ExamShortcut

Cyber Security

🔒 Log in to track
high importance⚡ 9 shortcuts4 subtopics
All subtopics·Subtopic 4 of 4

IT Act 2000, offences and authorities

🔒 Log in to track
⏱ 5 min read🧩 4 question types🎯 16 practice Q
The idea in one minute

The Information Technology Act, 2000 is India's cyber-law framework - passed in 2000, in force from 17 October 2000, based on the UNCITRAL model law on e-commerce, and amended in 2008 (adding 66C, 66D, 66F etc.).

SectionOffence
Sec 43Penalty (up to Rs. 1 crore) for unauthorised access/damage to computer, data, virus injection
Sec 65Tampering with computer source documents - up to 3 years
Sec 66Computer-related offences (dishonesty/franchise of Sec 43 acts)
Sec 66CIdentity theft - up to 3 years + fine
Sec 66DCheating by personation using a computer (online fraud) - up to 3 years
Sec 66EViolation of privacy (publishing private images) - up to 3 years
Sec 66FCyber terrorism - may extend to life imprisonment
Sec 67Publishing/transmitting obscene material electronically (first conviction up to 3 years + Rs. 5 lakh fine)
Sec 72Breach of confidentiality and privacy by a empowered body

Note: Sec 66A (punishing 'offensive messages') was struck down by the Supreme Court in Shreya Singhal v. Union of India (2015) as unconstitutional.

Authorities/portals: CERT-In (Indian Computer Emergency Response Team, 2004, under MeitY) - the national incident-response and warning body; NCIIPC protects critical information infrastructure; cybercrime.gov.in is the national reporting portal and 1930 the cyber-fraud helpline (freezing defrauded money quickly).

01

The Information Technology Act, 2000

India's law for the electronic world is the IT Act, 2000, in force from 17 October 2000. It grew out of the UNCITRAL model law (United Nations Commission on International Trade Law) on electronic commerce, which recommended that countries give legal recognition to electronic records and signatures. The Act legalised electronic records and digital signatures and created punishments for computer crimes. It was amended in 2008 (effective 2009), adding identity theft, cyber-terrorism provisions and the CERT-In mandate.

02

Sections the exams keep asking

SectionSubject
Sec 3authentication by digital (electronic) signature
Sec 43penalty/compensation for unauthorised access and damage to computer, data (hacking-type harm)
Sec 65tampering with computer source code
Sec 66computer-related offences — the "hacking" section (dishonest intent)
Sec 66Cidentity theft (fraudulent use of password/digital signature/biometric)
Sec 66Dcheating by personation using a computer resource (fake profiles)
Sec 67publishing/transmitting obscene material in electronic form
Sec 72breach of confidentiality and privacy (by those with lawful access to data)

Section 66A (punishment for "offensive messages") was struck down by the Supreme Court in Shreya Singhal v. Union of India (2015) as violative of free speech — a favourite trick option presented as still-valid law.

03

The watchdogs

  • CERT-In (Indian Computer Emergency Response Team) — the national incident-response agency under MeitY (Ministry of Electronics and IT); set up 2004, statutory backing via Sec 70B after the 2008 amendment.
  • NCIIPC (National Critical Information Infrastructure Protection Centre) — protects critical infrastructure (power, banking, telecom) under Sec 70A.
  • MeitY is the parent ministry for cyber laws and policy; the DPDP Act, 2023 (Digital Personal Data Protection Act) now governs personal-data privacy alongside the IT Act.
  • Reporting: national cyber-crime helpline 1930 and the portal cybercrime.gov.in.
04

Digital signature in one line

A digital signature (Sec 3) is the electronic equivalent of a handwritten signature: created with the signer's private key and verified by anyone with the public key (Certificate Authorities issue the keys). It proves who signed and that the document was not altered — authentication plus integrity.

05

Question types you will see

Each type: how to recognise it, the method step by step, and one question to try.

Type 1very common3 practice Q

IT Act basics (year, origin, amendment)

How to spot it:

'The IT Act was passed in ___', 'in force from 17 October 2000', 'based on which UN model law', 'the 2008 amendment'.

Method
  1. IT Act 2000, in force 17 October 2000 — India's cyber law.

  2. Based on the UNCITRAL model law on e-commerce (UN Commission on International Trade Law).

  3. Amended 2008 (effective 2009) — added identity theft (66C/66D), cyber-terrorism (66F), CERT-In backing.

Try this

India's Information Technology Act came into force on:

Show solution

17 October 2000 — based on the UNCITRAL model law; amended in 2008.

Type 2very common4 practice Q

Section-to-offence matching

How to spot it:

'Section 66 deals with ___', 'identity theft is which section', 'which section was struck down' — 43/65/66/66C/66D/67/72 and 66A.

Method
  1. 43 unauthorised access/damage penalty; 65 source-code tampering; 66 hacking (computer-related offences).

  2. 66C identity theft; 66D cheating by personation; 67 obscene material; 72 breach of privacy.

  3. 66A (offensive messages) was STRUCK DOWN in 2015 — Shreya Singhal case. Any option using 66A as live law is wrong.

Try this

Under which section of the IT Act is identity theft punished?

Show solution

Section 66C — fraudulent use of another's password, digital signature or biometric.

Type 3common3 practice Q

Authorities: CERT-In, NCIIPC, MeitY, helpline

How to spot it:

'CERT-In stands for / works under ___', 'critical infrastructure is protected by ___', 'the cyber-fraud helpline number'.

Method
  1. CERT-In (Indian Computer Emergency Response Team) = national incident-response agency, under MeitY.

  2. NCIIPC protects critical information infrastructure (power, banking, telecom).

  3. Report fraud on 1930 or cybercrime.gov.in; personal-data privacy now also under the DPDP Act 2023.

Try this

CERT-In, India's cyber incident response agency, functions under which ministry?

Show solution

MeitY — Ministry of Electronics and Information Technology.

Type 4occasional3 practice Q

Digital signature and e-record legality

How to spot it:

'A digital signature is used for ___', 'which section gives digital signatures legal status', authentication/integrity statements.

Method
  1. Digital signature (Sec 3) = electronic equivalent of a handwritten signature.

  2. It proves who signed (authentication) and that the document was not altered (integrity) — not secrecy.

  3. Signed with the signer's private key, verified with the public key; Certificate Authorities issue the credentials.

Try this

A digital signature primarily guarantees:

Show solution

Authenticity of the sender and integrity of the document — the file cannot be altered unnoticed; it is not encryption for secrecy.

06

Shortcuts that save time

⚡ Section story-line

43 = damage fine, 65 = source code, 66 = computer crime, 66C = identity (C for Credential theft), 66D = cheating by personation (D for Donning a false identity), 66F = terrorism (F for Fearsome), 67 = obscene.

Example

Under which IT Act section is identity theft punished?

Show solution

Section 66C.

⚡ 2000-17-10

IT Act passed and effective in 2000 (in force 17 October 2000), UNCITRAL-based, amended 2008. CERT-In follows in 2004.

Example

The IT Act came into force in the year?

Show solution
⚡ Helpline 1930

Money lost to online fraud? Dial 1930 fast and report at cybercrime.gov.in - the hotline aims to freeze the siphoned money in the banking chain.

Example

National cybercrime reporting helpline number?

Show solution
07

Mistakes to avoid

Where most students lose marks on this subtopic.

Mistake 01

Saying the IT Act was enacted in 2008 - 2008 is the AMENDMENT; the Act is 2000.

Mistake 02

Quoting Sec 66A as current law - it was struck down in 2015 (Shreya Singhal case).

Mistake 03

Mixing CERT-In (incident response, MeitY) with NCIIPC (critical-infrastructure protection).

08

Quick revision

Read this the night before the exam.

  • IT Act 2000, effective 17 Oct 2000, based on UNCITRAL; amended 2008.

  • 65 = source code; 66 = hacking; 66C = identity theft; 66D = online cheating; 67 = obscenity; 43 = unauthorised access penalty; 66A struck down 2015.

  • CERT-In = incident response under MeitY; NCIIPC = critical infrastructure; helpline 1930.

  • Digital signature = private key signs, public key verifies (Sec 3).

09

Practice: 16 questions

Sets of 10, mixed across the question types above. Every answer has a step-by-step explanation.

Topic test · 10 questions

Suggested time 5 min · wrong answers go to your mistake notebook automatically.