Un-authorized access to protected system - Sec.70 - Information Technology Act

July 18, 2017

Section 70 of the Information Technology Act allows the government to declare any computer resource affecting Critical Information Infrastructure as a protected system, prescribing up to ten years imprisonment for unauthorized access.

Critical Information Infrastructure and Protected System Definition

Section 70 of the Information Technology Act provides a statutory legal framework designed to safeguard strategic digital assets vital to national stability. Under Section 70(1), the appropriate Government may, by notification in the Official Gazette, declare any computer resource, network, or database that directly or indirectly affects Critical Information Infrastructure (CII) to be a protected system.

The statute explicitly defines Critical Information Infrastructure as any computer resource whose incapacitation or destruction would cause a debilitating impact on national security, the national economy, public health, or public safety. Key sectors notified under Section 70 include power grids, banking and financial gateways, telecom networks, nuclear facilities, civil aviation control systems, and defense databases.

Access Authorization and Security Controls

Under Section 70(2), access to a protected system is strictly restricted. Only individuals specifically authorized by an order in writing issued by the appropriate Government are legally permitted to secure access to notified computer resources. Organizations operating protected systems must implement rigorous physical, technical, and administrative access controls.

Section 70(4) mandates that the Central Government shall prescribe mandatory information security practices, audit guidelines, and technical procedures for protected systems. Compliance includes multi-factor authentication, privileged access management, encrypted storage, continuous intrusion detection, and mandatory security logging. Entities analyzing digital infractions can examine wider legal developments detailed in Cyber Crimes: Some Indian Cases.

Penalties for Unauthorized Access under Section 70(3)

Section 70(3) imposes severe criminal sanctions on any person who secures access or attempts to secure access to a protected system in contravention of statutory provisions. The offense is punishable with imprisonment of either description for a term which may extend to ten years, alongside a judicial fine. The statutory penal framework highlights the gravity of unauthorized access:

  • Imprisonment up to 10 years for unauthorized access or attempted intrusion;
  • Mandatory criminal trial before a Sessions Court with no option for administrative compounding;
  • Extraterritorial application under Section 75 where unauthorized access originates from outside Indian borders; and
  • Enhanced liability for malicious insiders, system administrators, or external hackers compromising critical assets.

Where offenses involve exploitation of digital platforms or sensitive content, prosecutors also examine provisions like Sec.67B IT Act alongside Section 70 charges to establish complete criminal liability.

Role of NCIIPC and Institutional Governance

To enforce Section 70 and safeguard national critical assets, the Central Government created the National Critical Information Infrastructure Protection Centre (NCIIPC) under Section 70A of the Act. NCIIPC serves as the national nodal agency for all CII security matters, conducting vulnerability assessments, issuing threat advisories, and ensuring that protected systems maintain international cybersecurity standards.

Found this helpful?

Share this page with others