Every Certifying Authority shall make use of hardware, software and procedures that secure them from intrusion and misuse, adhere to security procedures to ensure that the secrecy and privacy of the digital signatures are assured and shall be the repository of all Electronic Signature Certificates issued under the IT Act.