The Information Technology Act, 2000
CHAPTER VI: REGULATION OF CERTIFYING AUTHORITIES
Section 30: Certifying Authority To Follow Certain Procedures
Bare Act
Every Certifying Authority shall, -
-
make use of hardware, software and procedures that are secure from intrusion and misuse;
-
provide a reasonable level of reliability in its services which are reasonably suited to the performance of intended functions;
-
adhere to security procedures to ensure that the secrecy and privacy of the electronic signatures are assured;
-
be the repository of all electronic signature Certificates issued under this Act;
-
publish information regarding its practices, electronic signature Certificates and current status of such certificates;
-
observe such other standards as may be specified by regulations.
Simplified Act
Every company that issues digital certificates (Certifying Authority) must:
- use secure technology and processes to prevent unauthorized access and misuse;
- ensure that its services are dependable and appropriate for the tasks they're meant to perform;
- follow strict security measures to keep digital signatures confidential and protect the identity of the users;
- keep a record of all the digital certificates they issue;
- share information about the way they operate, the digital certificates they issue, and the current status of those certificates;
- comply with any additional standards set by the relevant regulations.
Explanation using examples
Let's consider a hypothetical scenario. Imagine a company named SecureSign Inc., which acts as a Certifying Authority under the Information Technology Act, 2000.
- SecureSign Inc. uses state-of-the-art servers, firewalls, and intrusion detection systems to ensure their hardware and software are secure from any unauthorized access or misuse.
- The company provides reliable services to its customers, ensuring their electronic signature services work seamlessly for signing documents online, which is the intended function.
- SecureSign Inc. follows stringent security procedures, including encryption and two-factor authentication, to ensure the privacy and secrecy of the electronic signatures generated through their platform.
- As a Certifying Authority, SecureSign Inc. stores all electronic signature Certificates issued under the IT Act, acting as a trusted repository.
- The company maintains transparency by publishing information about its practices, details about the electronic signature Certificates it issues, and the current status of these certificates on its official website.
- SecureSign Inc. also adheres to any additional standards or regulations specified by the governing bodies, ensuring their services are up-to-date and compliant with the latest rules.

