Cyber Security
Basics of Cyber Security
Cyber Threat Landscape & Components
Cyber Threat Landscape & Components
| What are the key classes of cyber threats? Provide examples. | Key threat vectors: - Malware: Ransomware (WannaCry, Locky), Spyware (Pegasus), Worms, and Trojans. - Social Engineering: Phishing, Spear Phishing (highly targeted). - Infrastructure Attacks: DDoS (Traffic flooding), SQL Injection, Zero-Day exploits. - State-Sponsored Actors: Advanced Persistent Threats (APTs) like Lazarus Group (NK), APT10 (China). |
| What are the six core components of a robust cybersecurity system? | - Cyber Security Components:
|
| Why is cybersecurity critical for national security and strategic autonomy? | Need and Importance: - National Security: Protects critical infrastructure (power, dams, defense communications) and prevents cyber-terrorism. - Economic Security: Secures payment gateways (UPI, SWIFT), stock exchanges, and guards against intellectual property theft. - Social Stability: Prevents cyber-bullying, identity theft, and secures personal data. - Governance: Secures Digital India databases (Aadhaar, DigiLocker, voter registries). - Strategic Autonomy: Promotes indigenous tech stacks, reducing reliance on vulnerable foreign software/hardware. |
Cyber Crimes & Warfare: The Fifth Domain
Cyber Crimes & Warfare: The Fifth Domain
| Classify the different types of cybercrimes with Indian contexts. | Classification of Cybercrimes: - Financial Crimes: UPI/net banking fraud, card cloning/skimming, cryptocurrency theft. - Data Breaches: Aadhaar/PAN leaks, corporate espionage, medical records theft. - Social Crimes: Cyber bullying, stalking, revenge porn, and sextortion. - Against Individuals: Identity theft, online harassment, lottery/job scams. - Against Organizations: Ransomware (WannaCry), DDoS disruption, defacement. - Against Government: Critical infrastructure targets, cyber espionage, state-sponsored misinformation. |
| How does Cyber Warfare differ from Traditional Warfare across key operational parameters? | Cyber Warfare (The Fifth Domain) vs Traditional Warfare: - Attribution: Traditional is clear and unambiguous. Cyber is extremely difficult to attribute due to proxy servers/spoofing. - Geography: Traditional is bound by physical frontiers. Cyber is completely borderless. - Cost: Traditional is highly capital-intensive. Cyber has a very low entry barrier. - Speed: Traditional requires mobilization time. Cyber is instantaneous. - Casualties: Traditional results in direct physical casualties. Cyber results in economic and system disruption. - Legal Framework: Traditional is governed by Geneva Conventions. Cyber is governed by emerging, non-binding global norms. |
| What are the key foreign cyber threat actors targeting India? | Hostile State Actors: - China: APT groups (APT1, APT10) targeting power grids and space institutions. - Pakistan: Inter-Services Intelligence (ISI) cyber cells pushing malware and fake news. - North Korea: Lazarus Group conducting ransomware and crypto-heists for state revenue. |
India's Cyber Vulnerabilities
Vulnerability Analysis & Historic Attacks
Vulnerability Analysis & Historic Attacks
| What are the main technical, human, and regulatory vulnerabilities in India's cyber ecosystem? | Key Vulnerabilities: - Infrastructure & Technical: Outdated legacy software in government offices, poor patch management, and high import dependence for hardware/chips (supply chain risk). - Human Factors: Low digital literacy, weak passwords, susceptibility to social engineering, and a severe shortage of skilled cyber professionals. - Organizational: Inadequate cybersecurity budgets, lack of periodic third-party audits, and poor incident response systems. - Legal & Regulatory: Slow judicial processes under the outdated IT Act (2000) leading to low conviction rates. |
| Detail major cyberattacks in India and the average cost of data breaches. | Major Incidents & Statistics: - 2020 Mumbai Power Outage: Suspected Chinese malware targeted SCADA systems, causing grid failure. - 2021 AIIMS Ransomware: Encrypted critical patient databases, disrupting healthcare delivery for weeks. - Aadhaar & CoWIN leaks: Recurrent security alerts over the exposure of personal data of millions. - 2016 Debit Card Hack: Compromised 3.2 million debit cards across major Indian banks. - Statistics: India ranks as the 3rd most targeted country globally. The average cost of a data breach in India is estimated at ₹17.9 crore. |
Critical Information Infrastructure (CII)
Critical Information Infrastructure (CII)
| Define Critical Information Infrastructure (CII) and its legal protection in India. | - CII Definition: Under Section 70 of the IT Act 2000, CII is defined as any computer resource, the destruction or disruption of which would have a debilitating impact on national security, economy, public health, or safety. |
| Identify the seven key sectors designated as CII. | - Designated CII Sectors:
|
| What is the role of NCIIPC? Specify its parent agency and year of establishment. | - NCIIPC: Established in 2014 under Section 70A of the IT Act. It functions under the National Technical Research Organisation (NTRO) as the national nodal agency for protecting Critical Information Infrastructure. |
| What are the operational challenges and way forward for protecting India's CII? | CII Protection Strategy: - Challenges: Securing legacy OT/SCADA systems, supply-chain vulnerabilities, and coordinate gaps between private and public operators. - Way Forward: Mandate **Air-Gapping** for nuclear/grid controls, establish redundancy (backups), conduct mandatory third-party audits, and create Public-Private Partnerships for threat sharing. |
Government Initiatives
Institutional and Legal Framework
Institutional and Legal Framework
| What is CERT-In? Detail its nodal role, parent ministry, and reporting guidelines. | CERT-In (Indian Computer Emergency Response Team): - Established in 2004 under the Ministry of Electronics and Information Technology (MeitY). - It is the national nodal agency for responding to computer security incidents, running situational alerts, and issuing threat advisories. - UPSC Trap Under 2022 guidelines, CERT-In mandates all entities to report cyber incidents within 6 hours of detection. |
| What is the I4C? Specify its ministry, nodal portal, and core modules. | I4C (Indian Cybercrime Coordination Centre): - Established in 2020 under the Ministry of Home Affairs (MHA). - Acts as a comprehensive portal to fight cybercrimes, hosting the National Cybercrime Reporting Portal (Helpline 1930). - Features the National Cybercrime Threat Analytics Unit (TAU), Joint Cybercrime Investigation Team, and the National Cybercrime Forensic Laboratory. |
| Explain the key sections of the IT Act 2000 and the controversy surrounding Section 66A. | IT Act 2000 Key Sections: - Section 43: Penalty for damage to computer system/unauthorized access. - Section 66: Computer-related offenses (hacking, data theft). - Section 66A: Punishment for sending offensive messages (Struck down by SC in Shreya Singhal vs Union of India (2015) for violating Article 19(1)(a)). - Section 69: Government power to intercept, monitor, or decrypt information. - Section 70: Legal declaration of Protected Systems (CII). |
| Detail the compliance requirements introduced under the IT Rules 2021 and 2023 Amendments. | IT Rules 2021 & 2023: - Traceability: Obligates messaging platforms to identify the first originator of a message. - SSMIs: Significant Social Media Intermediaries (5M+ users) must appoint a Chief Compliance Officer, Resident Grievance Officer, and Nodal Contact Person. - Grievance Appellate Committees (GACs): 2023 amendment set up government panels to hear user appeals against intermediary content moderation decisions. |
| Outline the core principles, duties, and penalties under the Digital Personal Data Protection (DPDP) Act, 2023. | DPDP Act 2023: - Constitutional Basis: Rooted in Article 21 (Right to Privacy) following the K.S. Puttaswamy judgment. - Entities: Identifies the Data Principal (individual) and Data Fiduciary (data processor). - Core Principles: Informed consent, purpose limitation, storage limitation, and data minimization. - Data Protection Board of India (DPBI): Set up as the independent, digital-first adjudicatory body. - SDFs: Significant Data Fiduciaries face higher compliance (data impact assessments, independent audits). - Penalties: Graded financial penalties capped at ₹250 crore for failure to prevent data breaches. - Mains Critique: Broad exemptions granted to state agencies on sovereignty/security grounds, lack of data portability rights, and potential dilute of the RTI Act. |
Schemes, R&D and Global Alliances
Schemes, R&D and Global Alliances
| What is the Cyber Surakshit Bharat Initiative? | - Cyber Surakshit Bharat (2018): Launched by MeitY in partnership with industry leaders to spread awareness about cyber hygiene and train Chief Information Security Officers (CISOs) in government departments. |
| Detail the functions of Cyber Swachhta Kendra and NCCC. | Defense Tools & Monitoring: - Cyber Swachhta Kendra: Botnet cleaning and malware analysis center, providing free malware detection tools to citizens. - NCCC (National Cyber Coordination Centre): Under MeitY; performs metadata-level scanning to provide real-time situational awareness of cyber threats. |
| Explain the role of DCyA and NATGRID. | Special Agencies: - Defense Cyber Agency (DCyA): Tri-service command responsible for offensive and defensive military operations in cyberspace. - NATGRID: A centralized intelligence-sharing platform connecting 21 databases of security and intelligence agencies. |
| What is the Budapest Convention? Explain India's stance and the reasons behind it. | Budapest Convention on Cybercrime (2001): - The first international treaty addressing computer crimes by harmonizing national laws. - UPSC Trap India is NOT a signatory. - Stance: India argues the convention was drafted without its participation, conflicts with national sovereignty (allows foreign agencies cross-border access to data without local warrants), and advocates instead for a UN-led multilateral framework. |
| Identify key bilateral and multilateral alliances India uses for cyber diplomacy. | Cyber Diplomacy: - UN GGE: Participates in establishing voluntary norms for state behavior. - SCO & BRICS: Cooperative cyber-drills and joint ICT security working groups. - Bilateral Joint Working Groups: Active frameworks with the US (US-India Cyber Dialogue), Japan, Israel, and the UK for real-time intelligence sharing. |
Emerging Technologies & Challenges
Facial Recognition & Surveillance Backing
Facial Recognition & Surveillance Backing
| What is NAFRS? Detail its implementation and key concerns. | NAFRS (National Automated Facial Recognition System): - Implemented by the NCRB (National Crime Records Bureau) to create a centralized database of photographs for matching against CCTV feeds. - Benefits: Speeds up criminal tracking, search for missing children, and border verification. - Concerns: High risk of mass surveillance, high false-positive rates (especially for women/minorities), lack of explicit user consent, and functioning in a legislative vacuum without dedicated FRT laws. |
| Detail the legal backing and oversight mechanism for state surveillance in India. | Surveillance Framework: - Legal Backing: Section 69 of the IT Act (for digital intercepts) and the Indian Telegraph Act 1885 (for phone tapping). - Authorization: Interception orders must be signed by the Union Home Secretary (Centre) or State Home Secretary (States). - Oversight: Orders are subject to review by a cabinet-level Review Committee to prevent arbitrary misuse. - Pegasus Controversy (2021): Highlighted vulnerabilities regarding zero-click commercial spyware targeting civil society, reinforcing the need for independent judicial warrant systems. |
| What is the Puttaswamy proportionality test for state surveillance? | - Proportionality Test (Puttaswamy 2017): State surveillance must satisfy four criteria:
|
Challenges & Way Forward
Challenges & Way Forward
| Summarize the core structural challenges facing India's cybersecurity. | Key Challenges: - Technical: Extreme hardware import dependency, lack of native OS/chip fabrication, and slow adoption of quantum-safe encryption. - Skill Deficit: Shortage of estimated 1 million cybersecurity professionals; brain drain of top talent. - Prosecution: Low conviction rate in cybercrimes (below 5%) due to poor forensic collection and police training. - International: Borderless nature of attacks and safe havens in hostile nations make prosecution almost impossible. |
| What are the key policy and institutional recommendations for a secure cyber future? | Way Forward Actions: - Policy: Enact a unified National Cyber Security Strategy (updating the 2013 Policy), and include safe harbor protections for ethical security researchers. - Institutional: Create a single-command National Cyber Security Agency (NCSA) to streamline actions across CERT-In, MHA, and Defense. - Capacity: Fund cybersecurity academies in IITs/NITs, mandate cyber hygiene education in schools, and set up state-level cyber forensics laboratories. - Technology: Incentivize indigenous hardware and software fabrication (Security-by-Design), launch national bug bounty programs, and build quantum-key distribution networks. |
Revision Strategy
Master Agencies: CERT-In (2004, MeitY), NCIIPC (2014, NTRO), I4C (2020, MHA). Remember Laws: IT Act 2000 (Sections 43, 66, 69, 70), IT Rules 2021 (originator traceability), DPDP Act 2023 (₹250 cr cap, DPBI). Concepts: Fifth Domain of Warfare, APT, Zero-Day Exploit, DDoS, Proportionality Test, NAFRS. Major Attacks: WannaCry 2017, Mumbai Power Outage 2020, AIIMS Ransomware 2021. Diplomacy: Budapest Convention (India is NOT a signatory), UN GGE, SCO.
💻 Cyber Security: The Fifth Domain
- 🏙️ Focus: Threat vectors, incident response, and legal frameworks.
- 🧱 Markers: CERT-In + NCIIPC + Zero-Day + DPDPA 2023 + IT Act. ✅
1. Cyber Threat Landscape
- 🦠 Malware:
- Ransomware: Encrypts data (e.g., WannaCry, Locky). ✅
- Spyware: Steals info (Pegasus). ✅
- Trojans: Disguised as legit software. ✅
- 🎯 Advanced Persistent Threats (APT): State-sponsored, long-term targeted (e.g., APT10, Lazarus). ✅
- 🚪 Zero-Day Exploit: Unknown vulnerability; no patch available. High danger. ✅
- 🌊 DDoS: Overwhelming systems with traffic to crash them. ✅
- 🎣 Phishing: Fraudulent messages for credentials. Spear Phishing is targeted. ✅
2. Institutional Framework (India)
- 🛡️ CERT-In (2004):
- Ministry: MeitY.
- Role: Nodal agency for incident response. 6-hour mandatory reporting. ✅
- 🧱 NCIIPC (2014):
- Parent: NTRO.
- Role: Protects Critical Information Infrastructure (CII) (Power, Banking, Telecom). ✅
- 🏢 I4C (2020):
- Ministry: MHA.
- Role: Cybercrime coordination; National Cyber Crime Reporting Portal (1930). ✅
- ⚔️ Defence Cyber Agency (DCyA): Tri-service command under Chief of Defense Staff (CDS) for offensive and defensive military cyber operations. ✅
- 📱 Sanchar Saathi & Chakshu Portal: DoT portal for citizens to report fraud calls/messages (Chakshu) and block lost phones (CEIR). ✅
- 🧱 NCRF (National Cybersecurity Reference Framework): Guidelines by NCIIPC defining governance for IT & Operational Technology (OT) networks. ✅
- 🔗 NATGRID: Centralized intelligence platform connecting 21 sovereign databases. ✅
- 🧹 Cyber Swachhta Kendra: Botnet cleaning and malware analysis portal. ✅
3. Legal & Regulatory
- 📜 IT Act 2000:
- Sec 66F: Cyber Terrorism (Life imprisonment). ✅
- Sec 69: Govt power to intercept. ✅
- Sec 70: Protected systems (CII). ✅
- Sec 79: Safe harbor for intermediaries. ✅
- 📱 IT Rules 2021: Traceability of 1st originator; SSMI (5M+ users) compliance. ✅
- 🧬 DPDPA 2023:
- Constitutional Basis: SC Puttaswamy judgment (Article 21 Right to Privacy).
- Parties: Data Principal (individual) and Data Fiduciary (processor).
- SDF (Significant Data Fiduciary): Large entities subject to strict third-party audits and data impact assessments.
- DPBI: Data Protection Board of India (digital-first enforcement body).
- Exemptions: Central government can exempt state agencies on sovereignty/security grounds.
- Penalties: Graded monetary fines capped at ₹250 crore for failing to prevent data breaches. ✅
4. Top UPSC Traps
- ❌ CERT-In: It is NOT under MHA (under MeitY). ✅
- ❌ NCIIPC: It is NOT under MeitY (under NTRO). ✅
- ❌ Sec 66A: NOT valid (Struck down in 2015 by SC). ✅
- ❌ CII: Disruption results in "debilitating impact" on national security. ✅
- ❌ Budapest Convention: India is NOT a signatory. ✅
Ultra-Fast Revision Series for UPSC CSE.