LEGAL GOVERNANCE OF CRITICAL INFORMATION INFRASTRUCTURE IN INDIA: A CRITICAL AND COMPARATIVE ANALYSIS

Authors

  • Puneet Sharma The North Cap University, Gurugram, Haryana-122017
  • Divya arora The North Cap University, Gurugram, Haryana-122017

DOI:

https://doi.org/10.70917/ijcisim-2026-5436

Keywords:

Digital technology, Cyber threat, Cyber security framework, Critical Information Infrastructure, Digitalization

Abstract

In today’s digital world, the Critical Information Infrastructure (CII) is the foundation for many essential services. CII also forms the backbone for national security, economic stability, and public welfare. The increasing dependence on digital technology and even faster-evolving cyber threats has made the protection of CII a matter of utmost importance. In India, the protection of CII is primarily recognized under the IT Act, 2000. Sections 70, 70A and 70B of the IT Act, 2000 provide the statutory basis of identification and protection of CII. In addition to these, the sector-specific guidelines and the Digital Personal Data Protection Act, 2023 (DPDP Act) also contribute to a broader cybersecurity framework. In an era of digitalization where dependence on technology is increasing, cyber threats have also become more sophisticated. This article aims to critically examine India’s existing legal framework for the protection of CII. Starting with the primary law – the IT Act 2000, it then covers various institutional mechanisms, sector-based regulations, and the relevance of the DPDP Act 2023. A comparative analysis with the legal approach adopted by various international jurisdictions – USA and UK – for protection of CII is also made. The methodology adopted during the study is doctrinal, which is supplemented by comparative analysis. The major legal and institutional issues and challenges are being identified during this study, which are affecting the effective protection of CII in today’s digital era. These include the absence of updated legal provisions, limited regulatory coordination, limited public-private cooperation, overlapping responsibilities, low incident reporting, etc. The article concludes by briefly suggesting the need for a more coherent, coordinated, and comprehensive legal framework for strengthening India’s legal regime governing CII.

Downloads

Download data is not yet available.

Downloads

Published

2026-08-02

How to Cite

Puneet Sharma, & Divya arora. (2026). LEGAL GOVERNANCE OF CRITICAL INFORMATION INFRASTRUCTURE IN INDIA: A CRITICAL AND COMPARATIVE ANALYSIS. International Journal of Computer Information Systems and Industrial Management Applications, 18(22s), 362–376. https://doi.org/10.70917/ijcisim-2026-5436

Issue

Section

Original Articles