UPSC CSE के लिए साइबर सुरक्षा: डिजिटल अवसंरचना, कानूनी ढाँचा और उभरते खतरे

advanced 22 min read

अवधारणा

साइबर सुरक्षा को सरल शब्दों में समझो: जिस तरह एक किले की सुरक्षा के लिए दीवारें, दरवाज़े, पहरेदार और आंतरिक नियम होते हैं — उसी तरह डिजिटल दुनिया में डेटा, नेटवर्क, और प्रणालियों की सुरक्षा के लिए तकनीकी, कानूनी और संस्थागत व्यवस्था को साइबर सुरक्षा कहते हैं।

UPSC के नज़रिए से साइबर सुरक्षा का अर्थ केवल "हैकिंग रोकना" नहीं है। इसके तीन आयाम हैं:

पहला — तकनीकी आयाम: एन्क्रिप्शन, फ़ायरवॉल, Public Key Infrastructure (PKI), Quantum Key Distribution (QKD), और intrusion detection systems जैसे उपकरण।

दूसरा — संस्थागत आयाम: CERT-In, NCIIPC, NCCC जैसी संस्थाएँ जो खतरों की निगरानी और प्रतिक्रिया देती हैं।

तीसरा — कानूनी-नीतिगत आयाम: IT Act 2000, राष्ट्रीय साइबर सुरक्षा नीति 2013, और Digital Personal Data Protection (DPDP) Act 2023।

UPSC Prelims में इस विषय से प्रायः संस्थाओं की भूमिकाओं में अंतर, कानूनी प्रावधानों की सटीकता, और नई प्रौद्योगिकियों (जैसे QKD) की सीमाओं पर प्रश्न आते हैं। Mains GS-III में "आंतरिक सुरक्षा" के अंतर्गत साइबर आतंकवाद, महत्वपूर्ण अवसंरचना की सुरक्षा, और डेटा संप्रभुता पर विश्लेषणात्मक उत्तर माँगे जाते हैं।

एक महत्वपूर्ण बात — पर्यावरण विषय के संदर्भ में साइबर सुरक्षा का उभरता हुआ क्षेत्र है: जलवायु परिवर्तन और साइबर जोखिमों का परस्पर संबंध, तथा "Green Cybersecurity" की अवधारणा। यह UPSC 2024-25 के पाठ्यक्रम में विशेष प्रासंगिकता रखता है।


गहन विश्लेषण

भारत का साइबर सुरक्षा संस्थागत ढाँचा

संस्थाओं में अंतर जानना Prelims के लिए अनिवार्य है:

CERT-In (Indian Computer Emergency Response Team):

NCIIPC (National Critical Information Infrastructure Protection Centre):

NCCC (National Cyber Coordination Centre):

याद रखो: CERT-In = घटना प्रतिक्रिया, NCIIPC = महत्वपूर्ण अवसंरचना सुरक्षा, NCCC = real-time निगरानी।


Public Key Infrastructure (PKI)

PKI डिजिटल सुरक्षा की रीढ़ है। इसमें:

PKI का उपयोग: e-governance, digital signatures, online banking, और aadhaar authentication में।


IT Act 2000 की प्रमुख धाराएँ

| धारा | विषय | |------|------| | धारा 43 | अनाधिकृत computer access | | धारा 66 | computer-related अपराध (hacking) | | धारा 69 | सरकार की निगरानी शक्ति | | धारा 70 | Critical Information Infrastructure की सुरक्षा | | धारा 70A | NCIIPC की स्थापना | | धारा 70B | CERT-In की स्थापना |


Digital Personal Data Protection Act, 2023

DPDP Act 2023 भारत का पहला व्यापक डेटा संरक्षण कानून है। UPSC के लिए तीन बातें अनिवार्य:

1. क्षेत्रीय अनुप्रयोग (Territorial Scope): यह अधिनियम केवल भारत के भीतर नहीं, बल्कि भारत के बाहर भी लागू होता है यदि भारतीय व्यक्तियों को वस्तुएँ/सेवाएँ प्रदान की जाती हैं। यह extra-territorial application है।

2. Data Protection Board of India: यह न्यायनिर्णायक निकाय (adjudicating body) है जो शिकायतों पर निर्णय करती है।

3. Consent अनिवार्यता: Data Fiduciary को personal data process करने से पहले स्पष्ट सहमति लेनी होगी। Data Principal (जिसका डेटा है) को सहमति वापस लेने का अधिकार भी है।


राष्ट्रीय साइबर सुरक्षा नीति, 2013

दो कथन सत्य हैं, एक झूठा — यही UPSC का तरीका है:


Quantum Key Distribution (QKD)

QKD quantum mechanics के सिद्धांतों पर आधारित है:


जलवायु परिवर्तन और साइबर सुरक्षा का परस्पर संबंध

यह UPSC के पर्यावरण-प्रौद्योगिकी convergence का उत्कृष्ट उदाहरण है:

जलवायु साइबर जोखिम:

"Green Cybersecurity" के दो अर्थ:

  1. साइबर सुरक्षा operations का carbon footprint कम करना (energy-efficient data centers)
  2. पर्यावरण निगरानी और प्रबंधन प्रणालियों को साइबर हमलों से बचाना

ध्यान दो: Paris Agreement (2015) Green Cybersecurity को अनिवार्य नहीं करता — यह एक सामान्य मिथक है।


Industrial Control Systems (ICS) और पर्यावरणीय खतरे

जल शोधन संयंत्र, बाँध प्रबंधन, वायु प्रदूषण निगरानी — ये सभी ICS पर चलते हैं। इन पर साइबर हमला = पर्यावरणीय आपदा। इनकी सुरक्षा IT Act 2000 की धारा 70 के तहत आती है, न कि Environment Protection Act 1986 के तहत।


शॉर्टकट और युक्तियाँ

patternCERT-NCIIPC-NCCC त्रिभुज

तीनों संस्थाओं को उनके कार्य से जोड़ो:

CERT-In = Crash response (घटना के बाद) NCIIPC = Nation की critical infrastructure (पहले से सुरक्षा) NCCC = Now monitoring (real-time निगरानी)

Pattern: C → बाद में, N(CIIPC) → पहले से, N(CCC) → अभी।

Prelims में "critical infrastructure की सुरक्षा" वाला प्रश्न हमेशा NCIIPC होगा, CERT-In नहीं — यह गलती 60%+ परीक्षार्थी करते हैं। Standard confusion time: 30 seconds → इस pattern से: 5 seconds।

patternIT Act धाराओं की संख्या का क्रम

धाराएँ याद करो इस क्रम में: 43-66-69-70-70A-70B

"43 अनधिकृत access → 66 criminal hacking → 69 government surveillance → 70 critical infra → 70A NCIIPC → 70B CERT-In"

याद रखो: 70 = infrastructure, फिर 70A = NCIIPC (A = Advanced protection), 70B = CERT-In (B = Breaking response)।

Standard method: रटना (3 बार revise) → इस pattern से: एक बार पढ़ो, टिका रहेगा।

eliminationDPDP Act 2023 — कौन सा कथन सत्य है

UPSC में DPDP Act पर तीन प्रकार के झूठे कथन आते हैं:

  1. "केवल भारत के भीतर लागू" → झूठ (extra-territorial है)
  2. "Data Protection Board न्यायिक नहीं, advisory है" → झूठ (adjudicating body है)
  3. "सहमति की आवश्यकता नहीं यदि legitimate interest हो" → आंशिक सत्य (exceptions हैं, लेकिन general rule = consent अनिवार्य)

Elimination: कोई भी कथन जो DPDP Act को "केवल territorial" बताए → तुरंत eliminate करो।

Step count: 4 options पढ़ना → 1 eliminate → 3 check → standard: 60s, shortcut: 20s।

eliminationQKD की सीमा — 'पूर्ण प्रतिस्थापन' का罗जाल

UPSC QKD पर हमेशा एक "QKD classical cryptography को पूरी तरह replace करता है" वाला कथन देता है — यह हमेशा गलत है।

कारण याद करो: QKD = distance-limited, cost-heavy, infrastructure-dependent। इसलिए classical methods के साथ supplementary रूप में चलता है।

जब भी कोई कथन कहे "QKD ने RSA/classical crypto को replace कर दिया" → सीधे eliminate करो। यह 4-statement question में 30 seconds बचाता है।

eliminationParis Agreement और Green Cybersecurity — जाल

"Paris Agreement 2015 ने Green Cybersecurity अनिवार्य किया" — यह हमेशा गलत है।

Paris Agreement = GHG emissions कम करना, adaptation, finance। Cybersecurity का इससे कोई direct mandate नहीं।

Rule: कोई भी कथन जो Paris Agreement को cybersecurity से सीधे जोड़े → eliminate। Time saved: 15 seconds per option।


तेज़-समाधान रूपरेखा

Prelims में साइबर सुरक्षा प्रश्न को हल करने का निर्णय वृक्ष:

चरण 1: क्या प्रश्न किसी संस्था की भूमिका पूछ रहा है?

चरण 2: क्या प्रश्न DPDP Act 2023 पर है?

चरण 3: क्या प्रश्न QKD या नई तकनीक पर है?

चरण 4: क्या प्रश्न जलवायु-साइबर संबंध पर है?

Mains के लिए: हर उत्तर में तीन layers दो — तकनीकी पहलू + संस्थागत ढाँचा + नीतिगत/कानूनी प्रावधान।


हल किए गए PYQs

क्यों यह प्रश्न: PKI की परिभाषा और संदर्भ पर UPSC का सीधा factual प्रश्न — यहाँ confusion "public infrastructure" और "digital security infrastructure" के बीच होती है।

समाधान का रास्ता: PKI में "Public" का अर्थ "सार्वजनिक" नहीं बल्कि "Public Key" से है — यह पूरी तरह digital security का domain है। बाकी तीन options (स्वास्थ्य, खाद्य, दूरसंचार) में PKI का कोई technical अर्थ नहीं होता। सीधे Option A।

Previous Year Questionपिछले वर्ष का प्रश्न2020
In India, the term "Public Key Infrastructure" is used in the context of
भारत में "पब्लिक की इन्फ्रास्ट्रक्चर" (Public Key Infrastructure) शब्द किस संदर्भ में इस्तेमाल किया जाता है?
  1. Digital security infrastructure
  2. Health care and education infrastructure
  3. Food security infrastructure
  4. Telecommunication and transportation infrastructure
  1. डिजिटल सुरक्षा इन्फ्रास्ट्रक्चर
  2. स्वास्थ्य और शिक्षा इन्फ्रास्ट्रक्चर
  3. खाद्य सुरक्षा इन्फ्रास्ट्रक्चर
  4. दूरसंचार और परिवहन इन्फ्रास्ट्रक्चर
Solutionसमाधान
Public Key Infrastructure (PKI) is used in the context of digital security infrastructure for secure electronic transfer of information through digital certificates and cryptography.

क्यों यह प्रश्न: CERT-In बनाम NCIIPC की भूमिका — UPSC का सबसे बार-बार आने वाला confusion। "Critical information infrastructure protection" के लिए exact धारा और संस्था जाननी चाहिए।

समाधान का रास्ता: CERT-In = incident response (धारा 70B), NCCC = real-time monitoring — लेकिन "critical information infrastructure की सुरक्षा" का statutory mandate = NCIIPC (धारा 70A)। Option C सीधा।

Previous Year Questionपिछले वर्ष का प्रश्न
Which Indian government body is primarily responsible for protecting critical information infrastructure, including systems related to environmental monitoring?
पर्यावरण निगरानी से जुड़े सिस्टम सहित महत्वपूर्ण सूचना अवसंरचना की सुरक्षा के लिए मुख्य रूप से कौन सी भारतीय सरकारी संस्था जिम्मेदार है?
  1. Cyber and Information Security Division of MHA
  2. National Cyber Coordination Centre (NCCC)
  3. National Critical Information Infrastructure Protection Centre (NCIIPC)
  4. Indian Computer Emergency Response Team (CERT-In)
  1. MHA का Cyber and Information Security Division
  2. National Cyber Coordination Centre (NCCC)
  3. National Critical Information Infrastructure Protection Centre (NCIIPC)
  4. Indian Computer Emergency Response Team (CERT-In)
Solutionसमाधान
NCIIPC, established under Section 70A of the Information Technology Act, 2000, is India's designated agency for protecting critical information infrastructure, which includes sectors such as energy, water, and environment. CERT-In handles incident response, while NCCC focuses on real-time threat monitoring.
NCIIPC, सूचना प्रौद्योगिकी अधिनियम 2000 की धारा 70A के तहत स्थापित, भारत की वह नामित संस्था है जो महत्वपूर्ण सूचना अवसंरचना की रक्षा करती है, जिसमें ऊर्जा, जल और पर्यावरण जैसे क्षेत्र शामिल हैं। CERT-In घटना प्रतिक्रिया संभालता है, जबकि NCCC वास्तविक समय के खतरों की निगरानी पर केंद्रित है।

क्यों यह प्रश्न: जलवायु-साइबर nexus पर UPSC का बहुकथन प्रश्न — कथन 2 ("जलवायु शरणार्थी साइबर अपराधी बनते हैं") एक unsubstantiated generalization है जिसे eliminate करना है।

समाधान का रास्ता: कथन 1 सत्य — extreme weather → data center damage → security gap। कथन 3 सत्य — subsea cables वैश्विक internet का 95%+ वहन करती हैं, sea-level rise से खतरा confirmed है। कथन 2 गलत — यह कोई recognized policy position नहीं है, बल्कि एक unfounded generalization है। → Option A (केवल 1 और 3)।

Previous Year Questionपिछले वर्ष का प्रश्न
Consider the following statements about the relationship between climate change and cybersecurity: 1. Extreme weather events can physically damage cybersecurity infrastructure, creating exploitable vulnerabilities. 2. Climate refugees moving to urban areas can increase the pool of cybercriminals. 3. Disruption of undersea communication cables by rising sea levels is a recognized climate-cyber risk. Which of the statements given above is/are correct?
जलवायु परिवर्तन और साइबर सुरक्षा के बीच संबंध के बारे में निम्नलिखित कथनों पर विचार कीजिए: 1. अत्यधिक मौसमी घटनाएं साइबर सुरक्षा अवसंरचना को भौतिक रूप से नुकसान पहुंचा सकती हैं, जिससे शोषण योग्य कमजोरियां पैदा होती हैं। 2. शहरी इलाकों में आने वाले जलवायु शरणार्थी साइबर अपराधियों की संख्या बढ़ा सकते हैं। 3. समुद्र के बढ़ते जलस्तर से समुद्र के नीचे बिछी संचार केबलों का बाधित होना एक मान्यता प्राप्त जलवायु-साइबर जोखिम है। ऊपर दिए गए कथनों में से कौन सा/से सही है/हैं?
  1. 1 and 3 only
  2. 1, 2, and 3
  3. 2 and 3 only
  4. 1 only
  1. केवल 1 और 3
  2. 1, 2 और 3
  3. केवल 2 और 3
  4. केवल 1
Solutionसमाधान
Statement 1 is correct: extreme weather such as floods and storms can damage data centres and communication infrastructure, creating security gaps. Statement 3 is correct: rising sea levels and stronger storms threaten undersea fiber optic cables, which carry over 95% of global internet traffic, representing a recognized climate-cyber risk. Statement 2 is an unfounded generalization and not a recognized policy position.
कथन 1 सही है: बाढ़ और तूफान जैसी चरम मौसम घटनाएं डेटा केंद्रों और संचार अवसंरचना को नुकसान पहुंचा सकती हैं, जिससे सुरक्षा अंतराल उत्पन्न होते हैं। कथन 3 सही है: बढ़ते समुद्र स्तर और तेज तूफान समुद्री फाइबर ऑप्टिक केबलों को खतरे में डालते हैं, जो वैश्विक इंटरनेट ट्रैफिक का 95% से अधिक वहन करते हैं। कथन 2 एक निराधार सामान्यीकरण है और कोई मान्यता प्राप्त नीतिगत स्थिति नहीं है।

क्यों यह प्रश्न: ICS पर साइबर हमले और applicable कानून — Environment Protection Act और IT Act के बीच confusion test करता है।

समाधान का रास्ता: यह पर्यावरणीय खतरा है, लेकिन खतरे का माध्यम cyber है। इसलिए applicable कानून = IT Act 2000 (धारा 70 — critical infrastructure)। EPA 1986 environmental standards के लिए है, cyber threats के लिए नहीं। → Option A।

Previous Year Questionपिछले वर्ष का प्रश्न
Cyber attacks on Industrial Control Systems (ICS) managing water treatment plants pose a direct environmental threat. Which Indian legislation primarily governs the cybersecurity of such critical infrastructure?
जल शोधन संयंत्रों का प्रबंधन करने वाले Industrial Control Systems (ICS) पर साइबर हमले सीधे पर्यावरणीय खतरा पैदा करते हैं। ऐसी महत्वपूर्ण अवसंरचना की साइबर सुरक्षा मुख्य रूप से किस भारतीय कानून के अंतर्गत आती है?
  1. Information Technology Act, 2000
  2. Environment Protection Act, 1986
  3. National Water Policy, 2012
  4. Disaster Management Act, 2005
  1. Information Technology Act, 2000
  2. Environment Protection Act, 1986
  3. National Water Policy, 2012
  4. Disaster Management Act, 2005
Solutionसमाधान
The Information Technology Act, 2000 (amended 2008) is India's primary legislation governing cybersecurity, including protection of critical information infrastructure under Section 70, which covers systems like water treatment plants. The Environment Protection Act deals with environmental standards, not cyber threats.
सूचना प्रौद्योगिकी अधिनियम, 2000 (2008 में संशोधित) भारत का प्राथमिक साइबर सुरक्षा कानून है, जिसकी धारा 70 के तहत जल उपचार संयंत्रों जैसी महत्वपूर्ण सूचना अवसंरचना की सुरक्षा की जाती है। पर्यावरण संरक्षण अधिनियम पर्यावरणीय मानकों से संबंधित है, साइबर खतरों से नहीं।

क्यों यह प्रश्न: DPDP Act 2023 पर तीन कथनों का प्रश्न — कथन 1 की territorial scope गलती सबसे आम है।

समाधान का रास्ता: कथन 1 गलत — DPDP Act extra-territorial है (भारत के बाहर भी लागू यदि भारतीयों को सेवाएँ दी जाएँ)। कथन 2 सही — Data Protection Board of India adjudicating body है। कथन 3 सही — consent अनिवार्य है। → Option B (केवल 2 और 3)।

Previous Year Questionपिछले वर्ष का प्रश्न
With reference to India's Personal Data Protection framework, which of the following statements is/are correct regarding the Digital Personal Data Protection Act, 2023? 1. The Act applies only to digital personal data processed within the territory of India. 2. The Act establishes a Data Protection Board of India as an adjudicatory body. 3. The Act mandates that data fiduciaries obtain explicit consent before processing personal data. Select the correct answer using the code given below:
भारत के व्यक्तिगत डेटा संरक्षण ढांचे के संदर्भ में, डिजिटल व्यक्तिगत डेटा संरक्षण अधिनियम, 2023 के बारे में निम्नलिखित में से कौन सा/से कथन सही है/हैं? 1. अधिनियम केवल भारत के क्षेत्र के भीतर संसाधित डिजिटल व्यक्तिगत डेटा पर लागू होता है। 2. अधिनियम एक न्यायनिर्णायक निकाय के रूप में भारत के डेटा संरक्षण बोर्ड की स्थापना करता है। 3. अधिनियम अनिवार्य करता है कि डेटा फिड्यूशियरी व्यक्तिगत डेटा को संसाधित करने से पहले स्पष्ट सहमति प्राप्त करें। नीचे दिए गए कोड का उपयोग करके सही उत्तर चुनें:
  1. 1 and 3 only
  2. 2 and 3 only
  3. 1 and 2 only
  4. 1, 2 and 3
  1. केवल 1 और 3
  2. केवल 2 और 3
  3. केवल 1 और 2
  4. 1, 2 और 3
Solutionसमाधान
The Digital Personal Data Protection Act, 2023 applies to digital personal data processed both within India AND outside India if it involves offering goods/services to individuals in India (extra-territorial application), so Statement 1 is incorrect. The Act does establish the Data Protection Board of India (Statement 2 correct) and mandates consent before processing personal data (Statement 3 correct). Hence only 2 and 3 are correct.
डिजिटल व्यक्तिगत डेटा संरक्षण अधिनियम, 2023 भारत के भीतर और बाहर दोनों जगह संसाधित डिजिटल व्यक्तिगत डेटा पर लागू होता है, यदि यह भारत में व्यक्तियों को वस्तुएं/सेवाएं प्रदान करने से संबंधित हो (अतिरिक्त-क्षेत्रीय अनुप्रयोग)। अतः कथन 1 गलत है। अधिनियम डेटा संरक्षण बोर्ड की स्थापना करता है (कथन 2 सही) और व्यक्तिगत डेटा संसाधन से पहले सहमति अनिवार्य करता है (कथन 3 सही)। अतः केवल 2 और 3 सही हैं।

क्यों यह प्रश्न: QKD की तकनीकी समझ और व्यावहारिक सीमाओं पर UPSC का प्रश्न — कथन 3 में "पूर्ण प्रतिस्थापन" वाला जाल।

समाधान का रास्ता: कथन 1 सही — QKD quantum mechanics (uncertainty principle, entanglement) पर आधारित है। कथन 2 सही — DRDO और C-DOT के QKD trials documented हैं। कथन 3 गलत — QKD distance, cost, और infrastructure constraints के कारण classical methods को पूरी तरह replace नहीं करता। → Option D (केवल 1 और 2)।

Previous Year Questionपिछले वर्ष का प्रश्न
With reference to 'Quantum Key Distribution (QKD)' in the context of cyber security, consider the following statements: 1. QKD uses principles of quantum mechanics to create theoretically unbreakable encryption keys. 2. India's DRDO and C-DOT have conducted successful QKD trials for secure communication. 3. QKD completely replaces classical cryptography methods such as RSA in all practical applications. Which of the statements given above is/are correct?
साइबर सुरक्षा के संदर्भ में 'Quantum Key Distribution (QKD)' के बारे में निम्नलिखित कथनों पर विचार करें: 1. QKD सैद्धांतिक रूप से अटूट एन्क्रिप्शन कुंजियाँ बनाने के लिए क्वांटम यांत्रिकी के सिद्धांतों का उपयोग करता है। 2. भारत के DRDO और C-DOT ने सुरक्षित संचार के लिए सफल QKD परीक्षण किए हैं। 3. QKD सभी व्यावहारिक अनुप्रयोगों में RSA जैसी शास्त्रीय क्रिप्टोग्राफी विधियों को पूरी तरह से प्रतिस्थापित करता है। उपरोक्त में से कौन सा/से कथन सही है/हैं?
  1. 1 and 3 only
  2. 2 and 3 only
  3. 1, 2 and 3
  4. 1 and 2 only
  1. केवल 1 और 3
  2. केवल 2 और 3
  3. 1, 2 और 3
  4. केवल 1 और 2
Solutionसमाधान
QKD uses quantum mechanical principles (photon polarization, quantum entanglement) to create encryption keys that are theoretically secure because any eavesdropping disturbs the quantum state and is detectable. India's DRDO and C-DOT have conducted QKD trials. However, Statement 3 is incorrect — QKD does not completely replace classical cryptography in all practical applications; it has limitations related to distance, cost, and infrastructure, and is currently used alongside classical methods.
QKD क्वांटम यांत्रिकी सिद्धांतों (फोटॉन ध्रुवीकरण, क्वांटम उलझाव) का उपयोग करके सैद्धांतिक रूप से सुरक्षित एन्क्रिप्शन कुंजियाँ बनाता है क्योंकि कोई भी जासूसी क्वांटम अवस्था को बाधित करती है और पता लगाई जा सकती है। भारत के DRDO और C-DOT ने QKD परीक्षण किए हैं। हालांकि, कथन 3 गलत है — QKD सभी व्यावहारिक अनुप्रयोगों में शास्त्रीय क्रिप्टोग्राफी को पूरी तरह से प्रतिस्थापित नहीं करता; दूरी, लागत और बुनियादी ढांचे की सीमाओं के कारण इसे शास्त्रीय विधियों के साथ उपयोग किया जाता है।

क्यों यह प्रश्न: राष्ट्रीय साइबर सुरक्षा नीति 2013 के प्रावधानों की सटीकता — कथन 2 में ISO 27001 की "दो वर्षों में अनिवार्यता" एक invented provision है।

समाधान का रास्ता: कथन 1 सही — नीति का core objective सुरक्षित cyber ecosystem और IT systems में विश्वास बनाना है। कथन 2 गलत — नीति में ISO 27001 certification की कोई specific two-year deadline नहीं है। कथन 3 सही — NCIIPC की स्थापना की परिकल्पना नीति में है। → Option D (केवल 1 और 3)।

Previous Year Questionपिछले वर्ष का प्रश्न
Consider the following regarding India's National Cyber Security Policy, 2013: 1. It aims to create a secure cyber ecosystem and adequate trust in IT systems, transactions and services. 2. It mandates that all government ministries implement ISO 27001 certification within two years of the policy's enactment. 3. It envisages creation of a National Critical Information Infrastructure Protection Centre (NCIIPC). Which of the statements given above is/are correct?
भारत की राष्ट्रीय साइबर सुरक्षा नीति, 2013 के बारे में निम्नलिखित पर विचार करें: 1. इसका उद्देश्य एक सुरक्षित साइबर पारिस्थितिकी तंत्र और IT प्रणालियों, लेनदेन और सेवाओं में पर्याप्त विश्वास बनाना है। 2. यह अनिवार्य करती है कि सभी सरकारी मंत्रालय नीति के अधिनियमन के दो वर्षों के भीतर ISO 27001 प्रमाणीकरण लागू करें। 3. यह महत्वपूर्ण सूचना बुनियादी ढांचे की सुरक्षा के लिए राष्ट्रीय महत्वपूर्ण सूचना बुनियादी ढांचा संरक्षण केंद्र (NCIIPC) की स्थापना की परिकल्पना करती है। उपरोक्त में से कौन सा/से कथन सही है/हैं?
  1. 1, 2 and 3
  2. 2 and 3 only
  3. 1 only
  4. 1 and 3 only
  1. 1, 2 और 3
  2. केवल 2 और 3
  3. केवल 1
  4. केवल 1 और 3
Solutionसमाधान
India's National Cyber Security Policy, 2013 aims to create a secure cyber ecosystem and adequate trust (Statement 1 correct) and envisages the creation of NCIIPC to protect critical information infrastructure (Statement 3 correct). Statement 2 is incorrect — the policy does not specifically mandate ISO 27001 certification for all government ministries within two years; this is a fabricated detail not present in the policy.
भारत की राष्ट्रीय साइबर सुरक्षा नीति, 2013 एक सुरक्षित साइबर पारिस्थितिकी तंत्र बनाने का लक्ष्य रखती है (कथन 1 सही) और महत्वपूर्ण सूचना बुनियादी ढांचे की रक्षा के लिए NCIIPC की स्थापना की परिकल्पना करती है (कथन 3 सही)। कथन 2 गलत है — नीति विशेष रूप से सभी सरकारी मंत्रालयों के लिए दो वर्षों के भीतर ISO 27001 प्रमाणीकरण अनिवार्य नहीं करती; यह नीति में मौजूद नहीं है।

क्यों यह प्रश्न: Green Cybersecurity की दोहरी परिभाषा और Paris Agreement से इसके संबंध की जाँच।

समाधान का रास्ता: कथन 1 सही — carbon footprint कम करना Green Cybersecurity का एक आयाम है। कथन 2 सही — environmental monitoring infrastructure की cyber protection दूसरा आयाम है। कथन 3 गलत — Paris Agreement 2015 जलवायु शमन के लिए है, इसमें cybersecurity का कोई mandate नहीं। → Option A (केवल 1 और 2)।

Previous Year Questionपिछले वर्ष का प्रश्न
Consider the following statements regarding 'Green Cybersecurity': 1. It refers to reducing the carbon footprint of cybersecurity operations. 2. It involves protecting environmental monitoring and management infrastructure from cyber attacks. 3. It is mandated under the Paris Agreement (2015). Which of the statements given above is/are correct?
'Green Cybersecurity' के संदर्भ में निम्नलिखित कथनों पर विचार कीजिए: 1. इसका अर्थ है साइबर सुरक्षा कार्यों के कार्बन फुटप्रिंट को कम करना। 2. इसमें पर्यावरण निगरानी और प्रबंधन अवसंरचना को साइबर हमलों से बचाना शामिल है। 3. यह Paris Agreement (2015) के तहत अनिवार्य है। ऊपर दिए गए कथनों में से कौन सा/से सही है/हैं?
  1. 1 and 2 only
  2. 2 and 3 only
  3. 1 only
  4. 1, 2 and 3
  1. केवल 1 और 2
  2. केवल 2 और 3
  3. केवल 1
  4. 1, 2 और 3
Solutionसमाधान
Green Cybersecurity encompasses both reducing the energy/carbon footprint of cybersecurity infrastructure (Statement 1) and protecting environmental management systems from cyber threats (Statement 2). Statement 3 is incorrect as the Paris Agreement (2015) deals with climate change mitigation and does not mandate green cybersecurity practices.
ग्रीन साइबर सुरक्षा में साइबर सुरक्षा अवसंरचना के ऊर्जा/कार्बन फुटप्रिंट को कम करना (कथन 1) और पर्यावरण प्रबंधन प्रणालियों को साइबर खतरों से बचाना (कथन 2) दोनों शामिल हैं। कथन 3 गलत है क्योंकि पेरिस समझौता (2015) जलवायु परिवर्तन शमन से संबंधित है और ग्रीन साइबर सुरक्षा को अनिवार्य नहीं करता।

आम गलतियाँ


संबंधित विषय

SarkariRise पर अभ्यास

Sign up + get 3 free mocks →