC bank and UPI managing entity National Payments Corporation of India (NPCI) as critical infrastructure.

The notification authorises access of IT resources of the notified entities by their designated employees, authorised team members of contractual managed service providers or third-party vendors who have been authorised by them for need-based access and any consultant, regulator, government official, auditor and stakeholder authorised by the entities on case-to-case basis.

"Looking at the recent sophisticated cyber attacks, it is high time all the banks and financial institutions get themselves notified as a protected system.

"Similarly, the control system of all the electricity, oil, airports, railways, metros and transport systems are critical infrastructure and must be declared as a protected system," SP, Cyber Crime, Uttar Pradesh Police, and certified cyber expert Triveni Singh said.

As per the Act, 'critical information infrastructure' means a computer resource, the incapacitation or destruction of which, shall have debilitating impact on national security, economy, public health or safety.

Any person who secures access or attempts to secure access to a protected system in contravention of the provisions shall be punished with imprisonment of a term which may extend to 10 years and shall also be liable for a fine, the Act says.

(Published 18 June 2022, 15:05 IST)

Follow us on