Technical

critical information infrastructure (CII)

Systems whose disruption would critically harm national functions.

Definitions (6)

Defined as computer systems, networks, or information systems whose incapacitation, destruction or unauthorized interference would have a serious impact on national security, the economy, public health, or public safety; the Act provides for formal designation, protection measures, and penalties for damage or interference with such infrastructure.

CII denotes systems, networks, services and assets in specified sectors (such as energy, communications, finance, health and utilities) whose disruption, incapacitation or destruction would severely affect national functions, public safety or economic stability. The Act identifies CII by reference to sectoral criteria and empowers the Agency to designate and impose resilience obligations on operators of such infrastructure.

Information infrastructure in key sectors (e.g., public communications, energy, transport, water conservancy, finance, public services and e-government) whose incapacitation or destruction would seriously harm national security, the national economy, public interests or societal welfare; designated CIIs are subject to enhanced protection, assessment, personnel vetting and data localization requirements.

Systems and assets that support essential services and national functions whose disruption or compromise would have a significant impact on national security, public health, safety, or economic stability. CII includes designated government and private-sector systems identified for prioritized protection under the policy.

Computer systems or networks so vital to the Republic that their incapacity or destruction would have a debilitating impact on national security, the economy, or public health.

Information systems, networks, and data centers used in state management, defense, healthcare, and finance whose disruption would cause serious national harm.