Full Text
REGD. No. D. L.-33004/99
The Gazette of India
CG-DL-E-29082024-256725
EXTRAORDINARY
PART II-Section 3-Sub-section (i)
PUBLISHED BY AUTHORITY
No. 482]
NEW DELHI, WEDNESDAY, AUGUST 28, 2024/ BHADRA 6, 1946
MINISTRY OF COMMUNICATIONS
(Department of Telecommunications)
NOTIFICATION
New Delhi, the 28th August, 2024
G.S.R. 521(E).- The following draft rules, which the Central Government proposes to make in exercise of
the powers conferred by sub-section (4) of section 22, read with clause (w) of sub-section (2) of section 56 of the
Telecommunications Act, 2023 (44 of 2023), are hereby published for the information of all persons likely to be
affected thereby and notice is hereby given that the said draft rules shall be taken into consideration after the expiry of
a period of thirty days from the date on which copies of this notification as published in the Official Gazette, are made
available to the public;
Objections or suggestions, if any, may be addressed to the Joint Secretary (Telecom), Department of
Telecommunications, Ministry of Communications, Government of India, Sanchar Bhawan, 20, Ashoka Road, New
Delhi- 110001;
The objections or suggestions which may be received from any person with respect to the said draft rules
before the expiry of the aforesaid period shall be taken into consideration by the Central Government.
1. Short title and commencement
(1) These rules may be called the Telecommunications (Critical Telecommunication Infrastructure) Rules, 2024.
(2) They shall come into force on the date of their publication in the Official Gazette.
2. Definitions
(1) In these rules, unless the context otherwise requires:
(a) "Act" means the Telecommunications Act, 2023 (44 of 2023);
(b) "Chief Telecommunication Security Officer" means the designated employee of a
telecommunication entity, appointed pursuant to the Telecommunications (Telecom Cyber Security)
Rules, 2024;
(c) "Critical Telecommunication Infrastructure" means any telecommunication network, or part thereof
notified under sub-section (3) of section 22 of the Act;
(d) "rules" means the Telecommunications (Critical Telecommunication Infrastructure) Rules, 2024;
(e) "security incident" shall have the meaning as provided under the Telecommunications (Telecom
Cyber Security) Rules, 2024; and
(f) "telecommunication entity" means any person providing telecommunication services, or establishing,
operating, maintaining, or expanding telecommunication network, including an authorised entity
holding an authorisation under sub-section (1) of section 3 of the Act, or a person exempted from the
requirement of authorisation under sub-section (3) of section 3 of the Act.
(2) The words and expressions used in these rules and not defined herein but defined in the Act, shall have the
meaning assigned to them in the Act.
3. Applicability
(1) These rules shall apply to telecommunication network, or any part thereof, which has been notified by the
Central Government as Critical Telecommunication Infrastructure, in accordance with the provisions of sub-
section (3) of section 22 of the Act, based on an assessment that disruption of such infrastructure will have a
debilitating impact on national security, economy, public health or safety of the nation.
(2) To enable notification of Critical Telecommunication Infrastructure, each telecommunication entity shall
provide the details of its telecommunication network, telecommunication services, elements of such network
and services, and other relevant information including software and hardware, upon request of the Central
Government, in the form specified for this purpose.
THE GAZETTE OF INDIA : EXTRAORDINARY
[PART II-SEC. 3(i)]
4. Compliance requirements
(1) A telecommunication entity shall ensure that Critical Telecommunication Infrastructure, including any
spares, hardware and software used in such Critical Telecommunication Infrastructure, are in compliance
with:
(a) Essential Requirements (ERs), Interface Requirements (IRs), Indian Telecommunication Security
Assurance Requirements (ITSARs) and specifications, testing requirements, or conformity assessment
issued by Telecommunication Engineering Centre, National Centre for Communication Security, or any
other person as may be notified by the Central Government for this purpose;
(b) National Security Directive on Telecommunication Sector (NSDTS) as issued by Central Government
and as amended from time to time; and
(c) Directives on Communication security certification issued by the Central Government.
(2) A telecommunication entity shall ensure compliance with standards on Critical Telecommunication
Infrastructure as may be notified or prescribed by the Central Government from time to time.
5. Inspection of Critical Telecommunication Infrastructure
(1) The Central Government, may, by an order, authorise its personnel to access and inspect hardware, software
and data pertaining to Critical Telecommunication Infrastructure of telecommunication entities.
(2) A telecommunication entity shall ensure access to any personnel authorised by the Central Government under
sub-rule (1) for inspection of Critical Telecommunication Infrastructure.
6. Chief Telecommunication Security Officer
The Chief Telecom Security Officer shall be responsible for the implementation of these rules, and shall provide
the following details in respect of Critical Telecommunication Infrastructure to the Central Government in the
form and manner as may be specified:
(a) Telecommunication network architecture of Critical Telecommunication Infrastructure;
(b) Authorised personnel having access to Critical Telecommunication Infrastructure;
(c) Inventory of spares, hardware and software related to Critical Telecommunication Infrastructure;
(d) Details of Vulnerability/ Threat/Risk analysis for the cyber security architecture of Critical
Telecommunication Infrastructure;
(e) Cyber Crisis Management Plan for Critical Telecommunication Infrastructure;
(f) Security audit reports and audit compliance reports of Critical Telecommunication Infrastructure;
and
(g) Service Level Agreements (SLAs) of services pertaining to Critical Telecommunication
Infrastructure;
(h) All logs relating to critical telecommunication infrastructure to assist in detection of anomalies and
enable the Central Government to generate intelligence on real time basis; and
(i) Reporting of security incidents within the timelines specified for Critical Telecommunication
Infrastructure under rule 7.
7. Obligations related to critical telecommunication infrastructure
(1) Each telecommunication entity shall comply with the following obligations, in the form and manner as
specified by the Central Government:
(a) implementation of the security measures, standards, specifications and upgradation requirements and
procedures, as notified by the Central Government in relation to Critical Telecommunication
Infrastructure;
(b) maintenance of a complete list of Critical Telecommunication Infrastructure along with the software and
hardware details, dependencies on and of Critical Telecommunication Infrastructure, or any other details
in accordance with the directions of the Central Government;
(c) preservation of the logs and documentation of the telecommunication network architecture of the Critical
Telecommunication Infrastructure including the changes in such telecommunication network
architecture;
(d) planning, development and maintenance of adequate verification practices and protocols applicable for
all personnel authorised to have access to Critical Telecommunication Infrastructure, and periodic
review of the same as directed by the Central Government;
(e) maintenance of records of the supply chain of the telecommunication equipment and other equipment
deployed in the Critical Telecommunication Infrastructure till the Critical Telecommunication
Infrastructure is in use, and provide such information as and when sought by the Central Government;
(f) ensuring that remote access to the Critical Telecommunication Infrastructure for the purpose of repair or
maintenance as the case may be, is provided only upon prior written approval of the Central Government
including the location from where such repair or maintenance may be provided;
(g) ensuring that the logs for the remote access as provided under clause (f) are preserved till the Critical
Telecommunication Infrastructure is in use and producing such logs as and when sought by the Central
Government;
(h) ensuring that vulnerability/threat/risk analysis for telecommunication network architecture of critical
telecommunication infrastructure is carried out annually or as per frequency directed by the Central
Government;
(i) planning, development, maintenance and review of documented processes required for service level
agreements entered into by the telecommunication entities with their vendors in relation to Critical
Telecommunication Infrastructure;
(j) planning, development, maintenance and review of the process of taking regular backup of logs of
networking and communication devices, servers, systems and services supporting the functioning of the
Critical Telecommunication Infrastructure;
(k) implementation of standard operating procedures for security incident response systems, including
disaster recovery and business continuity;
(1) implementation of mechanisms to ensure intimation of security incident(s) to the Central Government,
no later than within two hours of occurrence of such incident, in the form and manner as may be
specified for this purpose; and
(m) maintenance of a risk register including a graded risk assessment associated with different elements of
Critical Telecommunication Infrastructure within its network, identifying the potential and severity of
risks posed to the Critical Telecommunication Infrastructure and solutions to mitigate the same and
produce such information as and when sought by the Central Government.
8. Requirements for upgradation of Critical Telecommunication Infrastructure
(1) Where upgradation of the equipment which form part of the Critical Telecommunication Infrastructure is
required, the telecommunication entity shall inform the Central Government, along with details of the test
reports for such upgradation, in the form and manner as may be specified by the Central Government for this
purpose.
(2) Any upgradation activity shall be undertaken only upon the prior written certification by the Central
Government, or any person authorised by the Central Government for this purpose, that the test reports for
such upgradation submitted under sub-rule (1) are in compliance with standards specified by the Central
Government for this purpose.
(3) The Central Government may also direct a telecommunication entity to test any upgradation in the Critical
Telecommunication Infrastructure in an appropriate controlled environment and submit the results of such
THE GAZETTE OF INDIA: EXTRAORDINARY
[PART II-SEC. 3(i)]
tests in the form and manner as may be specified by the Central Government, and the telecommunication
entity shall comply with such directions.
(4) The telecommunication entity shall ensure preservation of records and information in relation to any
upgradation, till such time the relevant Critical Telecommunication Infrastructure is in use, and such records
shall be produced as and when sought by the Central Government.
9. Digital implementation of these rules
The Central Government, in furtherance of section 53 of the Act, may notify appropriate means for the digital
implementation of these rules, including for intimation by telecommunication entity of security incidents and
other details in relation to the Critical Telecommunication Infrastructure to the Central Government, reporting
procedures to be undertaken by the Chief Telecommunications Security Officer, and other procedures and
requirements as specified under these rules.
[F.No.24-05/2024-UBB]
DEVENDRA KUMAR RAI, Jt. Secy.
Login to read full text