Trap: Conflating IT Act (cyber crime, e-commerce) with critical infrastructure protection (NCIIPC) - different mandates
Most confused: CERT-In 2022 directions (6-hour incident reporting, KYC for VPN/VPS, clock sync) - scope and compliance burden
Key anchor: IT Act 2000 (amended 2008) + CERT-In directions 2022 + DPDP Act 2023 = current legal triad
Current affairs hook: AIIMS ransomware (2022), Air India data breach (2023), state-sponsored APT attacks (APT41, Lazarus), DPDP Act 2023 operationalisation
Mains hinge: Balancing security (CERT-In directions) vs privacy (DPDP Act) vs business ease; attribution difficulty in cyber attacks; India's strategic autonomy in cyberspace
Core Concept
India's cyber security architecture has evolved from the IT Act 2000 (e-commerce focus) to a multi-layered framework addressing critical infrastructure protection, data privacy, and strategic cyber operations - driven by escalating threats: ransomware (AIIMS, 2022), state-sponsored APTs (Chinese APT41, North Korean Lazarus), and data breaches (Air India, 2023; CoWIN leak allegations, 2023).
CERT-In Directions (April 28, 2022): Mandatory 6-hour incident reporting; KYC for VPN/VPS/cloud providers (5-year log retention); clock synchronisation with NTP (NPL/NIC); designated point of contact. Controversy: Overreach concerns, compliance burden on MSMEs, VPN providers exiting India (ExpressVPN, Surfshark). Revised FAQs (2023): Clarified "cyber incident" definition, exempted certain entities.
Digital Personal Data Protection Act, 2023 (DPDP): Consent-based processing; data fiduciary obligations; Data Protection Board; cross-border transfer rules; exemptions for state (security, sovereignty); penalties up to ₹250 cr. Not yet fully operational (rules pending).
Indian Cyber Crime Coordination Centre (I4C, MHA, 2020):
Defence Cyber Agency (DCA, 2019):
National Technical Research Organisation (NTRO):
Critical Information Infrastructure (CII)
Defined under IT Act S.70: "computer resource whose incapacitation would have debilitating impact on national security, economy, public health, safety." Sectors: Power (SCADA), Banking (CBS, SWIFT), Telecom (core network), Transport (rail signalling, ATC), Defence, Space, E-gov (Aadhaar, GSTN), Health (CoWIN, ABDM). NCIIPC mandate: Threat assessment, protection guidance, audit, incident response for CII.
Threat Landscape
Ransomware: AIIMS Delhi (Nov 2022, 1.3TB data, 2-week disruption), Oil India, SpiceJet, Solar Industries. State-sponsored APTs: APT41 (China) - power sector, telecom; Lazarus (North Korea) - crypto theft, banks; SideWinder (Pakistan) - government, defence. Data breaches: Air India (4.5M passengers, 2023), BigBasket (2020), Domino's (2021), CoWIN alleged leak (2023). Cyber crime: Phishing, KYC fraud, UPI fraud, sextortion - ₹11,000+ cr lost (2023, NCRB).
Capacity & International
Cyber Surakshit Bharat: MeitY training for CISOs. Information Security Education & Awareness (ISEA): Curriculum, certifications. Cyber Commandos: CAPF cyber units. International: Budapest Convention (India observer, not signatory - sovereignty concerns); UN GGE/OEWG (norms of responsible state behaviour); Quad Cyber Challenge; India-US Cyber Relationship Framework (2022); BIMSTEC cyber cooperation.
Treat these as original practice prompts unless a linked official UPSC paper is provided; they are not represented as verbatim PYQs.
| Type | Stage | What was tested |
|---|---|---|
| Practice | Mains | CERT-In directions 2022, privacy vs security, ransomware |
| Practice | Prelims | IT Act sections, CERT-In role, CII definition |
| Practice | Mains | Cyber security architecture, critical infrastructure, international cooperation |
| Practice | Prelims | NCIIPC, Cyber Swachhta Kendra, Budapest Convention |
| Practice | Mains | Data protection, cyber sovereignty, cyber crime trends |
Statement Elimination Guide
"CERT-In 2022 directions apply to all VPN providers globally." False. Applies to entities serving Indian users.
"India is a signatory to the Budapest Convention." False. Observer only - sovereignty/data localisation concerns.
"NCIIPC protects all government websites." False. Only notified Critical Information Infrastructure.
"DPDP Act 2023 is fully operational." False. Rules not yet notified; phased implementation expected.
"Cyber terrorism under IT Act requires foreign involvement." False. S.66F covers acts threatening India's unity, integrity, security - domestic or foreign.
"CERT-In and NCIIPC have identical mandates." False. CERT-In = national incident response; NCIIPC = CII protection.
"Intermediary safe harbour (S.79) is absolute." False. Conditional - due diligence, govt takedown orders.