Cyber Security
🔒 Log in to trackIT Act 2000, offences and authorities
🔒 Log in to trackThe Information Technology Act, 2000 is India's cyber-law framework - passed in 2000, in force from 17 October 2000, based on the UNCITRAL model law on e-commerce, and amended in 2008 (adding 66C, 66D, 66F etc.).
| Section | Offence |
|---|---|
| Sec 43 | Penalty (up to Rs. 1 crore) for unauthorised access/damage to computer, data, virus injection |
| Sec 65 | Tampering with computer source documents - up to 3 years |
| Sec 66 | Computer-related offences (dishonesty/franchise of Sec 43 acts) |
| Sec 66C | Identity theft - up to 3 years + fine |
| Sec 66D | Cheating by personation using a computer (online fraud) - up to 3 years |
| Sec 66E | Violation of privacy (publishing private images) - up to 3 years |
| Sec 66F | Cyber terrorism - may extend to life imprisonment |
| Sec 67 | Publishing/transmitting obscene material electronically (first conviction up to 3 years + Rs. 5 lakh fine) |
| Sec 72 | Breach of confidentiality and privacy by a empowered body |
Note: Sec 66A (punishing 'offensive messages') was struck down by the Supreme Court in Shreya Singhal v. Union of India (2015) as unconstitutional.
Authorities/portals: CERT-In (Indian Computer Emergency Response Team, 2004, under MeitY) - the national incident-response and warning body; NCIIPC protects critical information infrastructure; cybercrime.gov.in is the national reporting portal and 1930 the cyber-fraud helpline (freezing defrauded money quickly).
Detailed notes
The Information Technology Act, 2000
India's law for the electronic world is the IT Act, 2000, in force from 17 October 2000. It grew out of the UNCITRAL model law (United Nations Commission on International Trade Law) on electronic commerce, which recommended that countries give legal recognition to electronic records and signatures. The Act legalised electronic records and digital signatures and created punishments for computer crimes. It was amended in 2008 (effective 2009), adding identity theft, cyber-terrorism provisions and the CERT-In mandate.
Sections the exams keep asking
| Section | Subject |
|---|---|
| Sec 3 | authentication by digital (electronic) signature |
| Sec 43 | penalty/compensation for unauthorised access and damage to computer, data (hacking-type harm) |
| Sec 65 | tampering with computer source code |
| Sec 66 | computer-related offences — the "hacking" section (dishonest intent) |
| Sec 66C | identity theft (fraudulent use of password/digital signature/biometric) |
| Sec 66D | cheating by personation using a computer resource (fake profiles) |
| Sec 67 | publishing/transmitting obscene material in electronic form |
| Sec 72 | breach of confidentiality and privacy (by those with lawful access to data) |
Section 66A (punishment for "offensive messages") was struck down by the Supreme Court in Shreya Singhal v. Union of India (2015) as violative of free speech — a favourite trick option presented as still-valid law.
The watchdogs
- CERT-In (Indian Computer Emergency Response Team) — the national incident-response agency under MeitY (Ministry of Electronics and IT); set up 2004, statutory backing via Sec 70B after the 2008 amendment.
- NCIIPC (National Critical Information Infrastructure Protection Centre) — protects critical infrastructure (power, banking, telecom) under Sec 70A.
- MeitY is the parent ministry for cyber laws and policy; the DPDP Act, 2023 (Digital Personal Data Protection Act) now governs personal-data privacy alongside the IT Act.
- Reporting: national cyber-crime helpline 1930 and the portal cybercrime.gov.in.
Digital signature in one line
A digital signature (Sec 3) is the electronic equivalent of a handwritten signature: created with the signer's private key and verified by anyone with the public key (Certificate Authorities issue the keys). It proves who signed and that the document was not altered — authentication plus integrity.
Quick revision
- IT Act 2000, effective 17 Oct 2000, based on UNCITRAL; amended 2008.
- 65 = source code; 66 = hacking; 66C = identity theft; 66D = online cheating; 67 = obscenity; 43 = unauthorised access penalty; 66A struck down 2015.
- CERT-In = incident response under MeitY; NCIIPC = critical infrastructure; helpline 1930.
- Digital signature = private key signs, public key verifies (Sec 3).
Types of questions asked
Every way this subtopic shows up in exams — how to recognise it, the formula or logic to use, and a solved example.
Type 1: IT Act basics (year, origin, amendment)very common3 practice Q
'The IT Act was passed in ___', 'in force from 17 October 2000', 'based on which UN model law', 'the 2008 amendment'.
- IT Act 2000, in force 17 October 2000 — India's cyber law.
- Based on the UNCITRAL model law on e-commerce (UN Commission on International Trade Law).
- Amended 2008 (effective 2009) — added identity theft (66C/66D), cyber-terrorism (66F), CERT-In backing.
Example: India's Information Technology Act came into force on:
17 October 2000 — based on the UNCITRAL model law; amended in 2008.
Type 2: Section-to-offence matchingvery common4 practice Q
'Section 66 deals with ___', 'identity theft is which section', 'which section was struck down' — 43/65/66/66C/66D/67/72 and 66A.
- 43 unauthorised access/damage penalty; 65 source-code tampering; 66 hacking (computer-related offences).
- 66C identity theft; 66D cheating by personation; 67 obscene material; 72 breach of privacy.
- 66A (offensive messages) was STRUCK DOWN in 2015 — Shreya Singhal case. Any option using 66A as live law is wrong.
Example: Under which section of the IT Act is identity theft punished?
Section 66C — fraudulent use of another's password, digital signature or biometric.
Type 3: Authorities: CERT-In, NCIIPC, MeitY, helplinecommon3 practice Q
'CERT-In stands for / works under ___', 'critical infrastructure is protected by ___', 'the cyber-fraud helpline number'.
- CERT-In (Indian Computer Emergency Response Team) = national incident-response agency, under MeitY.
- NCIIPC protects critical information infrastructure (power, banking, telecom).
- Report fraud on 1930 or cybercrime.gov.in; personal-data privacy now also under the DPDP Act 2023.
Example: CERT-In, India's cyber incident response agency, functions under which ministry?
MeitY — Ministry of Electronics and Information Technology.
Type 4: Digital signature and e-record legalityoccasional3 practice Q
'A digital signature is used for ___', 'which section gives digital signatures legal status', authentication/integrity statements.
- Digital signature (Sec 3) = electronic equivalent of a handwritten signature.
- It proves who signed (authentication) and that the document was not altered (integrity) — not secrecy.
- Signed with the signer's private key, verified with the public key; Certificate Authorities issue the credentials.
Example: A digital signature primarily guarantees:
Authenticity of the sender and integrity of the document — the file cannot be altered unnoticed; it is not encryption for secrecy.
Shortcut tricks
⚡ Section story-line
43 = damage fine, 65 = source code, 66 = computer crime, 66C = identity (C for Credential theft), 66D = cheating by personation (D for Donning a false identity), 66F = terrorism (F for Fearsome), 67 = obscene.
Example: Under which IT Act section is identity theft punished?
Section 66C.
⚡ 2000-17-10
IT Act passed and effective in 2000 (in force 17 October 2000), UNCITRAL-based, amended 2008. CERT-In follows in 2004.
Example: The IT Act came into force in the year?
⚡ Helpline 1930
Money lost to online fraud? Dial 1930 fast and report at cybercrime.gov.in - the hotline aims to freeze the siphoned money in the banking chain.
Example: National cybercrime reporting helpline number?
Where students lose marks
Saying the IT Act was enacted in 2008 - 2008 is the AMENDMENT; the Act is 2000.
Quoting Sec 66A as current law - it was struck down in 2015 (Shreya Singhal case).
Mixing CERT-In (incident response, MeitY) with NCIIPC (critical-infrastructure protection).
Practice sets — 16 questions
Sets of 10, mixed across the question types above. Each answer comes with a step-by-step explanation.
Topic test · 10 questions
Suggested time 5 min · wrong answers go to your mistake notebook automatically.