The functions and duties of the National Critical Information Infrastructure Protection Centre shall be the following, namely:-
(1) National Critical Information Infrastructure Protection Centre shall function as the national nodal agency for all measures to protect nation's critical information infrastructure.
(2) The National Critical Information Infrastructure Protection Centre shall essentially protect and deliver advice that aims to reduce the vulnerabilities of critical information infrastructure, against cyber terrorism, cyber warfare and other threats.
(3) Identification of all critical information infrastructure elements for approval by Ihe appropriate Government for notifying ihc same.
?8t GZ/M-1 6 THE GAZETTE OF INDIA : EXTRAORDINARY (PARI ]]—SEC. 3(i)J
(4) Provide strategic leadership and coherence across Government to respond to cyber security threats against the identified critical information infrastructure.
(5) Coordinating, sharing, monitoring, collecting, analysing and forecasting, national-level threats to critical information infrastructure for policy guidance, expertise-sharing and situational awareness for early warning or alerts. The basic responsibility for protecting critical information infrastructure system shall lie with the agency running that critical information infrastructure.
(6) Assisting in the development of appropriate plans, adoption of standards, sharing of best practices and refinement of procurement processes in respect of protection of Critical Information Infrastructure.
(7) Evolving protection strategies, policies, vulnerability assessment and auditing methodologies and plans for their dissemination and implementation for protection of Critical Information Infrastructure.
(8) Undertaking research and development and allied activities, providing funding (including grants-in-aid) for creating, collaborating and development of innovative future technology for developing and enabling the growth of skHls, working closely with wider public sector industries, academia et al and with international partners for protection of Critical Information Infrastructure.
(9) Developing or organising training and awareness programs as also nurturing and development of audit and certification agencies for protection of Critical Informalion Infrastructure.
(10) Developing and executing national and international cooperation strategies for protection of Critical Information Infrastructure.
(11) Issuing guidelines, advisories and vulnerability or audit notes etc. relating to protection of critical information infrastructure and practices, procedures, prevention and response in consultation with the stake holders, in close coordination with Indian Computer Emergency Response Team and other organisations working in the field or related fields.
(12) Exchanging cyber incidents and other information relating to attacks and vulnerabilities with Indian Computer Emergency Response Team and other concerned organisations in the field.
(13) In the event of any threat to critical information infrastructure the National Critical Informalion Infrastructure Protection Centre may call for information and give directions to the critical sectors or persons serving or having a critical impact on Criiical Information Infrastructure.
S. Manner of per forming functions and duties.—
(1) (a) The National Critical Information Infrastructure Protection Centre shall essentially undertake its task and discharge its responsibilities in close association or coordination with the respective nodal officers of the critical sectors, Indian Computer Emergency Response Team and other organisations working in the field or related fields.
(b) Prioritisalion of actions against threats or vulnerabilities shall generally be based on the type, severity.
affected entity and availability of resources and the methodology for prioritization in descending order shall be as follows, namely:-
(t) the threat or vulnerability could result in significant physical or economic or other damage to the national critical information infrastructure;
(ii) Government property covered under critical information infrastructure, is in danger;
(iii) a significant number of sectors) of the national critical information infrastructure are in danger;
(iv) a particular sector of the national critical information infrastructure is endangered.
(2) Communication with National Critical Information Infrastructure Protection Centre
(a) The respective nodal officers in the various critical sectors shall communicate with the National Critical Information Infrastructure Protection Centre using all appropriate or available means of communication.
(b) The National Criiical Information Infrastructure Protection Centre may also take suo moto cognizance of any vulnerability'threat that comes to its notice and thai affects, or can affect, the nation's Critical Information Infrastructure, and initiate suitable measures.
(c) The National Criiical Information Infrastructure Protection Centre shall maintain a 24X7 help desk to facilitate reporting of incidents.
(3) National Criiical Informalion Infrastructure Protection Centre - Operations and Response lirn w-wrs 3(i)j tnra w ?&m : WH>IR"I 7
(a) National Critical Information Infrastructure Protection Centre shall, in conjunction with the respective nodal officers and other agencies like Indian Computer Emergency Response Team working in the field, issue advisories or alerts and provide guidance and expertise-sharing in addressing the thrcats'vulncrahilitics for protection of Critical Information Infrastructure.
(b) II shall, in the event of a likely/actual national-level threat, play a pivotal role and coordinate the response of the various stake-holders in the area of critical information infrastructure in close cooperation with Indian Computer Emergency Response Team.
(c) For protection of critical information infrastructure, the National Critical Information Infrastructure Protection Centre may take recourse for monitoring and collection of traffic data in accordance with the provisions of section 69B of the Act and the rules notified thereunder specific to critical information infrastructure and relevant to their cyber protection needs only.
(d> The powers to the National Critical Information Infrastructure Protection Centre for interception/monitoring/decryption and blocking of cyber information for the purpose of protection of critical information infrastructure shall be in accordance with the law and as per the Standard Operating Procedures/modalities to be jointly developed by Ministry of Home Affairs and NTRO.