Q19 · UPSC Civil Services Mains 2022 · GS III · 15 marks · 3 min read

← Q18 Q20 →

What are the different elements of cyber security ? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy.

Topic: Cyber Security and Money Laundering. Syllabus: Challenges to internal security through communication networks, role of media and social networking sites in internal security challenges, basics of cyber security; money-laundering and its prevention. Same official PYQ from year-wise 2022 and Cyber Security and Money Laundering.

Revision summary

Cyber security elements are confidentiality, integrity, availability, authentication, human process, supply chain, and legal institutions. India’s notified document is the National Cyber Security Policy 2013. A National Cyber Security Strategy was discussed around 2020; a complete public successor was not firmly in force as a single comprehensive charter by 2022. Operational bodies include CERT-In, NCIIPC and I4C, plus sector regulators. Gaps remain in MSME/hospital security, skills, supply chain and fragmented law.

Model answer

Introduction

Cyber security is the protection of networks, devices, data and people from unauthorised access and disruption. It is not only a firewall. India has a National Cyber Security Policy, 2013, a CERT-In, sectoral CERTs, and years of discussion of a fuller National Cyber Security Strategy (a public draft conversation around 2020). Comprehensive on paper is not the same as comprehensive in every ministry and firm.

Body

Elements of cyber security

  • Confidentiality: secrets and personal data stay with those allowed (encryption, access control). The Digital Personal Data Protection trajectory later added a legal overlay; in 2022 the IT Act and SPDI rules were still the main personal-data peg.
  • Integrity: data and software are not silently altered (hashing, signing, secure updates).
  • Availability: systems stay up under attack (DDoS defence, backups, redundancy)—critical for power, payments and hospitals.
  • Authentication and identity: who is at the keyboard; Aadhaar and e-sign help citizens but also enlarge the target.
  • People and process: phishing is still the usual door; training, least privilege, and incident response matter as much as tools.
  • Physical and supply chain: devices, undersea cables, and hardware/software provenance.
  • Legal-institutional: offences, MLATs, CERT-In directions, and sector regulators (RBI for banks, CERT-In for incident reporting).
  • Offensive-defensive balance: attribution, critical-information-infrastructure protection under the NCIIPC, and military cyber commands as a separate but related layer.

How far a comprehensive National Cyber Security Strategy?

  • 2013 Policy: the notified National Cyber Security Policy set aims—secure computing, 24×7 CERT-In, manpower, and public–private partnership. It was a policy, light on dated targets, budgets and ministry-by-ministry duties.
  • 2020 discussion: the National Security Council Secretariat process and a draft National Cyber Security Strategy around 2020 sought to update 2013 for 5G, cloud, supply chain, and a whole-of-nation approach. A single, fully notified, publicly detailed successor strategy was still awaited / partial in public domain at the time of the 2022 paper—candidates should not invent a gazette date that did not exist.
  • What does exist in practice: CERT-In (including 2022-type incident-reporting directions), NCIIPC for critical infrastructure, I4C (Indian Cyber Crime Coordination Centre), State cyber police, National Critical Information Infrastructure notifications, RBI/SEBI/IRDAI circulars, and Defence cyber capacity.
  • Gaps versus ‘comprehensive’: uneven State capacity; MSME and hospital security; supply-chain assurance for telecom; shortage of skilled analysts; fragmented laws (IT Act 2000 amendments vs a dedicated cyber security statute); and the tension between CERT-In logging directions and privacy/startup cost.
  • Verdict: India has a policy (2013) plus a dense operational stack, and a strategy still more discussed than finally, fully public as one binding 2020 text. It is substantial but not yet one comprehensive, uniformly implemented national strategy.

What would make it comprehensive

  • One public strategy with roles, funds, and review dates; cyber hygiene for MSMEs; supply-chain rules; and judicial capacity—without treating every citizen log as a security win.

Flow diagram

flowchart TD
  E[CIA identity people supply chain] --> CS[Cyber security]
  P2013[NCSP 2013] --> CS
  D2020[Strategy discussion 2020] --> CS
  O[CERT-In NCIIPC I4C] --> CS
  G[Gaps MSME supply chain skills law] --> CS

Conclusion

Cyber security is confidentiality, integrity, availability, identity, people, supply chain and law. India notified a 2013 policy and built CERT-In, NCIIPC and I4C. A full National Cyber Security Strategy was under discussion around 2020 and was not yet a complete, uniformly applied public charter by the 2022 exam window. The stack is real; the single strategy is unfinished.

Quick related

Students also ask

PYQ trend

When UPSC asked this

Related PYQs from other years, newest first. Open a question to read it.

  1. 2021 · Q9 · GS III · 10 marks

    Discuss how emerging technologies and globalisation contribute to money laundering. Elaborate measures to tackle the problem of money laundering both at national and international levels.

    View answer →

  2. 2021 · Q10 · GS III · 10 marks

    Keeping in view India's internal security, analyse the impact of cross-border cyber attacks. Also discuss defensive measures against these sophisticated attacks.

    View answer →

  3. 2020 · Q9 · GS III · 10 marks

    Discuss different types of cybercrimes and measures required to be taken to fight the menace.

    View answer →

  4. 2019 · Q10 · GS III · 10 marks

    What is CyberDome Project? Explain how it can be useful in controlling internet crimes in India.

    View answer →

  5. 2018 · Q19 · GS III · 15 marks

    Data security has assumed significant importance in the digitized world due to rising cyber-crimes. The Justice B. N. Srikrishna Committee Report addresses issues related to data security. What, in your view, are the strengths and weaknesses of the Report relating to protection of personal data in cyber space? (250 Words, 15 Marks).

    View answer →

  6. 2018 · Q20 · GS III · 15 marks

    India's proximity to two of the world's biggest illicit opium-growing states has enhanced her internal security concerns. Explain the linkages between drug trafficking and other illicit activities such as gunrunning, money laundering and human trafficking. What countermeasures should be taken to prevent the same? (250 Words, 15 Marks).

    View answer →

  7. 2017 · Q9 · GS III · 10 marks

    Discuss the potential threats of Cyber attack and the security framework to prevent it.

    View answer →

  8. 2015 · Q18 · GS III · 12 marks

    Religious indoctrination via social media has resulted in Indian youth joining the ISIS. What is ISIS and its mission? How can ISIS be dangerous to the internal security of our country.

    View answer →

More from this paper

Q1 · UPSC Mains 2022 · GS III · 10 marks

Why is Public Private Partnership (PPP) required in infrastructural projects ? Examine the role of PPP model in the redevelopment of Railway Stations in India.

Infrastructure

PPP is needed because public budgets cannot finance all long-life infrastructure on time, and private partners bring capital and operating skill. Risk and revenue are split by contract: the State keeps policy and often land; the concessionaire takes construction and commercial risk. Railway station redevelopment uses that split: trains stay with Indian Railways; buildings and retail can be private. IRSDC and railway SPVs bid packages; Habibganj (Rani Kamalapati) is an early example. PM Gati Shakti is meant to connect those stations to other modes. Small-town stations may still need public viability support.

Q2 · UPSC Mains 2022 · GS III · 10 marks

Is inclusive growth possible under market economy ? State the significance of financial inclusion in achieving economic growth in India.

Inclusive Growth

A market economy does not by itself deliver inclusive growth; it rewards those who already hold assets. Inclusion is possible when the State provides public goods and repairs missing credit and insurance markets. India pairs liberalisation with MGNREGA, NFSA 2013 and Direct Benefit Transfer. Financial inclusion (Jan Dhan, JAM, UPI, Mudra, PM-Kisan) channels savings, cuts leakage and supports demand. Significance for growth depends on actual use of accounts and fair credit, not on account-opening numbers alone.

Q3 · UPSC Mains 2022 · GS III · 10 marks

What are the major challenges of Public Distribution System (PDS) in India ? How can it be made effective and transparent ?

Farm Subsidies and PDS

PDS under NFSA 2013 is a legal grain entitlement, not a discretionary dole. Main challenges are wrong lists, diversion, poor quality, weak last-mile shops, and a rice-wheat nutrition gap. Migrants lose access when the card is locked to one State. Effectiveness needs computerised supply chains, e-PoS, One Nation One Ration Card, social audits, and exception rules when biometrics fail. DBT can complement urban PDS; it is a poor substitute where food markets are thin.

Toppers' copies

Toppers' copies for this question will be uploaded soon.