Cyber Security
Basics of Cyber Security
Cyber Threat Landscape & Components
Cyber Threat Landscape & Components
| Cue Words | Notes |
|---|---|
| What are the key classes of cyber threats? Provide examples. |
|
| What are the six core components of a robust cybersecurity system? |
|
| Why is cybersecurity critical for national security and strategic autonomy? |
|
Cyber Crimes & Warfare: The Fifth Domain
Cyber Crimes & Warfare: The Fifth Domain
| Cue Words | Notes |
|---|---|
| Classify the different types of cybercrimes with Indian contexts. |
|
| How does Cyber Warfare differ from Traditional Warfare across key operational parameters? |
|
| What are the key foreign cyber threat actors targeting India? |
|
India's Cyber Vulnerabilities
Vulnerability Analysis & Historic Attacks
Vulnerability Analysis & Historic Attacks
| Cue Words | Notes |
|---|---|
| What are the main technical, human, and regulatory vulnerabilities in India's cyber ecosystem? |
|
| Detail major cyberattacks in India and the average cost of data breaches. |
|
Critical Information Infrastructure (CII)
Critical Information Infrastructure (CII)
| Cue Words | Notes |
|---|---|
| Define Critical Information Infrastructure (CII) and its legal protection in India. |
|
| Identify the seven key sectors designated as CII. |
|
| What is the role of NCIIPC? Specify its parent agency and year of establishment. |
|
| What are the operational challenges and way forward for protecting India's CII? |
|
Government Initiatives
Institutional and Legal Framework
Institutional and Legal Framework
| Cue Words | Notes |
|---|---|
| What is CERT-In? Detail its nodal role, parent ministry, and reporting guidelines. |
|
| What is the I4C? Specify its ministry, nodal portal, and core modules. | I4C (Indian Cybercrime Coordination Centre): - Established in 2020 under the Ministry of Home Affairs (MHA). - Acts as a comprehensive portal to fight cybercrimes, hosting the National Cybercrime Reporting Portal (Helpline 1930). - Features the National Cybercrime Threat Analytics Unit (TAU), Joint Cybercrime Investigation Team, and the National Cybercrime Forensic Laboratory. |
| Explain the key sections of the IT Act 2000 and the controversy surrounding Section 66A. |
|
| Detail the compliance requirements introduced under the IT Rules 2021 and 2023 Amendments. |
|
| Outline the core principles, duties, and penalties under the Digital Personal Data Protection (DPDP) Act, 2023. |
|
Schemes, R&D and Global Alliances
Schemes, R&D and Global Alliances
| Cue Words | Notes |
|---|---|
| What is the Cyber Surakshit Bharat Initiative? |
|
| Detail the functions of Cyber Swachhta Kendra and NCCC. |
|
| Explain the role of DCyA and NATGRID. |
|
| What is the Budapest Convention? Explain India's stance and the reasons behind it. |
|
| Identify key bilateral and multilateral alliances India uses for cyber diplomacy. |
|
Emerging Technologies & Challenges
Facial Recognition & Surveillance Backing
Facial Recognition & Surveillance Backing
| Cue Words | Notes |
|---|---|
| What is NAFRS? Detail its implementation and key concerns. |
|
| Detail the legal backing and oversight mechanism for state surveillance in India. |
|
| What is the Puttaswamy proportionality test for state surveillance? |
|
Challenges & Way Forward
Challenges & Way Forward
| Cue Words | Notes |
|---|---|
| Summarize the core structural challenges facing India's cybersecurity. |
|
| What are the key policy and institutional recommendations for a secure cyber future? |
|
Recent Developments (2025–26)
Financial & Crypto Cyber Incidents
Financial & Crypto Cyber Incidents
| Cue Words | Notes |
|---|---|
| What DDoS-related steps did banks take after FM's cybersecurity review meeting? |
|
| Detail the CoinDCX and WazirX crypto exchange breaches. |
|
Quantum Threats & Emerging Fraud Vectors
Quantum Threats & Emerging Fraud Vectors
| Cue Words | Notes |
|---|---|
| What is Harvest Now, Decrypt Later (HNDL) and why does quantum computing threaten encryption? |
|
| What is APK fraud and how is it reported/investigated in India? |
|
| Explain 2FA mechanics: TOTP, HOTP, and hardware tokens. |
|
| What legal gaps exist around cyberbullying, doxxing, and deepfake abuse in India? |
|
Recent Cyber Threats & Incidents (2025-26)
Financial, Fraud & Infrastructure Threats
Financial, Fraud & Infrastructure Threats
| Cue Words | Notes |
|---|---|
| What legal gaps exist around cyberbullying, doxxing, and deepfake abuse in India? |
|
| What is a DDoS attack and how is India's financial sector responding? | DDoS & Financial Sector: - DDoS floods a target server/network via a botnet (multiple compromised systems), unlike a single-source DoS attack. - Banks now must designate 2 senior officials — one for cyber-incident reporting, one for operational continuity (ATM cash availability) — and deploy anti-DDoS systems. - CAPTCHA-based bot-detection tools help identify and block automated traffic. |
| What are the CoinDCX and WazirX crypto breaches, and how is the US regulating stablecoins? |
|
| What is Quantum Cyber Readiness and the Harvest Now, Decrypt Later threat? |
|
| What is the APK scam, and what does the National Cyber Crime Reporting Portal (NCRP) cover? |
|
Surveillance, Anonymity & Cybercrime Geography
Surveillance, Anonymity & Cybercrime Geography
| Cue Words | Notes |
|---|---|
| How does 2FA/TOTP work, and what newer authentication methods exist? |
|
| What is GhostPairing, and how does VPN traffic create security trade-offs? |
|
| What is GPS/GNSS spoofing, and how does it differ from jamming? |
|
| Where are Southeast Asian cybercrime scam hubs located, and what is the global legal response? |
|
| How can Wi-Fi signals enable covert surveillance without network access? |
|
Revision Strategy
Master Agencies: CERT-In (2004, MeitY), NCIIPC (2014, NTRO), I4C (2020, MHA). Remember Laws: IT Act 2000 (Sections 43, 66, 69, 70), IT Rules 2021 (originator traceability), DPDP Act 2023 (₹250 cr cap, DPBI). Concepts: Fifth Domain of Warfare, APT, Zero-Day Exploit, DDoS, Proportionality Test, NAFRS. Major Attacks: WannaCry 2017, Mumbai Power Outage 2020, AIIMS Ransomware 2021. Diplomacy: Budapest Convention (India is NOT a signatory), UN GGE, SCO.
*Ultra-Fast Revision Series for UPSC CSE.*I'll read the specified section of the notes file and convert every Cyber Security, Money Laundering, Organised Crime, Terrorism, and Military/Police Operations detail into VitePress + Cornell Notes format with zero loss.The military ops are near the end of that range; I'll search the rest of the notes for CERT-In, I4C, PMLA, FATF, NIA, and UAPA.Cyber Security / PMLA / NIA content isn't in that NOTES_FILE range—only the military ops are. I'll locate the full security block in the source materials.Checking for existing Cornell security conversions and reading the I4C/UAPA sections for completeness.Confirming: Cyber Security / PMLA / NIA live in the ECO security source; NOTES_FILE 3401–4224 holds the listed operations. Converting both into zero-loss Cornell notes.# Internal Security — Cyber · Money Laundering · Organised Crime · Terrorism · Military/Police Operations
Source conversion (zero-loss):
NOTES_FILE.mdlines 4200–4224 (Military/Police Ops) + Security corpus (CERT-In, I4C, PMLA, FATF, NIA, UAPA, Organised Crime) · VitePress + Cornell Notes format
A. Cyber Security (CERT-In, I4C)
CERT-In — Status, Mandate & Key Actions
| Cue Words | Notes |
|---|---|
| What is CERT-In and under which law is it designated? |
|
| What are key CERT-In actions / advisories in the notes? |
|
| What is Cyber Swachhta Kendra? |
|
I4C — Structure, Portals & e-Zero FIR
| Cue Words | Notes |
|---|---|
| What is I4C? |
|
| What is the National Cybercrime Reporting Portal? |
|
| What rackets does I4C flag? |
|
| What is the e-Zero FIR Initiative? |
|
| What is CCTNS (linked to I4C ecosystem)? |
|
Key Cyber Threats, Frauds & Legal Provisions
| Cue Words | Notes |
|---|---|
| What is a DDoS attack? |
|
| What laws apply to cyberbullying / online abuse? |
|
| What are modern cyber frauds and Section 66D? |
|
| What is a Digital Arrest scam? |
|
| What is 2FA / TOTP? |
|
| What are APK scams, CoinDCX, and SE Asia scam hubs? |
|
| What is GPS spoofing? |
|
| What about VPN regulation and GhostPairing? |
|
| What are mule accounts and MuleHunter.AI? |
|
| What is the UN Convention against Cybercrime? |
|
B. Money Laundering (PMLA, FATF)
PMLA, 2002 — Definition, Stages, Features & ED
| Cue Words | Notes |
|---|---|
| What is money laundering under PMLA? |
|
| What are the three stages of money laundering? |
|
| What are key features of PMLA? |
|
| What is the Enforcement Directorate (ED)? |
|
FATF — Structure, Lists, India & Reports
| Cue Words | Notes |
|---|---|
| What is FATF? |
|
| What are Grey List and Black List? |
|
| What FATF cases / reports are in the notes? |
|
| What is the FATF Asset Recovery Framework? |
|
C. Organised Crime
Organised Crime — NATGRID, MAC & Network Database
| Cue Words | Notes |
|---|---|
| What is NATGRID and how does it link to organised crime? |
|
| What is the Multi Agency Centre (MAC)? |
|
| How does NIA link terrorism to organised crime? |
|
D. Terrorism (NIA, UAPA)
NIA — Origin, Mandate & Expansion
| Cue Words | Notes |
|---|---|
| Why and how was the NIA established? |
|
| What is NIA’s primary function and expanded role? |
|
| What recent NIA-related policy/events are noted? |
|
UAPA — Investigation, Bail & Chargesheet
| Cue Words | Notes |
|---|---|
| What are key UAPA investigation / chargesheet rules? |
|
| What is the UAPA bail regime (Section 43D(5))? |
|
Terror Cases — Ricin, TATP, Tech Misuse & Forensics
| Cue Words | Notes |
|---|---|
| What is ricin and how does it act? |
|
| What explosives and forensics tools are noted (Red Fort blast context)? |
|
| How was technology misused by terror suspects? |
|
E. Military / Police Operations
UPSC Prelims PYQ — Army Goodwill Operations
| Cue Words | Notes |
|---|---|
| PYQ 2024: Operations for upliftment of local population in remote areas are called? |
|
Domestic Operations — Op Sarvashakti · Op Sadbhavana · Op Sankalp
| Cue Words | Notes |
|---|---|
| What is Operation Sarvashakti (2024)? |
|
| What is Operation Sadbhavana? |
|
| What is Operation Sankalp? |
|
Other Operations — Op Sindoor · Op Mahadev · Op Thunderbolt · Op Rakshak · Op Black Tornado
| Cue Words | Notes |
|---|---|
| What is Operation Sindoor? |
|
| What is Operation Mahadev? |
|
| What is Operation Thunderbolt? |
|
| What is Operation Rakshak? |
|
| What is Operation Black Tornado? |
|
Quick Ops Matrix (Zero-loss table form)
| Operation | Lead Agency | Location / Theatre | Objective / Context |
|---|---|---|---|
| Op Sarvashakti (2024) | Indian Army | Pir Panjal (J&K) | Anti-terror flush-out of terrorists |
| Op Sadbhavana | Indian Army | J&K and Ladakh | Ongoing “Goodwill” — Army Goodwill Schools & health |
| Op Sankalp | Indian Navy | Persian Gulf & Gulf of Oman | Safety of Indian-flagged vessels |
| Op Sindoor | Indian forces | Pakistan Border Areas | Multi-domain response to Pahalgam terror incidents |
| Op Mahadev | Army / CRPF (+ J&K Police) | Kashmir | Neutralized 3 terrorists responsible for Pahalgam attack |
| Op Thunderbolt | Kerala Police (“Kerala Thunderbolts” STF) | Kerala / Western Ghats | Curb Maoist sightings |
| Op Rakshak | Indian Army | J&K / Punjab | Longest-running CI ops since 1990; curb cross-border militancy |
| Op Black Tornado | NSG | Mumbai | Neutralize terrorists in 26/11 (2008) |