Trap: Confusing CERT-In (operational incident response) with NCIIPC (critical infrastructure protection) and NSCS (strategic policy). CERT-In = national incident response; NCIIPC = designated CII protection; NSCS = apex policy coordination.
Most confused: IT Act 2000 (amended 2008) vs DPDP Act 2023. IT Act = cybercrime, e-commerce, intermediary liability. DPDP Act = personal data protection, consent, data fiduciary duties. They overlap but serve different purposes.
Key anchor: The 'Protected System' designation under Section 70 IT Act - only NCIIPC can notify Critical Information Infrastructure (CII). Any unauthorised access = 10 years imprisonment. This is the legal backbone of CII protection.
Current affairs hook: 2024 - CERT-In's 6-hour incident reporting directive (April 2022) enforced with penalties; Digital Personal Data Protection Act (Aug 2023) rules notified 2024; National Cyber Security Strategy (2024) released; AIIMS ransomware (2022), SolarWinds/Sunburst impact on Indian entities; AI deepfakes in elections (2024).
Mains hinge: Frame as 'capability vs threat asymmetry'. India is a top-3 digital economy (UPI, Aadhaar, DPI) but faces state-sponsored APTs (APT41, Lazarus, SideWinder), ransomware-as-a-service, and supply chain vulnerabilities. The response must integrate legal (DPDP), institutional (CERT-In/NCIIPC), technical (SOCs), and diplomatic (Budapest Convention, UN OEWG) layers.
CERT-In's 6-hour incident reporting mandate comes under which Section? (70B IT Act)
2023
Mains
"India's cyber security architecture is fragmented across multiple agencies." Critically examine.
2022
Prelims
NCIIPC is designated to protect which infrastructure? (Critical Information Infrastructure)
2021
Mains
What are the key features of the Information Technology (Intermediary Guidelines) Rules, 2021?
2020
Prelims
The Budapest Convention relates to: Cybercrime
2019
Mains
Discuss the potential of cyber attacks on critical infrastructure. Suggest measures.
Statement Elimination Guide
Correct: "CERT-In is the national nodal agency for cyber incident response under Section 70B of the IT Act."
False: "NCIIPC operates under the Ministry of Electronics and IT." (It operates under NTRO, which reports to PMO)
Trap: "The DPDP Act 2023 applies to all personal data processing in India, including offline data." (False - only digital personal data; offline digitised later is covered)
Correct: "Section 70 of the IT Act empowers NCIIPC to declare 'Protected Systems' - unauthorised access attracts 10 years imprisonment."
False: "India is a signatory to the Budapest Convention on Cybercrime." (India has not signed - sovereignty, data localisation concerns)
Correct: "The Digital Personal Data Protection Act 2023 provides for a Data Protection Board of India as an adjudicatory body."
Current Affairs Hook
2024-25 Developments:
National Cyber Security Strategy 2024 released (successor to 2013 policy) - 6 pillars, 5-year roadmap
DPDP Rules 2024 notified - consent manager framework, children's data (verifiable parental consent), significant data fiduciary criteria
CERT-In 6-hour reporting: Enforcement notices sent to non-compliant entities; VPN/VPS providers required to maintain logs
Internal Security (GS 3): Cyber terrorism, critical infrastructure protection, radicalisation online, dark web (drugs, weapons)
Science & Tech (GS 3): AI/ML in cyber defence, quantum cryptography (QKD), blockchain for identity, 5G/6G security
Polity (GS 2): Right to Privacy (Puttaswamy), DPDP Act, intermediary liability (Shreya Singhal), surveillance reform
International Relations (GS 2): Budapest Convention, UN OEWG/GGE norms, QUAD cyber, ASEAN cyber cooperation, cyber diplomacy
Economy (GS 3): Fintech security (UPI, CBDC), crypto regulation, digital lending guidelines, cost of cybercrime (GDP impact)
Ethics (GS 4): Ethical hacking, vulnerability disclosure, AI ethics in surveillance, data colonialism
Common Mistakes
"CERT-In and NCIIPC do the same thing." False. CERT-In = incident response for ALL cyber incidents. NCIIPC = PROTECTION of designated Critical Information Infrastructure only.
"IT Act 2000 covers data privacy." Partially. Section 43A/72A (added 2008) had limited privacy provisions. DPDP Act 2023 is the comprehensive privacy law.
"Protected System = any government server." False. Only systems NOTIFIED by NCIIPC under Section 70 IT Act are 'Protected Systems'.
"India signed the Budapest Convention." False. India participated in negotiations but didn't sign - concerns over Article 32b (transborder access) and sovereignty.
"Cyber security is only a technical issue." UPSC frames it as governance, legal, diplomatic, and strategic - not just firewalls.