Cyber Security
Concepts (6)
This is a type of malware that kidnaps your data. It encrypts your files so you cannot open them. The attacker then asks for a 'ransom' payment to provide the unlock key.
This is a type of malware that kidnaps your data. It encrypts your files so you cannot open them. The attacker then asks for a 'ransom' payment to provide the unlock key. This payment is usually demanded in Bitcoin to keep the attacker's identity hidden. A famous example is the 'WannaCry' attack which hit hospitals and banks globally.
The Digital Personal Data Protection Act 2023 regulates digital personal data processing, ensuring individual privacy rights, imposing obligations on data fiduciaries, and establishing a Data Protecti
The Digital Personal Data Protection (DPDP) Act, 2023, assented to by the President of India, marks a significant legislative step towards safeguarding individual privacy in the digital age. It aims to regulate the processing of digital personal data within India, ensuring individuals' right to protect their data while recognizing the need for processing such data for lawful purposes. The Act applies to the processing of digital personal data within India, whether collected in digital form or subsequently digitized. It also extends its reach to personal data processed outside India if such processing is for offering goods or services to Data Principals within India. However, it does not apply to personal data processed for any personal purpose or data made publicly available by the Data Principal themselves.
Key provisions define 'Data Fiduciaries' as entities (persons, companies, government bodies) determining the purpose and means of processing personal data, and 'Data Principals' as individuals to whom the personal data relates. The Act outlines clear obligations for Data Fiduciaries regarding data processing, including collection, storage, and other operations, and specifies the rights and duties of Data Principals. A crucial aspect is the imposition of financial penalties for breaches of these rights, duties, and obligations, aiming to enforce compliance effectively. The Act mandates that Data Fiduciaries ensure the security of personal data, process it lawfully, and erase it once the purpose has been met or retention is no longer legally necessary. It also provides for the establishment of the Data Protection Board of India (DPBI) to monitor compliance, impose penalties, and address grievances, with appeals against its decisions lying with the Telecom Disputes Settlement and Appellate Tribunal (TDSAT).
For Prelims, understanding the definitions of Data Fiduciary, Data Principal, the DPDP Act's applicability/non-applicability, and the functions of DPBI are critical. Mains essays can explore the balance between individual privacy and national security, the impact on digital economy and startups, and the challenges in implementing such a comprehensive framework.
The Digital Personal Data Protection (DPDP) Act, 2023, is a landmark legislation in India, rooted in the Supreme Court's 2017 Puttaswamy judgment that recognized privacy as a fundamental right. It supersedes earlier attempts like the Personal Data Protection Bill, 2019, adopting a principles-based approach rather than a rigid, prescriptive one. The Act's core revolves around the concept of 'consent,' mandating that personal data can only be processed for a lawful purpose for which the Data Principal has given or is deemed to have given consent. This consent must be free, specific, informed, unconditional, and unambiguous, clearly outlining the purpose of processing.
Rights and Duties of Data Principals: Individuals (Data Principals) are empowered with several rights, including the right to obtain information about data processing, seek correction and erasure of their personal data, and avail grievance redressal. They also have the right to nominate a person to exercise these rights in case of death or incapacity. Crucially, the Act also imposes duties on Data Principals, such as refraining from filing false or frivolous complaints, with penalties up to Rs 10,000 for violations.
Obligations of Data Fiduciaries: Beyond obtaining consent, Data Fiduciaries are obligated to implement reasonable security safeguards to prevent data breaches, ensure data accuracy, and erase personal data as soon as its purpose is met and retention is not legally necessary. They must also establish a readily available grievance redressal mechanism.
Significant Data Fiduciaries (SDFs): The Act introduces a category of 'Significant Data Fiduciaries' (SDFs), which the Central Government may notify based on factors like the volume and sensitivity of data processed, risk to Data Principal rights, potential impact on India's sovereignty and integrity, security of the State, risk to electoral democracy, and public order. SDFs face additional obligations, including appointing a Data Protection Officer (DPO) based in India, an independent Data Auditor, and undertaking Data Protection Impact Assessments.
Exemptions: The Act provides specific exemptions where certain rights of Data Principals and obligations of Data Fiduciaries (except data security) may not apply. These include processing by notified agencies in the interest of security, sovereignty, and public order; for research, archiving, or statistical purposes; for startups or other notified categories; to enforce legal rights and claims; for prevention and investigation of offenses; and to perform judicial or regulatory functions. The Central Government also retains the power to exempt certain activities in the interest of security and public order.
Processing of Children's Data: Special provisions apply to children's data, prohibiting Data Fiduciaries from undertaking processing that is likely to cause harm to a child or engage in tracking, behavioral monitoring, or targeted advertising directed at children.
Data Protection Board of India (DPBI): The DPBI, to be established by the Central Government, is a quasi-judicial body responsible for monitoring compliance, imposing financial penalties (up to Rs 500 crore per instance), directing Data Fiduciaries to take necessary measures in case of data breaches, and hearing grievances. Its members are appointed for two years and are eligible for re-appointment, with appeals against its decisions lying with the TDSAT.
Comparison and Mains Angles: The DPDP Act, 2023, reflects India's unique approach to data governance, emphasizing 'Accountable Portability over Rigid Localisation,' as highlighted in the Economic Survey. Unlike some jurisdictions that mandate data localization, India's framework aims to preserve openness to cross-border data flows while ensuring regulatory oversight and enforceability over large-scale processing of Indian personal data, irrespective of where it occurs. This approach seeks to promote domestic value retention and India's AI capabilities without stifling innovation or investment. Mains essays can delve into the challenges of implementing the Act, particularly concerning the capacity of the DPBI, balancing national security exemptions with individual rights, ensuring effective grievance redressal for a vast population, and its implications for India's digital economy and global data flow dynamics. The Act's success will depend on robust enforcement, clear regulations, and continuous adaptation to evolving technological landscapes.
CERT-In under IT Act 2000 governs cyber security; India's 2022 directive mandates 6-hour incident reporting including for VPN providers.
Key Facts
- CERT-In (Indian Computer Emergency Response Team) established under Section 70B of IT Act 2000 is the nodal agency for cybersecurity incident response [Source: IT Act 2000]
- CERT-In's 2022 directive requires mandatory reporting of cyber incidents within 6 hours - among the strictest globally [Source: CERT-In Directive 2022]
In India, which law makes it mandatory for service providers, data centres, and body corporates to report cybersecurity incidents?
Section 70B of the Information Technology Act, 2000 provides for the establishment of CERT-In (Indian Computer Emergency Response Team). The IT (CERT-In and Manner of Performing Functions and Duties) Rules, 2013 mandated cybersecurity incident reporting. In 2022, CERT-In issued new directives requiring mandatory reporting within 6 hours of detecting cyber incidents - one of the strictest reporting timelines globally. Service providers, intermediaries, data centres, and body corporates are all covered under this mandatory reporting regime.
What is India's National Cyber Security Policy and what are its key objectives?
India's National Cyber Security Policy 2013 (NCSP 2013) aimed to create a secure cyber ecosystem with 5 pillars: (1) Creating a secure cyber ecosystem; (2) Creating assurance framework; (3) Encouraging open standards; (4) Strengthening regulatory framework; (5) Creating mechanisms for early warning and vulnerability management. A revised National Cyber Security Strategy 2020 was drafted but not officially released. CERT-In under MEITY is the nodal agency. The National Critical Information Infrastructure Protection Centre (NCIIPC) under NTRO protects critical information infrastructure.
What is a Virtual Private Network (VPN) and what are its legitimate and controversial uses?
A VPN creates an encrypted tunnel between a user and a server, allowing secure remote access to an organization's network over public internet while hiding the user's IP address and encrypting traffic. Legitimate uses include: secure remote work, protecting data on public Wi-Fi, and bypassing geographical restrictions. India's 2022 CERT-In directive required VPN providers to store user data for 5 years and report incidents within 6 hours, leading some major VPN providers to shut India servers. This created controversy around privacy vs security trade-offs.
What is the significance of zero-day vulnerabilities in cyber warfare and how do they relate to state-sponsored attacks?
A zero-day vulnerability is a software flaw unknown to the developer (vendor), giving attackers a 'zero days' head start before a patch exists. EternalBlue, which powered WannaCry, was a zero-day exploit developed by the NSA and later leaked by the Shadow Brokers group. State-sponsored cyber actors (like Lazarus Group linked to North Korea, APT28/Fancy Bear linked to Russia) stockpile zero-days as strategic weapons. India's NCIIPC monitors threats to critical information infrastructure, while CERT-In coordinates vulnerability disclosure through a coordinated vulnerability disclosure policy.
Common Mistakes
- Students assume CERT-In was newly created; it has existed under IT Act 2000 (Section 70B) but gained prominence through 2022 expanded directives
PYQ Patterns
- UPSC 2018: Law and regulatory body linkage
CERT-In under IT Act 2000 governs cyber security; India's 2022 directive mandates 6-hour incident reporting including for VPN providers.
Key Facts
- National Critical Information Infrastructure Protection Centre (NCIIPC) under NTRO protects critical information infrastructure [Source: IT Amendment Act 2008]
- UPSC 2018 PYQ: Cyber security applications include mobile phone operations and power grid control (not just banking) [Source: UPSC 2018 PYQ]
What are the applications of cyber security beyond just banking and internet, as tested in UPSC?
Cyber security is critical for: (1) Mobile phone operations - protecting personal data and preventing malware on smartphones; (2) Power grid control - Industrial Control Systems (ICS/SCADA) managing power infrastructure are vulnerable to cyberattacks that could cause blackouts; (3) Critical infrastructure including railways, aviation, nuclear facilities; (4) Defence networks; (5) Healthcare systems. The UPSC 2018 PYQ highlighted that banking operations are a financial security concern, while mobile operations and power grid control are core cyber security applications. Stuxnet worm (2010) demonstrated cyber weapons' power against nuclear infrastructure.
What is India's National Cyber Security Policy and what are its key objectives?
India's National Cyber Security Policy 2013 (NCSP 2013) aimed to create a secure cyber ecosystem with 5 pillars: (1) Creating a secure cyber ecosystem; (2) Creating assurance framework; (3) Encouraging open standards; (4) Strengthening regulatory framework; (5) Creating mechanisms for early warning and vulnerability management. A revised National Cyber Security Strategy 2020 was drafted but not officially released. CERT-In under MEITY is the nodal agency. The National Critical Information Infrastructure Protection Centre (NCIIPC) under NTRO protects critical information infrastructure.
What is the significance of zero-day vulnerabilities in cyber warfare and how do they relate to state-sponsored attacks?
A zero-day vulnerability is a software flaw unknown to the developer (vendor), giving attackers a 'zero days' head start before a patch exists. EternalBlue, which powered WannaCry, was a zero-day exploit developed by the NSA and later leaked by the Shadow Brokers group. State-sponsored cyber actors (like Lazarus Group linked to North Korea, APT28/Fancy Bear linked to Russia) stockpile zero-days as strategic weapons. India's NCIIPC monitors threats to critical information infrastructure, while CERT-In coordinates vulnerability disclosure through a coordinated vulnerability disclosure policy.
Common Mistakes
- Students confuse 'cybersecurity' applications - the UPSC 2018 PYQ answer was mobile operations (1) and power grid (3), NOT banking (2), because banking falls under financial security, not directly cyber security infrastructure protection
PYQ Patterns
- UPSC 2018: Application identification
Phishing is a trick to steal sensitive data. Attackers send fake emails or messages that look like they come from a trusted source, such as a bank. These messages often ask you to click a link or enter your login details.
Phishing is a trick to steal sensitive data. Attackers send fake emails or messages that look like they come from a trusted source, such as a bank. These messages often ask you to click a link or enter your login details. Once you provide the info, the attacker uses it to access your accounts. Always check the sender's email address carefully.
Malware stands for malicious software. It is a broad term for programs that damage your device or steal data. Examples include viruses, worms, and spyware. A virus attaches itself to a file and spreads when the file is opened.
Malware stands for malicious software. It is a broad term for programs that damage your device or steal data. Examples include viruses, worms, and spyware. A virus attaches itself to a file and spreads when the file is opened. Spyware secretly watches your activity to steal passwords. Trojan horses look like safe programs but hide a virus inside.
Ready to practice? Start an interactive lesson.
Start Lesson: Ransomware