Trap: Confusing CERT-In (operational incident response) with NCIIPC (critical infrastructure protection) and NSCS (strategic policy). CERT-In = national incident response; NCIIPC = designated CII protection; NSCS = apex policy coordination.
Most confused: IT Act 2000 (amended 2008) vs DPDP Act 2023. IT Act = cybercrime, e-commerce, intermediary liability. DPDP Act = personal data protection, consent, data fiduciary duties. They overlap but serve different purposes.
Key anchor: The 'Protected System' designation under Section 70 IT Act - only NCIIPC can notify Critical Information Infrastructure (CII). Any unauthorised access = 10 years imprisonment. This is the legal backbone of CII protection.
Current affairs hook: 2024 - CERT-In's 6-hour incident reporting directive (April 2022) enforced with penalties; Digital Personal Data Protection Act (Aug 2023) rules notified 2024; National Cyber Security Strategy (2024) released; AIIMS ransomware (2022), SolarWinds/Sunburst impact on Indian entities; AI deepfakes in elections (2024).
Mains hinge: Frame as 'capability vs threat asymmetry'. India is a top-3 digital economy (UPI, Aadhaar, DPI) but faces state-sponsored APTs (APT41, Lazarus, SideWinder), ransomware-as-a-service, and supply chain vulnerabilities. The response must integrate legal (DPDP), institutional (CERT-In/NCIIPC), technical (SOCs), and diplomatic (Budapest Convention, UN OEWG) layers.
Treat these as original practice prompts unless a linked official UPSC paper is provided; they are not represented as verbatim PYQs.
| Type | Stage | What was tested |
|------|-------|-----------------|
| Practice | Prelims | CERT-In's 6-hour incident reporting mandate comes under which Section? (70B IT Act) |
| Practice | Mains | "India's cyber security architecture is fragmented across multiple agencies." Critically examine. |
| Practice | Prelims | NCIIPC is designated to protect which infrastructure? (Critical Information Infrastructure) |
| Practice | Mains | What are the key features of the Information Technology (Intermediary Guidelines) Rules, 2021? |
| Practice | Prelims | The Budapest Convention relates to: Cybercrime |
| Practice | Mains | Discuss the potential of cyber attacks on critical infrastructure. Suggest measures. |
Statement Elimination Guide
Correct: "CERT-In is the national nodal agency for cyber incident response under Section 70B of the IT Act."
False: "NCIIPC operates under the Ministry of Electronics and IT." (It operates under NTRO, which reports to PMO)
Trap: "The DPDP Act 2023 applies to all personal data processing in India, including offline data." (False - only digital personal data; offline digitised later is covered)
Correct: "Section 70 of the IT Act empowers NCIIPC to declare 'Protected Systems' - unauthorised access attracts 10 years imprisonment."
False: "India is a signatory to the Budapest Convention on Cybercrime." (India has not signed - sovereignty, data localisation concerns)
Correct: "The Digital Personal Data Protection Act 2023 provides for a Data Protection Board of India as an adjudicatory body."
Current Affairs Hook
2024-25 Developments:
National Cyber Security Strategy 2024 released (successor to 2013 policy) - 6 pillars, 5-year roadmap
DPDP Rules 2024 notified - consent manager framework, children's data (verifiable parental consent), significant data fiduciary criteria
CERT-In 6-hour reporting: Enforcement notices sent to non-compliant entities; VPN/VPS providers required to maintain logs
Internal Security (GS 3): Cyber terrorism, critical infrastructure protection, radicalisation online, dark web (drugs, weapons)
Science & Tech (GS 3): AI/ML in cyber defence, quantum cryptography (QKD), blockchain for identity, 5G/6G security
Polity (GS 2): Right to Privacy (Puttaswamy), DPDP Act, intermediary liability (Shreya Singhal), surveillance reform
International Relations (GS 2): Budapest Convention, UN OEWG/GGE norms, QUAD cyber, ASEAN cyber cooperation, cyber diplomacy
Economy (GS 3): Fintech security (UPI, CBDC), crypto regulation, digital lending guidelines, cost of cybercrime (GDP impact)
Ethics (GS 4): Ethical hacking, vulnerability disclosure, AI ethics in surveillance, data colonialism
Common Mistakes
"CERT-In and NCIIPC do the same thing." False. CERT-In = incident response for ALL cyber incidents. NCIIPC = PROTECTION of designated Critical Information Infrastructure only.
"IT Act 2000 covers data privacy." Partially. Section 43A/72A (added 2008) had limited privacy provisions. DPDP Act 2023 is the comprehensive privacy law.
"Protected System = any government server." False. Only systems NOTIFIED by NCIIPC under Section 70 IT Act are 'Protected Systems'.
"India signed the Budapest Convention." False. India participated in negotiations but didn't sign - concerns over Article 32b (transborder access) and sovereignty.
"Cyber security is only a technical issue." UPSC frames it as governance, legal, diplomatic, and strategic - not just firewalls.