Skip to content
GK24
GK NotesScience & TechnologyCyber Security and Digital Public Infrastructure

Cyber Security and Digital Public Infrastructure: Notes

Exam notes on cyber security and digital public infrastructure: attacks, defences, the IT Act 2000, CERT-In, NCIIPC, the 2023 data law and India Stack.

By · Published · 5 min read

Cyber Security and Digital Public Infrastructure: Notes — GK24 title card
Cyber Security and Digital Public Infrastructure: Notes — GK24 title card

Cyber security is the protection of computers, networks and the data they hold from unauthorised access, damage and disruption, and digital public infrastructure is the set of open, population-scale digital systems a state builds so that identity, payments and data can be used by everyone. The two subjects now appear together in examinations because India's digital systems reach hundreds of millions of people, and the law and the agencies that protect them are examinable facts. This note covers the attacks, the defences, the law, the agencies and the building blocks of India's digital public infrastructure.

The goals of security and the common attacks

Security is built around three goals, remembered as the CIA triad: confidentiality, so that only authorised persons can read data; integrity, so that data is not altered without authority; and availability, so that a system works when it is needed. The attacks that break them have names that are regularly asked. Malware is the family term, and within it a virus attaches itself to a file and needs that file to be run, a worm spreads by itself across a network, a trojan hides inside an apparently useful program, ransomware encrypts a victim's files and demands payment, and spyware and a keylogger quietly record what is typed. Phishing is a fraudulent message that imitates a bank or an office to make the reader give up a password or a card number; by telephone it is called vishing and by text message smishing. A denial of service attack floods a server with requests so that genuine users cannot reach it, and when the flood comes from many machines at once it is a distributed denial of service. Other standard terms are spoofing, in which an address is faked, a man-in-the-middle attack, in which traffic is intercepted, SQL injection against a database and a zero-day exploit, which uses a flaw before a patch exists.

The defences

A firewall filters traffic between a network and the outside; an intrusion detection system watches for suspicious patterns. Encryption converts readable text into cipher text, and it is of two kinds: symmetric encryption uses one shared key, while asymmetric or public key encryption uses a public key to encrypt and a private key to decrypt. A digital signature reverses the order, signing with the private key so that anyone with the public key can verify the sender, and it is the basis of legal recognition of electronic records in India. Under section 17 of the Information Technology Act the Controller of Certifying Authorities licenses the Certifying Authorities that issue digital signature certificates. A hash function produces a fixed-length value from any input and is used to check integrity, and two-factor authentication adds a second proof, usually a one-time password, to a password.

The law and the agencies

India's principal cyber law is the Information Technology Act, 2000, drafted on the model of the UNCITRAL Model Law on Electronic Commerce and amended substantially in 2008.

Provision or bodyWhat it does
Section 43 and 43ADamage to a computer, and compensation where a body corporate fails to protect sensitive personal data
Section 66C and 66DIdentity theft, and cheating by personation using a computer resource
Section 66FCyber terrorism, punishable with imprisonment for life
Section 69Power to intercept, monitor or decrypt information in specified circumstances
Section 70ANodal agency for critical information infrastructure, the NCIIPC
Section 70BCERT-In as the national nodal agency for cyber security incidents
Section 79Safe harbour limiting the liability of an intermediary for third-party content
CERT-InIndian Computer Emergency Response Team, under MeitY, issuing advisories and handling incidents
NCIIPCNational Critical Information Infrastructure Protection Centre, functioning under the NTRO
I4CIndian Cyber Crime Coordination Centre of the Ministry of Home Affairs, which runs the national cybercrime reporting portal
Cyber Swachhta KendraBotnet cleaning and malware analysis centre under MeitY

Section 66A, which punished offensive messages sent through a communication service, was struck down as unconstitutional by the Supreme Court in Shreya Singhal v. Union of India in 2015 for violating the freedom of speech under Article 19(1)(a). The right to privacy was held to be a fundamental part of Article 21 in the Puttaswamy judgment of 2017, and that holding led to the Digital Personal Data Protection Act, 2023, which calls the individual a Data Principal, the entity processing the data a Data Fiduciary, and sets up a Data Protection Board of India. The National Cyber Security Policy was issued in 2013.

Digital public infrastructure in India

India's digital public infrastructure is often described as three layers, together called India Stack. The identity layer is Aadhaar, the twelve-digit number issued by the Unique Identification Authority of India, which began work in 2009 and was given statutory backing by the Aadhaar Act of 2016, together with electronic know-your-customer and e-Sign services. The payments layer is built by the National Payments Corporation of India, set up in 2008 under the Payment and Settlement Systems Act of 2007 by the Reserve Bank and the Indian Banks' Association; its products include RuPay, IMPS, the Aadhaar Enabled Payment System, NACH, FASTag under National Electronic Toll Collection and, above all, the Unified Payments Interface, launched in 2016, which lets a user move money between any two bank accounts with a virtual payment address. The data layer consists of DigiLocker, launched in 2015 for verified documents, and the Data Empowerment and Protection Architecture, under which the Account Aggregator framework of the Reserve Bank lets a person share financial data with consent. Around these sit the Digital India programme, launched on 1 July 2015, BharatNet for broadband to gram panchayats, Common Service Centres, the UMANG application and the Open Network for Digital Commerce.

Exam Point of View

The questions are definitional and institutional. Expect one on the meaning of a term (phishing, ransomware, worm, DDoS, zero-day, CIA triad), one on a section of the IT Act, and one on which agency does what: CERT-In under section 70B and MeitY, NCIIPC under section 70A and the NTRO, I4C under the Ministry of Home Affairs. The judgments in Shreya Singhal and Puttaswamy, the vocabulary of the Digital Personal Data Protection Act of 2023 and the layers of India Stack are the newer favourites. Beware of attributing UPI to the Reserve Bank instead of the NPCI, and of mixing section 70A with 70B.

Important Facts

Principal cyber lawInformation Technology Act, 2000; major amendment in 2008
Model for the ActUNCITRAL Model Law on Electronic Commerce
Cyber terrorismSection 66F, punishable with imprisonment for life
Interception powerSection 69 of the IT Act
CERT-InSection 70B; under the Ministry of Electronics and Information Technology
NCIIPCSection 70A; functions under the National Technical Research Organisation
I4CIndian Cyber Crime Coordination Centre, Ministry of Home Affairs
Section 66A struck downShreya Singhal v. Union of India, 2015
Right to privacyK. S. Puttaswamy v. Union of India, 2017, under Article 21
Data protection lawDigital Personal Data Protection Act, 2023; Data Principal, Data Fiduciary, Data Protection Board
UPILaunched by the National Payments Corporation of India in 2016
NPCISet up in 2008 under the Payment and Settlement Systems Act, 2007
Digital IndiaLaunched on 1 July 2015
AadhaarTwelve-digit number of the UIDAI, given statutory backing by the Aadhaar Act, 2016

Practice MCQs on this topic

Q1.Science & TechnologyEasy

Which Act is the principal law governing cyber activity and electronic records in India?

  1. A.Information Technology Act, 2000
  2. B.Indian Telegraph Act, 1885
  3. C.Indian Evidence Act, 1872
  4. D.Companies Act, 2013
Show answer

Correct answer: A. Information Technology Act, 2000

Explanation

The correct answer is A, the Information Technology Act, 2000. It gives legal recognition to electronic records and digital signatures, creates the offences of computer-related crime, and was amended substantially in 2008 to add provisions on cyber terrorism, interception and data protection by body corporates. Option B is wrong; the Indian Telegraph Act of 1885 governs telegraph and telephone services and the licensing of telecommunications, not computer offences. Option C is wrong because the Indian Evidence Act of 1872 deals with evidence generally, although the IT Act amended it so that electronic records could be admitted as evidence. Option D is wrong since the Companies Act of 2013 regulates companies and their governance. The IT Act was drafted on the model of the UNCITRAL Model Law on Electronic Commerce.

Q2.Science & TechnologyEasy

In cyber security, the CIA triad stands for:

  1. A.Control, Information, Access
  2. B.Confidentiality, Integrity, Availability
  3. C.Cryptography, Identity, Authentication
  4. D.Compliance, Inspection, Audit
Show answer

Correct answer: B. Confidentiality, Integrity, Availability

Explanation

The correct answer is B, Confidentiality, Integrity and Availability. These are the three goals of information security: only authorised persons should read the data, the data must not be altered without authority, and the system must work when it is needed. Option A is wrong; control and access are mechanisms rather than the named goals of the triad. Option C is wrong because cryptography, identity and authentication are tools used to achieve the three goals, not the goals themselves, and this option is attractive to anyone who remembers the technical vocabulary instead of the framework. Option D is wrong since compliance, inspection and audit belong to governance and assurance work. A denial of service attack is a good illustration, because it attacks availability alone while leaving confidentiality and integrity untouched.

Q3.Science & TechnologyMedium

Section 66A of the Information Technology Act was struck down by the Supreme Court in which case?

  1. A.K. S. Puttaswamy v. Union of India
  2. B.Shreya Singhal v. Union of India
  3. C.Anuradha Bhasin v. Union of India
  4. D.Maneka Gandhi v. Union of India
Show answer

Correct answer: B. Shreya Singhal v. Union of India

Explanation

The correct answer is B, Shreya Singhal v. Union of India. In 2015 the Supreme Court held section 66A, which punished the sending of offensive messages through a communication service, to be unconstitutional because it was vague and overbroad and violated the freedom of speech under Article 19(1)(a). Option A is wrong, although it is the closest in subject matter: the Puttaswamy judgment of 2017 held the right to privacy to be a fundamental right under Article 21, and it led to the data protection law rather than to the striking down of 66A. Option C is wrong; Anuradha Bhasin in 2020 concerned internet shutdowns in Jammu and Kashmir. Option D is wrong because Maneka Gandhi in 1978 expanded the meaning of personal liberty under Article 21 long before the internet.

Q4.Science & TechnologyHard

CERT-In, the national nodal agency for responding to cyber security incidents, is designated under which section of the IT Act?

  1. A.Section 69
  2. B.Section 70A
  3. C.Section 70B
  4. D.Section 79
Show answer

Correct answer: C. Section 70B

Explanation

The correct answer is C, Section 70B. The Indian Computer Emergency Response Team functions under the Ministry of Electronics and Information Technology and is designated by section 70B as the national agency for collecting and analysing information on cyber incidents, issuing advisories and coordinating responses. Option A is wrong; section 69 gives the power to intercept, monitor or decrypt information in specified circumstances. Option B is the hardest distractor because section 70A designates the nodal agency for critical information infrastructure, which is the NCIIPC, a different body working under the National Technical Research Organisation. Option D is wrong since section 79 is the safe harbour provision that limits an intermediary's liability for content uploaded by third parties. Keep 70A with NCIIPC and 70B with CERT-In.

Q5.Science & TechnologyHard

The National Critical Information Infrastructure Protection Centre (NCIIPC) functions under which organisation?

  1. A.Reserve Bank of India
  2. B.National Technical Research Organisation
  3. C.Ministry of Home Affairs
  4. D.National Informatics Centre
Show answer

Correct answer: B. National Technical Research Organisation

Explanation

The correct answer is B, the National Technical Research Organisation. The NCIIPC was designated under section 70A of the IT Act to protect critical information infrastructure, meaning computer resources whose incapacitation would have a debilitating effect on national security, the economy, public health or safety, and it works as a unit of the NTRO. Option A is wrong; the Reserve Bank regulates the financial sector's own cyber resilience but does not house the NCIIPC. Option C is wrong, although the Ministry of Home Affairs runs the Indian Cyber Crime Coordination Centre and the national cybercrime reporting portal, which is why it is a tempting choice. Option D is wrong because the National Informatics Centre provides information technology services to government departments rather than protecting critical infrastructure.

Q6.Science & TechnologyEasy

The Unified Payments Interface (UPI) was launched by which organisation?

  1. A.Reserve Bank of India
  2. B.National Payments Corporation of India
  3. C.State Bank of India
  4. D.Ministry of Electronics and Information Technology
Show answer

Correct answer: B. National Payments Corporation of India

Explanation

The correct answer is B, the National Payments Corporation of India. The NPCI, set up in 2008 under the Payment and Settlement Systems Act of 2007 by the Reserve Bank and the Indian Banks' Association, launched UPI in 2016; it also runs RuPay, IMPS, the Aadhaar Enabled Payment System, NACH and FASTag. Option A is wrong but is the commonest mistake, because the Reserve Bank promoted the NPCI and regulates payment systems, yet UPI is an NPCI product. Option C is wrong; the State Bank of India is one of the banks that participate in UPI, not its owner. Option D is wrong because the Ministry of Electronics and Information Technology runs DigiLocker and the Digital India programme, not the payments layer. UPI forms the payments layer of what is called India Stack.

Q7.Science & TechnologyMedium

An attack that floods a server with requests from many compromised machines so that genuine users cannot reach it is called:

  1. A.Phishing
  2. B.SQL injection
  3. C.Distributed denial of service
  4. D.Man-in-the-middle attack
Show answer

Correct answer: C. Distributed denial of service

Explanation

The correct answer is C, a distributed denial of service attack. A denial of service attack exhausts a server's capacity with a flood of requests, and when the flood is generated from many machines at once, often a botnet of infected computers, it is called distributed. The goal attacked here is availability, the third limb of the CIA triad. Option A is wrong; phishing is a fraudulent message imitating a trusted institution in order to obtain a password or card number. Option B is wrong because SQL injection inserts malicious database commands through an input field to read or alter stored data, which attacks confidentiality and integrity. Option D is wrong since a man-in-the-middle attack intercepts traffic between two parties without either of them knowing. The Cyber Swachhta Kendra exists to clean the botnets used in such attacks.

Q8.Science & TechnologyMedium

Under the Digital Personal Data Protection Act, 2023, the individual whose personal data is being processed is called the:

  1. A.Data Fiduciary
  2. B.Data Principal
  3. C.Consent Manager
  4. D.Data Processor
Show answer

Correct answer: B. Data Principal

Explanation

The correct answer is B, Data Principal. The Act of 2023 calls the individual to whom the personal data relates the Data Principal, and gives that person rights of access, correction, erasure and grievance redressal. Option A is wrong and is the commonest confusion: a Data Fiduciary is the person or entity that decides the purpose and means of processing the data, and it carries the duties under the Act. Option C is wrong because a Consent Manager is an entity registered with the Data Protection Board through which a Data Principal can give, manage and withdraw consent. Option D is wrong since a Data Processor processes data on behalf of a Data Fiduciary. The Act follows the Puttaswamy judgment of 2017 and the report of the Justice B. N. Srikrishna Committee.

Q9.Science & TechnologyMedium

A fraudulent email that imitates a bank in order to make the reader reveal a password or card number is an example of:

  1. A.Phishing
  2. B.Ransomware
  3. C.Spoofing of a network address
  4. D.A zero-day exploit
Show answer

Correct answer: A. Phishing

Explanation

The correct answer is A, phishing. Phishing uses a message that looks as though it comes from a trusted institution, so that the reader voluntarily gives up credentials; the same fraud carried out by telephone call is called vishing and by text message smishing. Option B is wrong; ransomware is malicious software that encrypts the victim's files and demands a payment for the key, so it does not depend on the victim disclosing a password. Option C is wrong because spoofing is the faking of an address or identifier at the technical level, and while a phishing email often spoofs a sender address, the named offence here is the deception of the reader. Option D is wrong since a zero-day exploit attacks a software flaw for which no patch yet exists, which is a technical weakness rather than a trick played on a person.

Q10.Science & TechnologyMedium

The Digital India programme was launched on which date?

  1. A.15 August 2014
  2. B.1 July 2015
  3. C.1 January 2016
  4. D.2 October 2014
Show answer

Correct answer: B. 1 July 2015

Explanation

The correct answer is B, 1 July 2015. Digital India was launched on that date with three stated aims: digital infrastructure as a utility for every citizen, governance and services on demand, and the digital empowerment of citizens; BharatNet, Common Service Centres, DigiLocker and the UMANG application all sit within it. Option A is wrong; 15 August 2014 is the date of the announcement of the Jan Dhan Yojana from the Red Fort, which was launched later that month. Option C is wrong and corresponds to no launch, although the Unified Payments Interface did come in 2016. Option D is wrong because 2 October 2014 is the launch of the Swachh Bharat Mission, chosen for Gandhi's birth anniversary, which makes it a plausible date for anyone guessing from the pattern of government launches.

Frequently Asked Questions

What is the difference between a virus, a worm and a trojan?

A virus attaches itself to a file or program and spreads only when that file is run. A worm is self-replicating and travels across a network without any user action. A trojan does not replicate at all; it hides inside a program that looks useful and opens a way in once the user installs it.

Which agency should a cyber security incident be reported to in India?

CERT-In, the Indian Computer Emergency Response Team, is the national nodal agency for cyber security incidents under section 70B of the IT Act and works under the Ministry of Electronics and Information Technology. A cybercrime against an individual is reported on the national cybercrime reporting portal run by the Indian Cyber Crime Coordination Centre of the Ministry of Home Affairs.

What is digital public infrastructure and what is India Stack?

Digital public infrastructure means open, interoperable digital systems built at population scale for use by government, business and citizens alike. India Stack is the Indian example, with an identity layer in Aadhaar and e-KYC, a payments layer in UPI and the other NPCI systems, and a data layer in DigiLocker and the consent-based Account Aggregator framework.

What does the Digital Personal Data Protection Act, 2023 change?

It gives an individual, called the Data Principal, rights over personal data held about them, places duties of notice, consent, purpose limitation and security on the Data Fiduciary that processes the data, allows Consent Managers to be registered, and creates the Data Protection Board of India to decide complaints and impose penalties.

Why was section 66A of the IT Act removed?

In Shreya Singhal v. Union of India in 2015 the Supreme Court found the section, which punished offensive messages sent through a communication service, to be vague and overbroad, so that it could chill lawful speech, and struck it down as a violation of the freedom of speech and expression under Article 19(1)(a).

Sources

View all