(1) In these rules, unless the context otherwise requires,--
(a) "Act" means the Information Technology Act, 2000 (21 of 2000);
(b) "Computer contaminant'* means computer contaminant as defined in section 43 (i) of the Information Technology Act, 2000;
(c) "Computer emergency response" means to coordinate action during cyber security emergencies, provide incident response services to users, publish alerts concerning vulnerabilities and threats, and offer information to help improve cyber security
(d) "Computer resource" means computer resource as defined in section 2(1 )(k) of the Information Technology Act, 2000;
(e) "Computer security incident" means cyber security incident;
(f) "Cyber security" means cyber security as defined in section 2(l)(nb) of the Information Technology Act, 2000;
(g) "Cyber incident", means any real or suspected adverse event that is likely to cause or causes an offence or contravention, harm to critical functions and services across the public and private sectors by impairing [*1PT II-T3*>5 3 ( i ) ] WcT ^1 T R ^ : STCTItlRTn 13 the confidentiality, integrity, or availability of electronic information, systems, services or networks resulting in unauthorised access, denial of service or disruption, unauthorised use of a computer resource, changes to data or information without authorisation; or threatens public safety, undermines public confidence, have a negative effect on the national economy, or diminishes the security posture of the nation;
(h) ''Cyber security incident" means any real or suspected adverse event in relation to cyber security that violates an explicitly or implicitly applicable security policy resulting in unauthorized access, denial of service or disruption, unauthorised use of a computer resource for processing or storage of information or changes to data, information without authorisation;
(i) "Cyber security breaches" means unauthorised acquisition or unauthorised use by a person as well as an entity of data or information that compromises the confidentiality, integrity or availability of information maintained in a computer resource;
(j.) "Director General" means the Director General of the Indian Computer Emergency Response Team;
(k) "Indian Computer Emergency Response Team" means the Indian Computer Emergency Response Team set up under sub-section (1) of section 70(B) of the Act;
(1) "Information" means information as defined in section 2(l)(v) of the Information Technology Act, 2000;
(m) "Information security practices" means implementation of security policies and standards in order to minimise the cyber security incidents and breaches;
(n) "National Critical Information Infrastructure Protection Centre" means the national nodal agency for protection of Critical Information Infrastructure set up under sub- section (1) of Section 70(B) of the Act;
(o) "Security policy" means documented business rules and processes for protecting information and the - computer resource;
(p) "Vulnerability" means the existence of a flaw or weakness in hardware or software of a computer resource that can be exploited resulting in their adverse or different functioning other than the intended functions.
(2) Words and expressions used in these rules but not defined and defined in the Act shall have the same meaning as is assigned to them in the Act.
J. Location.— The Indian Computer Emergency Response Team (hereinafter referred in these Rules as CERT-In) shall function at Department of Electronics and Information Technology, Ministry of Communications and Information Technology and shall be located at "Electronics Niketan", 6, CGO Complex, Lodhi Road, New Delhi -
110003.