"The central government hereby declares the computer resources relating to the Core Banking Solution, Real Time Gross Settlement and National Electronic Fund Transfer comprising Structured Financial Messaging Server, being critical information infrastructure of the ICICI Bank, and the computer resources of its associated dependencies to be protected systems for the purpose of the said Act," the notification said.
In a similar worded two other notifications, Meity declared IT resources of HDFC bank and UPI managing entity National Payments Corporation of India (NPCI) as critical infrastructure.
The notification authorises access of IT resources of the notified entities by their designated employees, authorised team members of contractual managed service providers or third-party vendors who have been authorised by them for need-based access and any consultant, regulator, government official, auditor and stakeholder authorised by the entities on case-to-case basis.
"Looking at the recent sophisticated cyber attacks, it is high time all the banks and financial institutions get themselves notified as a protected system.
"Similarly, the control system of all the electricity, oil, airports, railways, metros and transport systems are critical infrastructure and must be declared as a protected system," SP, Cyber Crime, Uttar Pradesh Police, and certified cyber expert Triveni Singh said.
As per the Act, 'critical information infrastructure' means a computer resource, the incapacitation or destruction of which, shall have debilitating impact on national security, economy, public health or safety.
Any person who secures access or attempts to secure access to a protected system in contravention of the provisions shall be punished with imprisonment of a term which may extend to 10 years and shall also be liable for a fine, the Act says.