Cyber Security for UPSC CSE — Digital Threats, Laws, and Critical Infrastructure

advanced 22 min read

Concept

Cyber security is the practice of protecting digital systems, networks, data, and the services that depend on them from unauthorized access, disruption, theft, or destruction. The term sounds technical, but for UPSC purposes, you need to think of it as the governance problem of the digital age — who protects what, under which law, through which institution.

Here is a useful analogy. Think of India's physical infrastructure: roads, dams, power plants. The state protects these through the Army, NDRF, and state police. Digital infrastructure — data centres, government servers, financial networks, power-grid control systems — needs an equivalent protection architecture. Cyber security is that architecture, adapted for threats that cross borders invisibly, arrive in milliseconds, and leave no physical trace.

The scope matters for UPSC. Cyber security is not just about hackers stealing credit-card numbers. It spans:

These three principles form the CIA triad, the foundational framework used by policy documents worldwide, including India's National Cyber Security Policy (NCSP), 2013.

For UPSC Prelims, the questions cluster around institutions (CERT-In, NCIIPC), legislation (IT Act 2000, DPDP Act 2023), and emerging technologies (QKD, PKI). For Mains, the angle is broader — cyber threats to democratic institutions, environmental monitoring systems, financial stability, and India's strategic autonomy in cyberspace.

One more framing device: the convergence of cyber security with other domains. Climate change damages physical infrastructure that digital systems rely on. Disinformation exploits social media algorithms. AI enables both superior attack and superior defence. UPSC increasingly tests you at these intersections, not on the isolated technical facts.


Deep Dive

India's Institutional Architecture for Cyber Security

India's cyber governance is multi-layered. Knowing which body does what is the single highest-yield area for Prelims.

CERT-In (Indian Computer Emergency Response Team) — Established under Section 70B of the IT Act 2000, CERT-In is the national nodal agency for responding to cybersecurity incidents. It issues advisories, coordinates incident response, and mandates reporting of cyber incidents by service providers. Critically, CERT-In handles reactive security — what happens after an attack.

NCIIPC (National Critical Information Infrastructure Protection Centre) — Established under Section 70A of the IT Act 2000, NCIIPC is the designated agency for proactively protecting Critical Information Infrastructure (CII). CII is defined as computer resources whose incapacitation would have a debilitating effect on national security, economy, public health, or safety. Protected sectors include energy, banking, transport, telecom, and government. This is the proactive counterpart to CERT-In's reactive role.

NCCC (National Cyber Coordination Centre) — Operates under the Ministry of Electronics and Information Technology (MeitY) and focuses on real-time threat monitoring and intelligence sharing. Think of it as the early-warning layer.

Cyber and Information Security Division of MHA — Deals with cybercrime investigation, particularly relating to national security and law enforcement.

The exam often conflates CERT-In and NCIIPC. Burn this distinction: CERT-In = incident response; NCIIPC = protecting critical infrastructure proactively.

Legislative Framework

Information Technology Act, 2000 (amended 2008) — India's primary cyber law. Key sections for UPSC:

Digital Personal Data Protection Act, 2023 (DPDP Act) — India's first comprehensive data protection law. Key features:

National Cyber Security Policy, 2013 — India's foundational policy framework. It aims to create a secure cyber ecosystem, build trust in IT transactions, and envisages the creation of NCIIPC. It does not mandate specific certifications like ISO 27001 for all government ministries within a fixed timeline — a detail that appears as a distracter in PYQs.

Key Technical Concepts

Public Key Infrastructure (PKI) — A framework for managing digital certificates and public-key encryption to enable secure electronic communication. PKI uses asymmetric cryptography: a public key (shared openly) encrypts data, while only the corresponding private key (held secretly) decrypts it. In India, PKI is deployed through the Controller of Certifying Authorities (CCA) under the IT Act. It underpins digital signatures, SSL/TLS website security, and Aadhaar-based authentication. When UPSC asks about PKI, the answer is always in the domain of digital security infrastructure.

Quantum Key Distribution (QKD) — A method of secure communication using principles of quantum mechanics. Any attempt to intercept a QKD-generated key disturbs the quantum state (due to the no-cloning theorem and Heisenberg's uncertainty principle), making eavesdropping detectable. India's DRDO and C-DOT have conducted QKD trials for secure communication links. However, QKD is not a replacement for classical cryptography (RSA, AES) in all practical applications — distance limitations and cost make it currently complementary, not substitutive.

The Cyber-Environment Nexus

This intersection is increasingly tested. Two directions matter:

Cyber attacks on environmental infrastructure: Industrial Control Systems (ICS) and SCADA (Supervisory Control and Data Acquisition) systems manage water treatment, power grids, and pollution monitoring. A cyber attack on a water treatment plant's ICS could cause direct environmental harm — contaminating water supplies or disabling pollution controls. Such systems fall under the IT Act 2000 (Section 70) as protected critical infrastructure, not under the Environment Protection Act 1986 (which deals with environmental standards, not cyber threats).

Climate change threatening cyber infrastructure: Extreme weather events (floods, cyclones) damage data centres, communication towers, and undersea fiber-optic cables. Undersea cables carry over 95% of global internet traffic; rising sea levels and stronger storms are a recognized threat to their integrity. This is a documented climate-cyber risk, not speculation. Note that the claim that climate displacement increases cybercrime is not a recognized policy position — a frequent distracter.

Green Cybersecurity is an emerging concept with two dimensions: (1) reducing the energy and carbon footprint of cybersecurity operations (data centres consume enormous power), and (2) protecting environmental monitoring and management systems from cyber attacks. It is not mandated under the Paris Agreement 2015, which focuses exclusively on climate mitigation and adaptation targets.


Memory Tricks and Shortcuts

patternCERT vs NCIIPC — React vs Protect

Remember: CERT-In = Crisis Emergency Response Team = reacts after the attack. NCIIPC = National Critical Infrastructure = prevents attack on critical systems before it happens. In PYQs, if the question says "protecting" or "critical information infrastructure", the answer is NCIIPC. If it says "responding to incidents" or "issuing advisories", the answer is CERT-In. Applying this pattern eliminates wrong options in under 10 seconds vs. 40 seconds of second-guessing.

eliminationDPDP Act's Extra-Territorial Trap

Statement 1 type: "DPDP Act applies only within India" — this is always WRONG. The Act explicitly has extra-territorial application when goods/services are offered to persons in India. Eliminate any option that includes Statement 1 as correct in DPDP Act questions. This reduces a 4-option question to a 2-option question instantly, cutting decision time from 60 seconds to 20 seconds.

patternPKI = Digital Security Only

Every UPSC question on PKI pairs it against tempting distracters like health infrastructure, food security, or telecom. PKI is cryptography-based — it is always and only about digital security. If you see PKI and "digital security infrastructure" in the same option, select it without reading the others. Standard elimination: 30 seconds. Pattern recognition: 5 seconds.

eliminationQKD's One Hard Limit

QKD questions almost always carry a false Statement 3: "QKD completely replaces classical cryptography." This is wrong — QKD has distance and cost constraints and is used alongside RSA/AES, not instead of them. Eliminate any option that marks this statement correct. Statements about QKD's quantum-mechanical basis and India's DRDO/C-DOT trials are generally correct. Use this to narrow 4 options to 1 in about 15 seconds.

substitutionIT Act vs EPA for Cyber Attacks on Environment

When a question links cyber attacks on water plants / power grids / environmental systems to legislation, the governing law is always the IT Act 2000 (Sections 70, 70A), not the Environment Protection Act 1986. Substitute mentally: the EPA governs pollution standards and environmental clearances; it has no cyber provisions. The IT Act governs all computer-resource-related security. Applying this substitution collapses a 4-option question to a confident single answer in under 10 seconds.


Fast-Solving Framework

When you see a cyber security question in Prelims, run this decision tree:

Step 1 — Identify the subject. Is it about an institution, a law, a technology concept, or a policy?

Step 2 — Institutions. NCIIPC = critical infrastructure protection. CERT-In = incident response and advisories. NCCC = real-time monitoring. MHA Cyber Division = cybercrime and law enforcement.

Step 3 — Laws. IT Act 2000 = primary cyber law; governs critical infrastructure (Section 70), NCIIPC (70A), CERT-In (70B). DPDP Act 2023 = personal data; extra-territorial; Data Protection Board; consent mandatory.

Step 4 — Technology concepts. PKI = digital security only. QKD = quantum-based, theoretically secure, does not replace classical crypto. Encryption = CIA triad.

Step 5 — Cyber-environment nexus. Physical damage to cyber infrastructure from climate = valid. Climate displacement causing cybercrime = not a recognized position (distracter). Cyber attacks on ICS = governed by IT Act, not EPA. Green Cybersecurity = not mandated by Paris Agreement.

Apply the appropriate eliminator from the tricks above. If two options survive, look for the statement that contains a "completely", "all", "only within India" type absolute — it is usually the wrong one.


Solved PYQs

Why this question: PKI is the most fundamental cryptographic concept in India's digital governance. UPSC tests whether you link it to digital security rather than physical infrastructure.

Previous Year Questionपिछले वर्ष का प्रश्न2020
In India, the term "Public Key Infrastructure" is used in the context of
भारत में "पब्लिक की इन्फ्रास्ट्रक्चर" (Public Key Infrastructure) शब्द किस संदर्भ में इस्तेमाल किया जाता है?
  1. Digital security infrastructure
  2. Health care and education infrastructure
  3. Food security infrastructure
  4. Telecommunication and transportation infrastructure
  1. डिजिटल सुरक्षा इन्फ्रास्ट्रक्चर
  2. स्वास्थ्य और शिक्षा इन्फ्रास्ट्रक्चर
  3. खाद्य सुरक्षा इन्फ्रास्ट्रक्चर
  4. दूरसंचार और परिवहन इन्फ्रास्ट्रक्चर
Solutionसमाधान
Public Key Infrastructure (PKI) is used in the context of digital security infrastructure for secure electronic transfer of information through digital certificates and cryptography.

Solving path: PKI = Public Key Infrastructure. "Public key" and "private key" are cryptographic terms, firmly in the digital security domain. Options B (health/education), C (food security), D (telecom/transport) describe physical infrastructure sectors. Eliminate all three. Select A. Time: 8 seconds.


Why this question: The NCIIPC vs CERT-In distinction is the most-tested institutional fact in India's cyber security framework.

Previous Year Questionपिछले वर्ष का प्रश्न
Which Indian government body is primarily responsible for protecting critical information infrastructure, including systems related to environmental monitoring?
पर्यावरण निगरानी से जुड़े सिस्टम सहित महत्वपूर्ण सूचना अवसंरचना की सुरक्षा के लिए मुख्य रूप से कौन सी भारतीय सरकारी संस्था जिम्मेदार है?
  1. Cyber and Information Security Division of MHA
  2. National Cyber Coordination Centre (NCCC)
  3. National Critical Information Infrastructure Protection Centre (NCIIPC)
  4. Indian Computer Emergency Response Team (CERT-In)
  1. MHA का Cyber and Information Security Division
  2. National Cyber Coordination Centre (NCCC)
  3. National Critical Information Infrastructure Protection Centre (NCIIPC)
  4. Indian Computer Emergency Response Team (CERT-In)
Solutionसमाधान
NCIIPC, established under Section 70A of the Information Technology Act, 2000, is India's designated agency for protecting critical information infrastructure, which includes sectors such as energy, water, and environment. CERT-In handles incident response, while NCCC focuses on real-time threat monitoring.
NCIIPC, सूचना प्रौद्योगिकी अधिनियम 2000 की धारा 70A के तहत स्थापित, भारत की वह नामित संस्था है जो महत्वपूर्ण सूचना अवसंरचना की रक्षा करती है, जिसमें ऊर्जा, जल और पर्यावरण जैसे क्षेत्र शामिल हैं। CERT-In घटना प्रतिक्रिया संभालता है, जबकि NCCC वास्तविक समय के खतरों की निगरानी पर केंद्रित है।

Solving path: The question asks for the body "primarily responsible for protecting critical information infrastructure." Protecting CII = NCIIPC (Section 70A). CERT-In = incident response (Section 70B). NCCC = monitoring, not protection. MHA Cyber Division = cybercrime. Select C. Time: 12 seconds.


Why this question: The climate-cyber nexus is a signature UPSC intersection topic. Statement 2 about climate refugees and cybercrime is a classic unfounded generalization distracter.

Previous Year Questionपिछले वर्ष का प्रश्न
Consider the following statements about the relationship between climate change and cybersecurity: 1. Extreme weather events can physically damage cybersecurity infrastructure, creating exploitable vulnerabilities. 2. Climate refugees moving to urban areas can increase the pool of cybercriminals. 3. Disruption of undersea communication cables by rising sea levels is a recognized climate-cyber risk. Which of the statements given above is/are correct?
जलवायु परिवर्तन और साइबर सुरक्षा के बीच संबंध के बारे में निम्नलिखित कथनों पर विचार कीजिए: 1. अत्यधिक मौसमी घटनाएं साइबर सुरक्षा अवसंरचना को भौतिक रूप से नुकसान पहुंचा सकती हैं, जिससे शोषण योग्य कमजोरियां पैदा होती हैं। 2. शहरी इलाकों में आने वाले जलवायु शरणार्थी साइबर अपराधियों की संख्या बढ़ा सकते हैं। 3. समुद्र के बढ़ते जलस्तर से समुद्र के नीचे बिछी संचार केबलों का बाधित होना एक मान्यता प्राप्त जलवायु-साइबर जोखिम है। ऊपर दिए गए कथनों में से कौन सा/से सही है/हैं?
  1. 1 and 3 only
  2. 1, 2, and 3
  3. 2 and 3 only
  4. 1 only
  1. केवल 1 और 3
  2. 1, 2 और 3
  3. केवल 2 और 3
  4. केवल 1
Solutionसमाधान
Statement 1 is correct: extreme weather such as floods and storms can damage data centres and communication infrastructure, creating security gaps. Statement 3 is correct: rising sea levels and stronger storms threaten undersea fiber optic cables, which carry over 95% of global internet traffic, representing a recognized climate-cyber risk. Statement 2 is an unfounded generalization and not a recognized policy position.
कथन 1 सही है: बाढ़ और तूफान जैसी चरम मौसम घटनाएं डेटा केंद्रों और संचार अवसंरचना को नुकसान पहुंचा सकती हैं, जिससे सुरक्षा अंतराल उत्पन्न होते हैं। कथन 3 सही है: बढ़ते समुद्र स्तर और तेज तूफान समुद्री फाइबर ऑप्टिक केबलों को खतरे में डालते हैं, जो वैश्विक इंटरनेट ट्रैफिक का 95% से अधिक वहन करते हैं। कथन 2 एक निराधार सामान्यीकरण है और कोई मान्यता प्राप्त नीतिगत स्थिति नहीं है।

Solving path: Statement 1 — extreme weather damaging data centres and communication infrastructure is factually documented. Mark correct. Statement 2 — linking climate refugees to cybercrime is a sweeping, unsubstantiated generalization. Mark incorrect. This eliminates options B and C. Statement 3 — undersea cables carrying global internet traffic are a documented climate-cyber vulnerability. Mark correct. Answer = A (1 and 3 only). Time: 45 seconds.


Why this question: Tests the intersection of cyber law and environmental infrastructure, and the common trap of attributing cyber regulation to the EPA.

Previous Year Questionपिछले वर्ष का प्रश्न
Cyber attacks on Industrial Control Systems (ICS) managing water treatment plants pose a direct environmental threat. Which Indian legislation primarily governs the cybersecurity of such critical infrastructure?
जल शोधन संयंत्रों का प्रबंधन करने वाले Industrial Control Systems (ICS) पर साइबर हमले सीधे पर्यावरणीय खतरा पैदा करते हैं। ऐसी महत्वपूर्ण अवसंरचना की साइबर सुरक्षा मुख्य रूप से किस भारतीय कानून के अंतर्गत आती है?
  1. Information Technology Act, 2000
  2. Environment Protection Act, 1986
  3. National Water Policy, 2012
  4. Disaster Management Act, 2005
  1. Information Technology Act, 2000
  2. Environment Protection Act, 1986
  3. National Water Policy, 2012
  4. Disaster Management Act, 2005
Solutionसमाधान
The Information Technology Act, 2000 (amended 2008) is India's primary legislation governing cybersecurity, including protection of critical information infrastructure under Section 70, which covers systems like water treatment plants. The Environment Protection Act deals with environmental standards, not cyber threats.
सूचना प्रौद्योगिकी अधिनियम, 2000 (2008 में संशोधित) भारत का प्राथमिक साइबर सुरक्षा कानून है, जिसकी धारा 70 के तहत जल उपचार संयंत्रों जैसी महत्वपूर्ण सूचना अवसंरचना की सुरक्षा की जाती है। पर्यावरण संरक्षण अधिनियम पर्यावरणीय मानकों से संबंधित है, साइबर खतरों से नहीं।

Solving path: Cyber attacks on ICS = a cybersecurity matter. Governing law = IT Act 2000 (Section 70 covers protected computer resources including water treatment systems). EPA 1986 = environmental standards, no cyber provisions. National Water Policy = water allocation, not cyber. Disaster Management Act = disaster response, not primary cyber governance. Select A. Time: 15 seconds.


Why this question: The DPDP Act 2023 is a high-priority topic. The extra-territorial application trap in Statement 1 is the single most important fact to remember.

Previous Year Questionपिछले वर्ष का प्रश्न
With reference to India's Personal Data Protection framework, which of the following statements is/are correct regarding the Digital Personal Data Protection Act, 2023? 1. The Act applies only to digital personal data processed within the territory of India. 2. The Act establishes a Data Protection Board of India as an adjudicatory body. 3. The Act mandates that data fiduciaries obtain explicit consent before processing personal data. Select the correct answer using the code given below:
भारत के व्यक्तिगत डेटा संरक्षण ढांचे के संदर्भ में, डिजिटल व्यक्तिगत डेटा संरक्षण अधिनियम, 2023 के बारे में निम्नलिखित में से कौन सा/से कथन सही है/हैं? 1. अधिनियम केवल भारत के क्षेत्र के भीतर संसाधित डिजिटल व्यक्तिगत डेटा पर लागू होता है। 2. अधिनियम एक न्यायनिर्णायक निकाय के रूप में भारत के डेटा संरक्षण बोर्ड की स्थापना करता है। 3. अधिनियम अनिवार्य करता है कि डेटा फिड्यूशियरी व्यक्तिगत डेटा को संसाधित करने से पहले स्पष्ट सहमति प्राप्त करें। नीचे दिए गए कोड का उपयोग करके सही उत्तर चुनें:
  1. 1 and 3 only
  2. 2 and 3 only
  3. 1 and 2 only
  4. 1, 2 and 3
  1. केवल 1 और 3
  2. केवल 2 और 3
  3. केवल 1 और 2
  4. 1, 2 और 3
Solutionसमाधान
The Digital Personal Data Protection Act, 2023 applies to digital personal data processed both within India AND outside India if it involves offering goods/services to individuals in India (extra-territorial application), so Statement 1 is incorrect. The Act does establish the Data Protection Board of India (Statement 2 correct) and mandates consent before processing personal data (Statement 3 correct). Hence only 2 and 3 are correct.
डिजिटल व्यक्तिगत डेटा संरक्षण अधिनियम, 2023 भारत के भीतर और बाहर दोनों जगह संसाधित डिजिटल व्यक्तिगत डेटा पर लागू होता है, यदि यह भारत में व्यक्तियों को वस्तुएं/सेवाएं प्रदान करने से संबंधित हो (अतिरिक्त-क्षेत्रीय अनुप्रयोग)। अतः कथन 1 गलत है। अधिनियम डेटा संरक्षण बोर्ड की स्थापना करता है (कथन 2 सही) और व्यक्तिगत डेटा संसाधन से पहले सहमति अनिवार्य करता है (कथन 3 सही)। अतः केवल 2 और 3 सही हैं।

Solving path: Statement 1 — "applies only within India" — FALSE. The DPDP Act has extra-territorial reach. Eliminate immediately. This removes options A, C, D (all include Statement 1 as correct). Statement 2 — Data Protection Board = correct. Statement 3 — consent before processing = correct. Answer = B (2 and 3 only). Time: 20 seconds.


Why this question: QKD is a cutting-edge technology with a reliably false Statement 3 about replacing classical cryptography.

Previous Year Questionपिछले वर्ष का प्रश्न
With reference to 'Quantum Key Distribution (QKD)' in the context of cyber security, consider the following statements: 1. QKD uses principles of quantum mechanics to create theoretically unbreakable encryption keys. 2. India's DRDO and C-DOT have conducted successful QKD trials for secure communication. 3. QKD completely replaces classical cryptography methods such as RSA in all practical applications. Which of the statements given above is/are correct?
साइबर सुरक्षा के संदर्भ में 'Quantum Key Distribution (QKD)' के बारे में निम्नलिखित कथनों पर विचार करें: 1. QKD सैद्धांतिक रूप से अटूट एन्क्रिप्शन कुंजियाँ बनाने के लिए क्वांटम यांत्रिकी के सिद्धांतों का उपयोग करता है। 2. भारत के DRDO और C-DOT ने सुरक्षित संचार के लिए सफल QKD परीक्षण किए हैं। 3. QKD सभी व्यावहारिक अनुप्रयोगों में RSA जैसी शास्त्रीय क्रिप्टोग्राफी विधियों को पूरी तरह से प्रतिस्थापित करता है। उपरोक्त में से कौन सा/से कथन सही है/हैं?
  1. 1 and 3 only
  2. 2 and 3 only
  3. 1, 2 and 3
  4. 1 and 2 only
  1. केवल 1 और 3
  2. केवल 2 और 3
  3. 1, 2 और 3
  4. केवल 1 और 2
Solutionसमाधान
QKD uses quantum mechanical principles (photon polarization, quantum entanglement) to create encryption keys that are theoretically secure because any eavesdropping disturbs the quantum state and is detectable. India's DRDO and C-DOT have conducted QKD trials. However, Statement 3 is incorrect — QKD does not completely replace classical cryptography in all practical applications; it has limitations related to distance, cost, and infrastructure, and is currently used alongside classical methods.
QKD क्वांटम यांत्रिकी सिद्धांतों (फोटॉन ध्रुवीकरण, क्वांटम उलझाव) का उपयोग करके सैद्धांतिक रूप से सुरक्षित एन्क्रिप्शन कुंजियाँ बनाता है क्योंकि कोई भी जासूसी क्वांटम अवस्था को बाधित करती है और पता लगाई जा सकती है। भारत के DRDO और C-DOT ने QKD परीक्षण किए हैं। हालांकि, कथन 3 गलत है — QKD सभी व्यावहारिक अनुप्रयोगों में शास्त्रीय क्रिप्टोग्राफी को पूरी तरह से प्रतिस्थापित नहीं करता; दूरी, लागत और बुनियादी ढांचे की सीमाओं के कारण इसे शास्त्रीय विधियों के साथ उपयोग किया जाता है।

Solving path: Statement 1 — QKD uses quantum mechanics for theoretically unbreakable keys = correct. Statement 3 — "completely replaces classical cryptography in all practical applications" = FALSE (QKD has distance and cost limits). Eliminate options A, B, C (all include Statement 3 as correct). Statement 2 — India's DRDO and C-DOT QKD trials = documented fact. Answer = D (1 and 2 only). Time: 25 seconds.


Why this question: National Cyber Security Policy 2013 is a frequently cited document. Statement 2 with the ISO 27001 specifics is a fabricated detail — the policy never mandated this.

Previous Year Questionपिछले वर्ष का प्रश्न
Consider the following regarding India's National Cyber Security Policy, 2013: 1. It aims to create a secure cyber ecosystem and adequate trust in IT systems, transactions and services. 2. It mandates that all government ministries implement ISO 27001 certification within two years of the policy's enactment. 3. It envisages creation of a National Critical Information Infrastructure Protection Centre (NCIIPC). Which of the statements given above is/are correct?
भारत की राष्ट्रीय साइबर सुरक्षा नीति, 2013 के बारे में निम्नलिखित पर विचार करें: 1. इसका उद्देश्य एक सुरक्षित साइबर पारिस्थितिकी तंत्र और IT प्रणालियों, लेनदेन और सेवाओं में पर्याप्त विश्वास बनाना है। 2. यह अनिवार्य करती है कि सभी सरकारी मंत्रालय नीति के अधिनियमन के दो वर्षों के भीतर ISO 27001 प्रमाणीकरण लागू करें। 3. यह महत्वपूर्ण सूचना बुनियादी ढांचे की सुरक्षा के लिए राष्ट्रीय महत्वपूर्ण सूचना बुनियादी ढांचा संरक्षण केंद्र (NCIIPC) की स्थापना की परिकल्पना करती है। उपरोक्त में से कौन सा/से कथन सही है/हैं?
  1. 1, 2 and 3
  2. 2 and 3 only
  3. 1 only
  4. 1 and 3 only
  1. 1, 2 और 3
  2. केवल 2 और 3
  3. केवल 1
  4. केवल 1 और 3
Solutionसमाधान
India's National Cyber Security Policy, 2013 aims to create a secure cyber ecosystem and adequate trust (Statement 1 correct) and envisages the creation of NCIIPC to protect critical information infrastructure (Statement 3 correct). Statement 2 is incorrect — the policy does not specifically mandate ISO 27001 certification for all government ministries within two years; this is a fabricated detail not present in the policy.
भारत की राष्ट्रीय साइबर सुरक्षा नीति, 2013 एक सुरक्षित साइबर पारिस्थितिकी तंत्र बनाने का लक्ष्य रखती है (कथन 1 सही) और महत्वपूर्ण सूचना बुनियादी ढांचे की रक्षा के लिए NCIIPC की स्थापना की परिकल्पना करती है (कथन 3 सही)। कथन 2 गलत है — नीति विशेष रूप से सभी सरकारी मंत्रालयों के लिए दो वर्षों के भीतर ISO 27001 प्रमाणीकरण अनिवार्य नहीं करती; यह नीति में मौजूद नहीं है।

Solving path: Statement 1 — NCSP 2013 aims to create secure cyber ecosystem and trust = correct. Statement 2 — mandatory ISO 27001 for all ministries within two years = NOT in the policy, fabricated. Eliminate. Statement 3 — NCSP envisages NCIIPC creation = correct. Answer = D (1 and 3 only). Time: 30 seconds.


Common Mistakes


Related Topics


Practice on SarkariRise

Sign up + get 3 free mocks →