Gazette Tracker
Gazette Tracker

Core Purpose

Draft notification of the Telecommunications (Critical Telecommunication Infrastructure) Rules, 2024, published for public comment under section 22(4) read with section 56(2)(w) of the Telecommunications Act, 2023.

Detailed Summary

G.S.R. 521(E), issued by the Department of Telecommunications, Ministry of Communications on 28 August 2024, publishes draft Telecommunications (Critical Telecommunication Infrastructure) Rules, 2024 under sub-section (4) of section 22 read with clause (w) of sub-section (2) of section 56 of the Telecommunications Act, 2023 (44 of 2023), inviting objections or suggestions to the Joint Secretary (Telecom), Department of Telecommunications, Sanchar Bhawan, 20 Ashoka Road, New Delhi, within thirty days of publication; the draft rules define Critical Telecommunication Infrastructure as network(s) notified under section 22(3) of the Act, and require notified telecommunication entities to comply with Essential Requirements, Interface Requirements and Indian Telecommunication Security Assurance Requirements issued by the Telecommunication Engineering Centre and National Centre for Communication Security, appoint a Chief Telecommunication Security Officer, maintain network architecture, personnel-access, supply-chain and vulnerability/risk records, report security incidents to the Central Government within two hours, obtain prior written Central Government approval for remote access and infrastructure upgradation, and permit Central Government inspection of hardware, software and data; the notification bears file number 24-05/2024-UBB and is signed by Devendra Kumar Rai, Joint Secretary.

Full Text

REGD. No. D. L.-33004/99 The Gazette of India CG-DL-E-29082024-256725 EXTRAORDINARY PART II-Section 3-Sub-section (i) PUBLISHED BY AUTHORITY No. 482] NEW DELHI, WEDNESDAY, AUGUST 28, 2024/ BHADRA 6, 1946 MINISTRY OF COMMUNICATIONS (Department of Telecommunications) NOTIFICATION New Delhi, the 28th August, 2024 G.S.R. 521(E).- The following draft rules, which the Central Government proposes to make in exercise of the powers conferred by sub-section (4) of section 22, read with clause (w) of sub-section (2) of section 56 of the Telecommunications Act, 2023 (44 of 2023), are hereby published for the information of all persons likely to be affected thereby and notice is hereby given that the said draft rules shall be taken into consideration after the expiry of a period of thirty days from the date on which copies of this notification as published in the Official Gazette, are made available to the public; Objections or suggestions, if any, may be addressed to the Joint Secretary (Telecom), Department of Telecommunications, Ministry of Communications, Government of India, Sanchar Bhawan, 20, Ashoka Road, New Delhi- 110001; The objections or suggestions which may be received from any person with respect to the said draft rules before the expiry of the aforesaid period shall be taken into consideration by the Central Government. 1. Short title and commencement (1) These rules may be called the Telecommunications (Critical Telecommunication Infrastructure) Rules, 2024. (2) They shall come into force on the date of their publication in the Official Gazette. 2. Definitions (1) In these rules, unless the context otherwise requires: (a) "Act" means the Telecommunications Act, 2023 (44 of 2023); (b) "Chief Telecommunication Security Officer" means the designated employee of a telecommunication entity, appointed pursuant to the Telecommunications (Telecom Cyber Security) Rules, 2024; (c) "Critical Telecommunication Infrastructure" means any telecommunication network, or part thereof notified under sub-section (3) of section 22 of the Act; (d) "rules" means the Telecommunications (Critical Telecommunication Infrastructure) Rules, 2024; (e) "security incident" shall have the meaning as provided under the Telecommunications (Telecom Cyber Security) Rules, 2024; and (f) "telecommunication entity" means any person providing telecommunication services, or establishing, operating, maintaining, or expanding telecommunication network, including an authorised entity holding an authorisation under sub-section (1) of section 3 of the Act, or a person exempted from the requirement of authorisation under sub-section (3) of section 3 of the Act. (2) The words and expressions used in these rules and not defined herein but defined in the Act, shall have the meaning assigned to them in the Act. 3. Applicability (1) These rules shall apply to telecommunication network, or any part thereof, which has been notified by the Central Government as Critical Telecommunication Infrastructure, in accordance with the provisions of sub- section (3) of section 22 of the Act, based on an assessment that disruption of such infrastructure will have a debilitating impact on national security, economy, public health or safety of the nation. (2) To enable notification of Critical Telecommunication Infrastructure, each telecommunication entity shall provide the details of its telecommunication network, telecommunication services, elements of such network and services, and other relevant information including software and hardware, upon request of the Central Government, in the form specified for this purpose. THE GAZETTE OF INDIA : EXTRAORDINARY [PART II-SEC. 3(i)] 4. Compliance requirements (1) A telecommunication entity shall ensure that Critical Telecommunication Infrastructure, including any spares, hardware and software used in such Critical Telecommunication Infrastructure, are in compliance with: (a) Essential Requirements (ERs), Interface Requirements (IRs), Indian Telecommunication Security Assurance Requirements (ITSARs) and specifications, testing requirements, or conformity assessment issued by Telecommunication Engineering Centre, National Centre for Communication Security, or any other person as may be notified by the Central Government for this purpose; (b) National Security Directive on Telecommunication Sector (NSDTS) as issued by Central Government and as amended from time to time; and (c) Directives on Communication security certification issued by the Central Government. (2) A telecommunication entity shall ensure compliance with standards on Critical Telecommunication Infrastructure as may be notified or prescribed by the Central Government from time to time. 5. Inspection of Critical Telecommunication Infrastructure (1) The Central Government, may, by an order, authorise its personnel to access and inspect hardware, software and data pertaining to Critical Telecommunication Infrastructure of telecommunication entities. (2) A telecommunication entity shall ensure access to any personnel authorised by the Central Government under sub-rule (1) for inspection of Critical Telecommunication Infrastructure. 6. Chief Telecommunication Security Officer The Chief Telecom Security Officer shall be responsible for the implementation of these rules, and shall provide the following details in respect of Critical Telecommunication Infrastructure to the Central Government in the form and manner as may be specified: (a) Telecommunication network architecture of Critical Telecommunication Infrastructure; (b) Authorised personnel having access to Critical Telecommunication Infrastructure; (c) Inventory of spares, hardware and software related to Critical Telecommunication Infrastructure; (d) Details of Vulnerability/ Threat/Risk analysis for the cyber security architecture of Critical Telecommunication Infrastructure; (e) Cyber Crisis Management Plan for Critical Telecommunication Infrastructure; (f) Security audit reports and audit compliance reports of Critical Telecommunication Infrastructure; and (g) Service Level Agreements (SLAs) of services pertaining to Critical Telecommunication Infrastructure; (h) All logs relating to critical telecommunication infrastructure to assist in detection of anomalies and enable the Central Government to generate intelligence on real time basis; and (i) Reporting of security incidents within the timelines specified for Critical Telecommunication Infrastructure under rule 7. 7. Obligations related to critical telecommunication infrastructure (1) Each telecommunication entity shall comply with the following obligations, in the form and manner as specified by the Central Government: (a) implementation of the security measures, standards, specifications and upgradation requirements and procedures, as notified by the Central Government in relation to Critical Telecommunication Infrastructure; (b) maintenance of a complete list of Critical Telecommunication Infrastructure along with the software and hardware details, dependencies on and of Critical Telecommunication Infrastructure, or any other details in accordance with the directions of the Central Government; (c) preservation of the logs and documentation of the telecommunication network architecture of the Critical Telecommunication Infrastructure including the changes in such telecommunication network architecture; (d) planning, development and maintenance of adequate verification practices and protocols applicable for all personnel authorised to have access to Critical Telecommunication Infrastructure, and periodic review of the same as directed by the Central Government; (e) maintenance of records of the supply chain of the telecommunication equipment and other equipment deployed in the Critical Telecommunication Infrastructure till the Critical Telecommunication Infrastructure is in use, and provide such information as and when sought by the Central Government; (f) ensuring that remote access to the Critical Telecommunication Infrastructure for the purpose of repair or maintenance as the case may be, is provided only upon prior written approval of the Central Government including the location from where such repair or maintenance may be provided; (g) ensuring that the logs for the remote access as provided under clause (f) are preserved till the Critical Telecommunication Infrastructure is in use and producing such logs as and when sought by the Central Government; (h) ensuring that vulnerability/threat/risk analysis for telecommunication network architecture of critical telecommunication infrastructure is carried out annually or as per frequency directed by the Central Government; (i) planning, development, maintenance and review of documented processes required for service level agreements entered into by the telecommunication entities with their vendors in relation to Critical Telecommunication Infrastructure; (j) planning, development, maintenance and review of the process of taking regular backup of logs of networking and communication devices, servers, systems and services supporting the functioning of the Critical Telecommunication Infrastructure; (k) implementation of standard operating procedures for security incident response systems, including disaster recovery and business continuity; (1) implementation of mechanisms to ensure intimation of security incident(s) to the Central Government, no later than within two hours of occurrence of such incident, in the form and manner as may be specified for this purpose; and (m) maintenance of a risk register including a graded risk assessment associated with different elements of Critical Telecommunication Infrastructure within its network, identifying the potential and severity of risks posed to the Critical Telecommunication Infrastructure and solutions to mitigate the same and produce such information as and when sought by the Central Government. 8. Requirements for upgradation of Critical Telecommunication Infrastructure (1) Where upgradation of the equipment which form part of the Critical Telecommunication Infrastructure is required, the telecommunication entity shall inform the Central Government, along with details of the test reports for such upgradation, in the form and manner as may be specified by the Central Government for this purpose. (2) Any upgradation activity shall be undertaken only upon the prior written certification by the Central Government, or any person authorised by the Central Government for this purpose, that the test reports for such upgradation submitted under sub-rule (1) are in compliance with standards specified by the Central Government for this purpose. (3) The Central Government may also direct a telecommunication entity to test any upgradation in the Critical Telecommunication Infrastructure in an appropriate controlled environment and submit the results of such THE GAZETTE OF INDIA: EXTRAORDINARY [PART II-SEC. 3(i)] tests in the form and manner as may be specified by the Central Government, and the telecommunication entity shall comply with such directions. (4) The telecommunication entity shall ensure preservation of records and information in relation to any upgradation, till such time the relevant Critical Telecommunication Infrastructure is in use, and such records shall be produced as and when sought by the Central Government. 9. Digital implementation of these rules The Central Government, in furtherance of section 53 of the Act, may notify appropriate means for the digital implementation of these rules, including for intimation by telecommunication entity of security incidents and other details in relation to the Critical Telecommunication Infrastructure to the Central Government, reporting procedures to be undertaken by the Chief Telecommunications Security Officer, and other procedures and requirements as specified under these rules. [F.No.24-05/2024-UBB] DEVENDRA KUMAR RAI, Jt. Secy.

Never miss important gazettes

Create a free account to save gazettes, add notes, and get email alerts for keywords you care about.

Sign Up Free