Correct answer: (d) 1, 2 and 3
Explanation
- A
1 only
Option (a) is 1 only. Service providers are covered, but the Information Technology (Amendment) Act / CERT-In rules also bind data centres and body corporates. This option is incomplete. This option is not the key.
- B
1 and 2 only
Option (b) is 1 and 2 only. It omits body corporates, which are also required to report prescribed cyber-security incidents. This option is not the key.
- C
3 only
Option (c) is 3 only. Body corporates are in, but so are intermediaries/service providers and data centres. This option is therefore wrong.
- D
1, 2 and 3
Section 70B of the IT Act and the CERT-In directions / Intermediary Rules require service providers, data centres, body corporates and others to report cyber-security incidents to CERT-In. All three stem entities are covered, so 1, 2 and 3 is the official key.
Summary. Official key is (d) 1, 2 and 3. Indian law treats cyber-incident reporting as a duty of a wide class of intermediaries and companies, not of one subset. CERT-In is the national nodal agency. Service providers, data centres and body corporates all appear in the reporting net. None of the three can be dropped.
Same topic · past papers
UPSC has asked this before
These previous-year questions sit on the same topic. Open one to practise the earlier ask.
-
2015 · Q67 · General Studies · 2 marks
With reference to the 'Indian Ocean Rim Association for Regional Cooperation (IOR-ARC)', consider the following statements: 1. It was established very recently in response to incidents of piracy and accidents of oil spills. 2. It is an alliance meant for maritime security only. Which of the statements given above is/are correct?