ExamShortcut

Cyber Security

🔒 Log in to track
high importance⚡ 9 shortcuts4 subtopics

IT Act 2000, offences and authorities

🔒 Log in to track

The Information Technology Act, 2000 is India's cyber-law framework - passed in 2000, in force from 17 October 2000, based on the UNCITRAL model law on e-commerce, and amended in 2008 (adding 66C, 66D, 66F etc.).

SectionOffence
Sec 43Penalty (up to Rs. 1 crore) for unauthorised access/damage to computer, data, virus injection
Sec 65Tampering with computer source documents - up to 3 years
Sec 66Computer-related offences (dishonesty/franchise of Sec 43 acts)
Sec 66CIdentity theft - up to 3 years + fine
Sec 66DCheating by personation using a computer (online fraud) - up to 3 years
Sec 66EViolation of privacy (publishing private images) - up to 3 years
Sec 66FCyber terrorism - may extend to life imprisonment
Sec 67Publishing/transmitting obscene material electronically (first conviction up to 3 years + Rs. 5 lakh fine)
Sec 72Breach of confidentiality and privacy by a empowered body

Note: Sec 66A (punishing 'offensive messages') was struck down by the Supreme Court in Shreya Singhal v. Union of India (2015) as unconstitutional.

Authorities/portals: CERT-In (Indian Computer Emergency Response Team, 2004, under MeitY) - the national incident-response and warning body; NCIIPC protects critical information infrastructure; cybercrime.gov.in is the national reporting portal and 1930 the cyber-fraud helpline (freezing defrauded money quickly).

Detailed notes

The Information Technology Act, 2000

India's law for the electronic world is the IT Act, 2000, in force from 17 October 2000. It grew out of the UNCITRAL model law (United Nations Commission on International Trade Law) on electronic commerce, which recommended that countries give legal recognition to electronic records and signatures. The Act legalised electronic records and digital signatures and created punishments for computer crimes. It was amended in 2008 (effective 2009), adding identity theft, cyber-terrorism provisions and the CERT-In mandate.

Sections the exams keep asking

SectionSubject
Sec 3authentication by digital (electronic) signature
Sec 43penalty/compensation for unauthorised access and damage to computer, data (hacking-type harm)
Sec 65tampering with computer source code
Sec 66computer-related offences — the "hacking" section (dishonest intent)
Sec 66Cidentity theft (fraudulent use of password/digital signature/biometric)
Sec 66Dcheating by personation using a computer resource (fake profiles)
Sec 67publishing/transmitting obscene material in electronic form
Sec 72breach of confidentiality and privacy (by those with lawful access to data)

Section 66A (punishment for "offensive messages") was struck down by the Supreme Court in Shreya Singhal v. Union of India (2015) as violative of free speech — a favourite trick option presented as still-valid law.

The watchdogs

  • CERT-In (Indian Computer Emergency Response Team) — the national incident-response agency under MeitY (Ministry of Electronics and IT); set up 2004, statutory backing via Sec 70B after the 2008 amendment.
  • NCIIPC (National Critical Information Infrastructure Protection Centre) — protects critical infrastructure (power, banking, telecom) under Sec 70A.
  • MeitY is the parent ministry for cyber laws and policy; the DPDP Act, 2023 (Digital Personal Data Protection Act) now governs personal-data privacy alongside the IT Act.
  • Reporting: national cyber-crime helpline 1930 and the portal cybercrime.gov.in.

Digital signature in one line

A digital signature (Sec 3) is the electronic equivalent of a handwritten signature: created with the signer's private key and verified by anyone with the public key (Certificate Authorities issue the keys). It proves who signed and that the document was not altered — authentication plus integrity.

Quick revision

  • IT Act 2000, effective 17 Oct 2000, based on UNCITRAL; amended 2008.
  • 65 = source code; 66 = hacking; 66C = identity theft; 66D = online cheating; 67 = obscenity; 43 = unauthorised access penalty; 66A struck down 2015.
  • CERT-In = incident response under MeitY; NCIIPC = critical infrastructure; helpline 1930.
  • Digital signature = private key signs, public key verifies (Sec 3).

Types of questions asked

Every way this subtopic shows up in exams — how to recognise it, the formula or logic to use, and a solved example.

Type 1: IT Act basics (year, origin, amendment)very common3 practice Q
How to spot it:

'The IT Act was passed in ___', 'in force from 17 October 2000', 'based on which UN model law', 'the 2008 amendment'.

  1. IT Act 2000, in force 17 October 2000 — India's cyber law.
  2. Based on the UNCITRAL model law on e-commerce (UN Commission on International Trade Law).
  3. Amended 2008 (effective 2009) — added identity theft (66C/66D), cyber-terrorism (66F), CERT-In backing.

Example: India's Information Technology Act came into force on:

17 October 2000 — based on the UNCITRAL model law; amended in 2008.

Type 2: Section-to-offence matchingvery common4 practice Q
How to spot it:

'Section 66 deals with ___', 'identity theft is which section', 'which section was struck down' — 43/65/66/66C/66D/67/72 and 66A.

  1. 43 unauthorised access/damage penalty; 65 source-code tampering; 66 hacking (computer-related offences).
  2. 66C identity theft; 66D cheating by personation; 67 obscene material; 72 breach of privacy.
  3. 66A (offensive messages) was STRUCK DOWN in 2015 — Shreya Singhal case. Any option using 66A as live law is wrong.

Example: Under which section of the IT Act is identity theft punished?

Section 66C — fraudulent use of another's password, digital signature or biometric.

Type 3: Authorities: CERT-In, NCIIPC, MeitY, helplinecommon3 practice Q
How to spot it:

'CERT-In stands for / works under ___', 'critical infrastructure is protected by ___', 'the cyber-fraud helpline number'.

  1. CERT-In (Indian Computer Emergency Response Team) = national incident-response agency, under MeitY.
  2. NCIIPC protects critical information infrastructure (power, banking, telecom).
  3. Report fraud on 1930 or cybercrime.gov.in; personal-data privacy now also under the DPDP Act 2023.

Example: CERT-In, India's cyber incident response agency, functions under which ministry?

MeitY — Ministry of Electronics and Information Technology.

Type 4: Digital signature and e-record legalityoccasional3 practice Q
How to spot it:

'A digital signature is used for ___', 'which section gives digital signatures legal status', authentication/integrity statements.

  1. Digital signature (Sec 3) = electronic equivalent of a handwritten signature.
  2. It proves who signed (authentication) and that the document was not altered (integrity) — not secrecy.
  3. Signed with the signer's private key, verified with the public key; Certificate Authorities issue the credentials.

Example: A digital signature primarily guarantees:

Authenticity of the sender and integrity of the document — the file cannot be altered unnoticed; it is not encryption for secrecy.

Shortcut tricks

⚡ Section story-line

43 = damage fine, 65 = source code, 66 = computer crime, 66C = identity (C for Credential theft), 66D = cheating by personation (D for Donning a false identity), 66F = terrorism (F for Fearsome), 67 = obscene.

Example: Under which IT Act section is identity theft punished?

Section 66C.

⚡ 2000-17-10

IT Act passed and effective in 2000 (in force 17 October 2000), UNCITRAL-based, amended 2008. CERT-In follows in 2004.

Example: The IT Act came into force in the year?

⚡ Helpline 1930

Money lost to online fraud? Dial 1930 fast and report at cybercrime.gov.in - the hotline aims to freeze the siphoned money in the banking chain.

Example: National cybercrime reporting helpline number?

Where students lose marks

  • Saying the IT Act was enacted in 2008 - 2008 is the AMENDMENT; the Act is 2000.

  • Quoting Sec 66A as current law - it was struck down in 2015 (Shreya Singhal case).

  • Mixing CERT-In (incident response, MeitY) with NCIIPC (critical-infrastructure protection).

Practice sets — 16 questions

Sets of 10, mixed across the question types above. Each answer comes with a step-by-step explanation.

Topic test · 10 questions

Suggested time 5 min · wrong answers go to your mistake notebook automatically.