Revision summary
Cyber security elements are confidentiality, integrity, availability, authentication, human process, supply chain, and legal institutions. India’s notified document is the National Cyber Security Policy 2013. A National Cyber Security Strategy was discussed around 2020; a complete public successor was not firmly in force as a single comprehensive charter by 2022. Operational bodies include CERT-In, NCIIPC and I4C, plus sector regulators. Gaps remain in MSME/hospital security, skills, supply chain and fragmented law.
Model answer
Introduction
Cyber security is the protection of networks, devices, data and people from unauthorised access and disruption. It is not only a firewall. India has a National Cyber Security Policy, 2013, a CERT-In, sectoral CERTs, and years of discussion of a fuller National Cyber Security Strategy (a public draft conversation around 2020). Comprehensive on paper is not the same as comprehensive in every ministry and firm.
Body
Elements of cyber security
- Confidentiality: secrets and personal data stay with those allowed (encryption, access control). The Digital Personal Data Protection trajectory later added a legal overlay; in 2022 the IT Act and SPDI rules were still the main personal-data peg.
- Integrity: data and software are not silently altered (hashing, signing, secure updates).
- Availability: systems stay up under attack (DDoS defence, backups, redundancy)—critical for power, payments and hospitals.
- Authentication and identity: who is at the keyboard; Aadhaar and e-sign help citizens but also enlarge the target.
- People and process: phishing is still the usual door; training, least privilege, and incident response matter as much as tools.
- Physical and supply chain: devices, undersea cables, and hardware/software provenance.
- Legal-institutional: offences, MLATs, CERT-In directions, and sector regulators (RBI for banks, CERT-In for incident reporting).
- Offensive-defensive balance: attribution, critical-information-infrastructure protection under the NCIIPC, and military cyber commands as a separate but related layer.
How far a comprehensive National Cyber Security Strategy?
- 2013 Policy: the notified National Cyber Security Policy set aims—secure computing, 24×7 CERT-In, manpower, and public–private partnership. It was a policy, light on dated targets, budgets and ministry-by-ministry duties.
- 2020 discussion: the National Security Council Secretariat process and a draft National Cyber Security Strategy around 2020 sought to update 2013 for 5G, cloud, supply chain, and a whole-of-nation approach. A single, fully notified, publicly detailed successor strategy was still awaited / partial in public domain at the time of the 2022 paper—candidates should not invent a gazette date that did not exist.
- What does exist in practice: CERT-In (including 2022-type incident-reporting directions), NCIIPC for critical infrastructure, I4C (Indian Cyber Crime Coordination Centre), State cyber police, National Critical Information Infrastructure notifications, RBI/SEBI/IRDAI circulars, and Defence cyber capacity.
- Gaps versus ‘comprehensive’: uneven State capacity; MSME and hospital security; supply-chain assurance for telecom; shortage of skilled analysts; fragmented laws (IT Act 2000 amendments vs a dedicated cyber security statute); and the tension between CERT-In logging directions and privacy/startup cost.
- Verdict: India has a policy (2013) plus a dense operational stack, and a strategy still more discussed than finally, fully public as one binding 2020 text. It is substantial but not yet one comprehensive, uniformly implemented national strategy.
What would make it comprehensive
- One public strategy with roles, funds, and review dates; cyber hygiene for MSMEs; supply-chain rules; and judicial capacity—without treating every citizen log as a security win.
Flow diagram
flowchart TD E[CIA identity people supply chain] --> CS[Cyber security] P2013[NCSP 2013] --> CS D2020[Strategy discussion 2020] --> CS O[CERT-In NCIIPC I4C] --> CS G[Gaps MSME supply chain skills law] --> CS
Conclusion
Cyber security is confidentiality, integrity, availability, identity, people, supply chain and law. India notified a 2013 policy and built CERT-In, NCIIPC and I4C. A full National Cyber Security Strategy was under discussion around 2020 and was not yet a complete, uniformly applied public charter by the 2022 exam window. The stack is real; the single strategy is unfinished.
Quick related
Students also ask
-
Naxalism is a social, economic and developmental issue manifesting as a violent internal security threat. In this context, discuss the emerging issues gest a multilayered strategy to tackle the menace of Naxalism.
Next question in the 2022 paper (Q20). View answer →
-
Is the 2013 document a ‘strategy’?
It is a policy. A strategy usually adds threats, resources, timelines and roles. That fuller NCSS text was still in process around 2020.
-
Does CERT-In equal comprehensive national cyber security?
CERT-In is the incident node. Comprehensive security also needs NCIIPC, police, regulators, firms and users.
PYQ trend
When UPSC asked this
Related PYQs from other years, newest first. Open a question to read it.
-
2021 · Q9 · GS III · 10 marks
Discuss how emerging technologies and globalisation contribute to money laundering. Elaborate measures to tackle the problem of money laundering both at national and international levels. -
2021 · Q10 · GS III · 10 marks
Keeping in view India's internal security, analyse the impact of cross-border cyber attacks. Also discuss defensive measures against these sophisticated attacks. -
2020 · Q9 · GS III · 10 marks
Discuss different types of cybercrimes and measures required to be taken to fight the menace. -
2019 · Q10 · GS III · 10 marks
What is CyberDome Project? Explain how it can be useful in controlling internet crimes in India. -
2018 · Q19 · GS III · 15 marks
Data security has assumed significant importance in the digitized world due to rising cyber-crimes. The Justice B. N. Srikrishna Committee Report addresses issues related to data security. What, in your view, are the strengths and weaknesses of the Report relating to protection of personal data in cyber space? (250 Words, 15 Marks). -
2018 · Q20 · GS III · 15 marks
India's proximity to two of the world's biggest illicit opium-growing states has enhanced her internal security concerns. Explain the linkages between drug trafficking and other illicit activities such as gunrunning, money laundering and human trafficking. What countermeasures should be taken to prevent the same? (250 Words, 15 Marks). -
2017 · Q9 · GS III · 10 marks
Discuss the potential threats of Cyber attack and the security framework to prevent it. -
2015 · Q18 · GS III · 12 marks
Religious indoctrination via social media has resulted in Indian youth joining the ISIS. What is ISIS and its mission? How can ISIS be dangerous to the internal security of our country.
More from this paper
Q1 · UPSC Mains 2022 · GS III · 10 marks
Why is Public Private Partnership (PPP) required in infrastructural projects ? Examine the role of PPP model in the redevelopment of Railway Stations in India.
Infrastructure
PPP is needed because public budgets cannot finance all long-life infrastructure on time, and private partners bring capital and operating skill. Risk and revenue are split by contract: the State keeps policy and often land; the concessionaire takes construction and commercial risk. Railway station redevelopment uses that split: trains stay with Indian Railways; buildings and retail can be private. IRSDC and railway SPVs bid packages; Habibganj (Rani Kamalapati) is an early example. PM Gati Shakti is meant to connect those stations to other modes. Small-town stations may still need public viability support.
Q2 · UPSC Mains 2022 · GS III · 10 marks
Is inclusive growth possible under market economy ? State the significance of financial inclusion in achieving economic growth in India.
Inclusive Growth
A market economy does not by itself deliver inclusive growth; it rewards those who already hold assets. Inclusion is possible when the State provides public goods and repairs missing credit and insurance markets. India pairs liberalisation with MGNREGA, NFSA 2013 and Direct Benefit Transfer. Financial inclusion (Jan Dhan, JAM, UPI, Mudra, PM-Kisan) channels savings, cuts leakage and supports demand. Significance for growth depends on actual use of accounts and fair credit, not on account-opening numbers alone.
Q3 · UPSC Mains 2022 · GS III · 10 marks
What are the major challenges of Public Distribution System (PDS) in India ? How can it be made effective and transparent ?
Farm Subsidies and PDS
PDS under NFSA 2013 is a legal grain entitlement, not a discretionary dole. Main challenges are wrong lists, diversion, poor quality, weak last-mile shops, and a rice-wheat nutrition gap. Migrants lose access when the card is locked to one State. Effectiveness needs computerised supply chains, e-PoS, One Nation One Ration Card, social audits, and exception rules when biometrics fail. DBT can complement urban PDS; it is a poor substitute where food markets are thin.
Toppers' copies
Toppers' copies for this question will be uploaded soon.