(1) No person shall –
(a) endanger telecom cyber security; or
(b) send any message which adversely affects telecom cyber security.
(2) Without prejudice to the generality of sub-rule (1), no person shall endanger telecom cyber security by misuse of telecommunication equipment or telecommunication identifier or telecommunication network or telecommunication services or by – 1 The word “and” omitted by G.S.R. 771(E), dated 22.10.2025.
2 Ins. by ibid.
3 Ins. by ibid.
(a) fraud, cheating or personation;
(b) transmitting any message which is fraudulent;
(c) committing or intending to commit any security incident;
(d) engaging in any other use which is contrary to the provision, of any other law for the time being in force; or
(e) any other means which may have security risk on telecom cyber security.
(3) Every telecommunication entity 1 and TIUE] shall ensure compliance with the directions and standards, including timelines for their implementation, as may be issued by the Central Government for the prevention of misuse of telecommunication identifiers or telecommunication equipment or telecommunication network or telecommunication services for ensuring telecom cyber security.
(4) Every telecommunication entity shall implement the following measures to ensure telecom cyber security, namely :—
(a) adopt a telecom cyber security policy, which shall include—
(i) security safeguards, risk management approaches, actions, training, best practices and technologies, to enhance telecom cyber security;
(ii) telecommunication network testing including hardening, vulnerability assessment and penetration testing;
(iii) risk assessment, identification and prevention of security incidents;
(iv) rapid action system to deal with security incidents including mitigation measures to limit the impact of such incidents; and
(v) forensic analysis of security incidents to ensure learnings from such incidents and further strengthening telecom cyber security;
(b) inform the Central Government on adoption of the policy referred to in sub-clause
(a), in the manner as may be determined by the Central Government;
(c) identify and reduce the risks of security incidents and ensure timely responses to such incidents;
(d) take appropriate action for addressing security incidents, and mitigate their impact;
(e) ensure implementation of directions and standards issued by the Central Government on telecom cyber security;
(f) conduct periodic telecom cyber security audits of its network to assess resilience to threats on telecom cyber security through its own mechanisms and through the 1 Ins. by G.S.R. 771(E), dated 22.10.2025.
certified agency in such intervals as may be specified by the Central Government on the portal, and share the audit report with the Central Government, which may undertake further audits if so required;
(g) report security incidents to the Central Government, or any officer authorised in this behalf by the Central Government, and measures taken to address such incidents in the manner specified in rule 7;
(h) establish facilities such as Security Operations Centre (SOC), by itself or in collaboration with other telecommunication entities, within the time period as may be specified by the Central Government under sub-rule (3), to address the following, namely:
(i) monitor telecom cyber security and security incidents, intrusions and breaches of telecommunication services or telecommunication network, as well as, attempts to cause such incidents, intrusions or breaches;
(ii) maintain details of threat actors impacting its telecommunication services, or telecommunication network;
(iii) maintain command logs of operation and maintenance;
(iv) maintain logs of Security Operations Centre (SOC) (firewall, Intrusion Detection System (IDS) or Intrusion Prevention System (IPS), or Security Information and Event Management (SIEM) or other such solution);
(v) maintain logs of elements of telecommunication service, or telecommunication network or any other element required for security of telecommunication service or telecommunication network;
(vi) maintain all records or logs specified in this sub-rule, for a period as specified on the portal by the Central Government, and make such records available to the person authorised by the Central Government in this behalf; and
(vii) provide necessary support to the person authorised by the Central Government, including law enforcement agencies for the purpose of investigation related to security incidents.
(5) Every telecommunication entity shall furnish a detailed report relating to the action taken by it under sub-rule (4) in the form and manner as may be specified on the portal.
(6) The Central Government may, pursuant to any report or other information received from a telecommunication entity under sub-rule (4), may ––
(a) seek further clarifications from such telecommunication entity; or
(b) issue any directions, orders or instructions to such telecommunication entity for the protection of telecom cyber security and mitigate risks to telecom cyber security.