Cyber Security and Digital Public Infrastructure: Notes
Exam notes on cyber security and digital public infrastructure: attacks, defences, the IT Act 2000, CERT-In, NCIIPC, the 2023 data law and India Stack.
By GK24 Editorial Team· Published · 5 min read

Cyber security is the protection of computers, networks and the data they hold from unauthorised access, damage and disruption, and digital public infrastructure is the set of open, population-scale digital systems a state builds so that identity, payments and data can be used by everyone. The two subjects now appear together in examinations because India's digital systems reach hundreds of millions of people, and the law and the agencies that protect them are examinable facts. This note covers the attacks, the defences, the law, the agencies and the building blocks of India's digital public infrastructure.
The goals of security and the common attacks
Security is built around three goals, remembered as the CIA triad: confidentiality, so that only authorised persons can read data; integrity, so that data is not altered without authority; and availability, so that a system works when it is needed. The attacks that break them have names that are regularly asked. Malware is the family term, and within it a virus attaches itself to a file and needs that file to be run, a worm spreads by itself across a network, a trojan hides inside an apparently useful program, ransomware encrypts a victim's files and demands payment, and spyware and a keylogger quietly record what is typed. Phishing is a fraudulent message that imitates a bank or an office to make the reader give up a password or a card number; by telephone it is called vishing and by text message smishing. A denial of service attack floods a server with requests so that genuine users cannot reach it, and when the flood comes from many machines at once it is a distributed denial of service. Other standard terms are spoofing, in which an address is faked, a man-in-the-middle attack, in which traffic is intercepted, SQL injection against a database and a zero-day exploit, which uses a flaw before a patch exists.
The defences
A firewall filters traffic between a network and the outside; an intrusion detection system watches for suspicious patterns. Encryption converts readable text into cipher text, and it is of two kinds: symmetric encryption uses one shared key, while asymmetric or public key encryption uses a public key to encrypt and a private key to decrypt. A digital signature reverses the order, signing with the private key so that anyone with the public key can verify the sender, and it is the basis of legal recognition of electronic records in India. Under section 17 of the Information Technology Act the Controller of Certifying Authorities licenses the Certifying Authorities that issue digital signature certificates. A hash function produces a fixed-length value from any input and is used to check integrity, and two-factor authentication adds a second proof, usually a one-time password, to a password.
The law and the agencies
India's principal cyber law is the Information Technology Act, 2000, drafted on the model of the UNCITRAL Model Law on Electronic Commerce and amended substantially in 2008.
| Provision or body | What it does |
|---|---|
| Section 43 and 43A | Damage to a computer, and compensation where a body corporate fails to protect sensitive personal data |
| Section 66C and 66D | Identity theft, and cheating by personation using a computer resource |
| Section 66F | Cyber terrorism, punishable with imprisonment for life |
| Section 69 | Power to intercept, monitor or decrypt information in specified circumstances |
| Section 70A | Nodal agency for critical information infrastructure, the NCIIPC |
| Section 70B | CERT-In as the national nodal agency for cyber security incidents |
| Section 79 | Safe harbour limiting the liability of an intermediary for third-party content |
| CERT-In | Indian Computer Emergency Response Team, under MeitY, issuing advisories and handling incidents |
| NCIIPC | National Critical Information Infrastructure Protection Centre, functioning under the NTRO |
| I4C | Indian Cyber Crime Coordination Centre of the Ministry of Home Affairs, which runs the national cybercrime reporting portal |
| Cyber Swachhta Kendra | Botnet cleaning and malware analysis centre under MeitY |
Section 66A, which punished offensive messages sent through a communication service, was struck down as unconstitutional by the Supreme Court in Shreya Singhal v. Union of India in 2015 for violating the freedom of speech under Article 19(1)(a). The right to privacy was held to be a fundamental part of Article 21 in the Puttaswamy judgment of 2017, and that holding led to the Digital Personal Data Protection Act, 2023, which calls the individual a Data Principal, the entity processing the data a Data Fiduciary, and sets up a Data Protection Board of India. The National Cyber Security Policy was issued in 2013.
Digital public infrastructure in India
India's digital public infrastructure is often described as three layers, together called India Stack. The identity layer is Aadhaar, the twelve-digit number issued by the Unique Identification Authority of India, which began work in 2009 and was given statutory backing by the Aadhaar Act of 2016, together with electronic know-your-customer and e-Sign services. The payments layer is built by the National Payments Corporation of India, set up in 2008 under the Payment and Settlement Systems Act of 2007 by the Reserve Bank and the Indian Banks' Association; its products include RuPay, IMPS, the Aadhaar Enabled Payment System, NACH, FASTag under National Electronic Toll Collection and, above all, the Unified Payments Interface, launched in 2016, which lets a user move money between any two bank accounts with a virtual payment address. The data layer consists of DigiLocker, launched in 2015 for verified documents, and the Data Empowerment and Protection Architecture, under which the Account Aggregator framework of the Reserve Bank lets a person share financial data with consent. Around these sit the Digital India programme, launched on 1 July 2015, BharatNet for broadband to gram panchayats, Common Service Centres, the UMANG application and the Open Network for Digital Commerce.
Exam Point of View
The questions are definitional and institutional. Expect one on the meaning of a term (phishing, ransomware, worm, DDoS, zero-day, CIA triad), one on a section of the IT Act, and one on which agency does what: CERT-In under section 70B and MeitY, NCIIPC under section 70A and the NTRO, I4C under the Ministry of Home Affairs. The judgments in Shreya Singhal and Puttaswamy, the vocabulary of the Digital Personal Data Protection Act of 2023 and the layers of India Stack are the newer favourites. Beware of attributing UPI to the Reserve Bank instead of the NPCI, and of mixing section 70A with 70B.
Important Facts
| Principal cyber law | Information Technology Act, 2000; major amendment in 2008 |
|---|---|
| Model for the Act | UNCITRAL Model Law on Electronic Commerce |
| Cyber terrorism | Section 66F, punishable with imprisonment for life |
| Interception power | Section 69 of the IT Act |
| CERT-In | Section 70B; under the Ministry of Electronics and Information Technology |
| NCIIPC | Section 70A; functions under the National Technical Research Organisation |
| I4C | Indian Cyber Crime Coordination Centre, Ministry of Home Affairs |
| Section 66A struck down | Shreya Singhal v. Union of India, 2015 |
| Right to privacy | K. S. Puttaswamy v. Union of India, 2017, under Article 21 |
| Data protection law | Digital Personal Data Protection Act, 2023; Data Principal, Data Fiduciary, Data Protection Board |
| UPI | Launched by the National Payments Corporation of India in 2016 |
| NPCI | Set up in 2008 under the Payment and Settlement Systems Act, 2007 |
| Digital India | Launched on 1 July 2015 |
| Aadhaar | Twelve-digit number of the UIDAI, given statutory backing by the Aadhaar Act, 2016 |
Practice MCQs on this topic
Which Act is the principal law governing cyber activity and electronic records in India?
- A.Information Technology Act, 2000
- B.Indian Telegraph Act, 1885
- C.Indian Evidence Act, 1872
- D.Companies Act, 2013
Show answer
Correct answer: A. Information Technology Act, 2000
Explanation
The correct answer is A, the Information Technology Act, 2000. It gives legal recognition to electronic records and digital signatures, creates the offences of computer-related crime, and was amended substantially in 2008 to add provisions on cyber terrorism, interception and data protection by body corporates. Option B is wrong; the Indian Telegraph Act of 1885 governs telegraph and telephone services and the licensing of telecommunications, not computer offences. Option C is wrong because the Indian Evidence Act of 1872 deals with evidence generally, although the IT Act amended it so that electronic records could be admitted as evidence. Option D is wrong since the Companies Act of 2013 regulates companies and their governance. The IT Act was drafted on the model of the UNCITRAL Model Law on Electronic Commerce.
In cyber security, the CIA triad stands for:
- A.Control, Information, Access
- B.Confidentiality, Integrity, Availability
- C.Cryptography, Identity, Authentication
- D.Compliance, Inspection, Audit
Show answer
Correct answer: B. Confidentiality, Integrity, Availability
Explanation
The correct answer is B, Confidentiality, Integrity and Availability. These are the three goals of information security: only authorised persons should read the data, the data must not be altered without authority, and the system must work when it is needed. Option A is wrong; control and access are mechanisms rather than the named goals of the triad. Option C is wrong because cryptography, identity and authentication are tools used to achieve the three goals, not the goals themselves, and this option is attractive to anyone who remembers the technical vocabulary instead of the framework. Option D is wrong since compliance, inspection and audit belong to governance and assurance work. A denial of service attack is a good illustration, because it attacks availability alone while leaving confidentiality and integrity untouched.
Section 66A of the Information Technology Act was struck down by the Supreme Court in which case?
- A.K. S. Puttaswamy v. Union of India
- B.Shreya Singhal v. Union of India
- C.Anuradha Bhasin v. Union of India
- D.Maneka Gandhi v. Union of India
Show answer
Correct answer: B. Shreya Singhal v. Union of India
Explanation
The correct answer is B, Shreya Singhal v. Union of India. In 2015 the Supreme Court held section 66A, which punished the sending of offensive messages through a communication service, to be unconstitutional because it was vague and overbroad and violated the freedom of speech under Article 19(1)(a). Option A is wrong, although it is the closest in subject matter: the Puttaswamy judgment of 2017 held the right to privacy to be a fundamental right under Article 21, and it led to the data protection law rather than to the striking down of 66A. Option C is wrong; Anuradha Bhasin in 2020 concerned internet shutdowns in Jammu and Kashmir. Option D is wrong because Maneka Gandhi in 1978 expanded the meaning of personal liberty under Article 21 long before the internet.
CERT-In, the national nodal agency for responding to cyber security incidents, is designated under which section of the IT Act?
- A.Section 69
- B.Section 70A
- C.Section 70B
- D.Section 79
Show answer
Correct answer: C. Section 70B
Explanation
The correct answer is C, Section 70B. The Indian Computer Emergency Response Team functions under the Ministry of Electronics and Information Technology and is designated by section 70B as the national agency for collecting and analysing information on cyber incidents, issuing advisories and coordinating responses. Option A is wrong; section 69 gives the power to intercept, monitor or decrypt information in specified circumstances. Option B is the hardest distractor because section 70A designates the nodal agency for critical information infrastructure, which is the NCIIPC, a different body working under the National Technical Research Organisation. Option D is wrong since section 79 is the safe harbour provision that limits an intermediary's liability for content uploaded by third parties. Keep 70A with NCIIPC and 70B with CERT-In.
The National Critical Information Infrastructure Protection Centre (NCIIPC) functions under which organisation?
- A.Reserve Bank of India
- B.National Technical Research Organisation
- C.Ministry of Home Affairs
- D.National Informatics Centre
Show answer
Correct answer: B. National Technical Research Organisation
Explanation
The correct answer is B, the National Technical Research Organisation. The NCIIPC was designated under section 70A of the IT Act to protect critical information infrastructure, meaning computer resources whose incapacitation would have a debilitating effect on national security, the economy, public health or safety, and it works as a unit of the NTRO. Option A is wrong; the Reserve Bank regulates the financial sector's own cyber resilience but does not house the NCIIPC. Option C is wrong, although the Ministry of Home Affairs runs the Indian Cyber Crime Coordination Centre and the national cybercrime reporting portal, which is why it is a tempting choice. Option D is wrong because the National Informatics Centre provides information technology services to government departments rather than protecting critical infrastructure.
The Unified Payments Interface (UPI) was launched by which organisation?
- A.Reserve Bank of India
- B.National Payments Corporation of India
- C.State Bank of India
- D.Ministry of Electronics and Information Technology
Show answer
Correct answer: B. National Payments Corporation of India
Explanation
The correct answer is B, the National Payments Corporation of India. The NPCI, set up in 2008 under the Payment and Settlement Systems Act of 2007 by the Reserve Bank and the Indian Banks' Association, launched UPI in 2016; it also runs RuPay, IMPS, the Aadhaar Enabled Payment System, NACH and FASTag. Option A is wrong but is the commonest mistake, because the Reserve Bank promoted the NPCI and regulates payment systems, yet UPI is an NPCI product. Option C is wrong; the State Bank of India is one of the banks that participate in UPI, not its owner. Option D is wrong because the Ministry of Electronics and Information Technology runs DigiLocker and the Digital India programme, not the payments layer. UPI forms the payments layer of what is called India Stack.
An attack that floods a server with requests from many compromised machines so that genuine users cannot reach it is called:
- A.Phishing
- B.SQL injection
- C.Distributed denial of service
- D.Man-in-the-middle attack
Show answer
Correct answer: C. Distributed denial of service
Explanation
The correct answer is C, a distributed denial of service attack. A denial of service attack exhausts a server's capacity with a flood of requests, and when the flood is generated from many machines at once, often a botnet of infected computers, it is called distributed. The goal attacked here is availability, the third limb of the CIA triad. Option A is wrong; phishing is a fraudulent message imitating a trusted institution in order to obtain a password or card number. Option B is wrong because SQL injection inserts malicious database commands through an input field to read or alter stored data, which attacks confidentiality and integrity. Option D is wrong since a man-in-the-middle attack intercepts traffic between two parties without either of them knowing. The Cyber Swachhta Kendra exists to clean the botnets used in such attacks.
Under the Digital Personal Data Protection Act, 2023, the individual whose personal data is being processed is called the:
- A.Data Fiduciary
- B.Data Principal
- C.Consent Manager
- D.Data Processor
Show answer
Correct answer: B. Data Principal
Explanation
The correct answer is B, Data Principal. The Act of 2023 calls the individual to whom the personal data relates the Data Principal, and gives that person rights of access, correction, erasure and grievance redressal. Option A is wrong and is the commonest confusion: a Data Fiduciary is the person or entity that decides the purpose and means of processing the data, and it carries the duties under the Act. Option C is wrong because a Consent Manager is an entity registered with the Data Protection Board through which a Data Principal can give, manage and withdraw consent. Option D is wrong since a Data Processor processes data on behalf of a Data Fiduciary. The Act follows the Puttaswamy judgment of 2017 and the report of the Justice B. N. Srikrishna Committee.
A fraudulent email that imitates a bank in order to make the reader reveal a password or card number is an example of:
- A.Phishing
- B.Ransomware
- C.Spoofing of a network address
- D.A zero-day exploit
Show answer
Correct answer: A. Phishing
Explanation
The correct answer is A, phishing. Phishing uses a message that looks as though it comes from a trusted institution, so that the reader voluntarily gives up credentials; the same fraud carried out by telephone call is called vishing and by text message smishing. Option B is wrong; ransomware is malicious software that encrypts the victim's files and demands a payment for the key, so it does not depend on the victim disclosing a password. Option C is wrong because spoofing is the faking of an address or identifier at the technical level, and while a phishing email often spoofs a sender address, the named offence here is the deception of the reader. Option D is wrong since a zero-day exploit attacks a software flaw for which no patch yet exists, which is a technical weakness rather than a trick played on a person.
The Digital India programme was launched on which date?
- A.15 August 2014
- B.1 July 2015
- C.1 January 2016
- D.2 October 2014
Show answer
Correct answer: B. 1 July 2015
Explanation
The correct answer is B, 1 July 2015. Digital India was launched on that date with three stated aims: digital infrastructure as a utility for every citizen, governance and services on demand, and the digital empowerment of citizens; BharatNet, Common Service Centres, DigiLocker and the UMANG application all sit within it. Option A is wrong; 15 August 2014 is the date of the announcement of the Jan Dhan Yojana from the Red Fort, which was launched later that month. Option C is wrong and corresponds to no launch, although the Unified Payments Interface did come in 2016. Option D is wrong because 2 October 2014 is the launch of the Swachh Bharat Mission, chosen for Gandhi's birth anniversary, which makes it a plausible date for anyone guessing from the pattern of government launches.
Frequently Asked Questions
What is the difference between a virus, a worm and a trojan?
A virus attaches itself to a file or program and spreads only when that file is run. A worm is self-replicating and travels across a network without any user action. A trojan does not replicate at all; it hides inside a program that looks useful and opens a way in once the user installs it.
Which agency should a cyber security incident be reported to in India?
CERT-In, the Indian Computer Emergency Response Team, is the national nodal agency for cyber security incidents under section 70B of the IT Act and works under the Ministry of Electronics and Information Technology. A cybercrime against an individual is reported on the national cybercrime reporting portal run by the Indian Cyber Crime Coordination Centre of the Ministry of Home Affairs.
What is digital public infrastructure and what is India Stack?
Digital public infrastructure means open, interoperable digital systems built at population scale for use by government, business and citizens alike. India Stack is the Indian example, with an identity layer in Aadhaar and e-KYC, a payments layer in UPI and the other NPCI systems, and a data layer in DigiLocker and the consent-based Account Aggregator framework.
What does the Digital Personal Data Protection Act, 2023 change?
It gives an individual, called the Data Principal, rights over personal data held about them, places duties of notice, consent, purpose limitation and security on the Data Fiduciary that processes the data, allows Consent Managers to be registered, and creates the Data Protection Board of India to decide complaints and impose penalties.
Why was section 66A of the IT Act removed?
In Shreya Singhal v. Union of India in 2015 the Supreme Court found the section, which punished offensive messages sent through a communication service, to be vague and overbroad, so that it could chill lawful speech, and struck it down as a violation of the freedom of speech and expression under Article 19(1)(a).
Sources
- The Information Technology Act, 2000 — India Code, Government of India
- About CERT-In and its mandate under section 70B — Indian Computer Emergency Response Team, MeitY
- The Digital Personal Data Protection Act, 2023 — Ministry of Electronics and Information Technology





