Information Technology Act Section 18 — Functions of Controller
CHAPTER VI REGULATION OF CERTIFYING AUTHORITIES
Cyber Law
Summary
The Controller may perform all or any of the functions listed in this section. This means the Controller has the power to choose which of these tasks to carry out, and is not required to do all of them.
Under clause (a), the Controller supervises the activities of Certifying Authorities, which are the bodies that issue electronic signature certificates.
Under clause (b), the Controller certifies the public keys of the Certifying Authorities, confirming their authenticity.
Under clause (c), the Controller sets the standards that Certifying Authorities must maintain.
Under clause (d), the Controller specifies the qualifications and experience that employees of a Certifying Authority should have.
Under clause (e), the Controller specifies the conditions under which Certifying Authorities must conduct their business.
Under clause (f), the Controller specifies the contents of written, printed, or visual materials and advertisements that may be distributed or used in relation to an electronic signature Certificate and the public key.
Under clause (g), the Controller specifies the form and content of an electronic signature Certificate and the key.
Under clause (h), the Controller specifies the form and manner in which Certifying Authorities must maintain their accounts.
Under clause (i), the Controller specifies the terms and conditions under which auditors may be appointed, as well as the remuneration to be paid to them.
Under clause (j), the Controller facilitates the establishment of any electronic system by a Certifying Authority, either alone or jointly with other Certifying Authorities, and regulates such systems.
Under clause (k), the Controller specifies the manner in which Certifying Authorities must conduct their dealings with subscribers, who are the users of the certificates.
Under clause (l), the Controller resolves any conflicts of interest between Certifying Authorities and subscribers.
Under clause (m), the Controller lays down the duties of the Certifying Authorities.
Under clause (n), the Controller maintains a database containing the disclosure record of every Certifying Authority, with such particulars as may be specified by regulations, and this database must be accessible to the public.
Official Text
The Controller may perform all or any of the following functions, namely:–
(a) exercising supervision over the activities of the Certifying Authorities;
(b) certifying public keys of the Certifying Authorities;
(c) laying down the standards to be maintained by the Certifying Authorities;
(d) specifying the qualifications and experience which employees of the Certifying Authority should possess;
(e) specifying the conditions subject to which the Certifying Authorities shall conduct their business;
(f) specifying the contents of written, printed or visual materials and advertisements that may be distributed or used in respect of a 2[electronic signature] Certificate and the public key;
(g) specifying the form and content of a 2[electronic signature] Certificate and the key;
(h) specifying the form and manner in which accounts shall be maintained by the Certifying Authorities;
(i) specifying the terms and conditions subject to which auditors may be appointed and the remuneration to be paid to them;
(j) facilitating the establishment of any electronic system by a Certifying Authority either solely or jointly with other Certifying Authorities and regulation of such systems;
(k) specifying the manner in which the Certifying Authorities shall conduct their dealings with the subscribers;
(l) resolving any conflict of interests between the Certifying Authorities and the subscribers;
(m) laying down the duties of the Certifying Authorities;
(n) maintaining a data base containing the disclosure record of every Certifying Authority containing such particulars as may be specified by regulations, which shall be accessible to public.