Skip to content

CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice

Cyber Security: formula sheet

Full chapter guide

Key formulas

CIA triad
Cyber security objectives = Confidentiality + Integrity + Availability
Learn each term with its meaning, a control, and a breach example.
Confidentiality
Only authorised persons can access information
Breach example: a data leak. Controls: encryption, access control, passwords.
Integrity
Information is accurate and changed only by authorised persons
Breach example: altering a bank record. Controls: hashing, digital signature, audit trail.
Availability
Authorised users get timely access to systems and data
Breach example: denial-of-service or ransomware. Controls: backups, redundancy, recovery plans.
Extended objectives
Authentication, authorisation, non-repudiation, accountability
Mention these as additions to the triad, not replacements.
CIA triad
Confidentiality + Integrity + Availability
Name the property each attack hits: ransomware and DDoS hit availability, data theft hits confidentiality, tampering hits integrity.
Threat–attack link
Threat + Vulnerability → Attack
Use this to separate the three terms in definition questions.
Virus vs worm vs trojan
Virus = needs host file and user action; Worm = self-spreading; Trojan = disguised, no self-replication
The most asked comparison.
Phishing vs spear phishing
Phishing = bulk, generic; Spear phishing = targeted, personalised
Mention research on the victim as the key difference.
CIA triad
Information security = Confidentiality + Integrity + Availability
The three goals every framework and ISMS control aims to protect.
NIST CSF functions
Govern → Identify → Protect → Detect → Respond → Recover
Five functions in version 1.1 (without Govern); six in version 2.0. Govern sits across all the others.
ISO/IEC 27001 cycle
Plan → Do → Check → Act (continual improvement)
The ISMS is a continuing process, not a one-time project.
Annex A structure (2022 edition)
93 controls = 4 themes: organisational, people, physical, technological
Controls are selected on risk; exclusions must be justified in the Statement of Applicability.
Certification rule
ISO/IEC 27001: certifiable. NIST CSF: not certifiable.
This is the sharpest point of difference in comparison questions.
Risk
Risk = Likelihood × Impact
Used in risk assessment under both ISO 27001 and the NIST Identify function.
Section 43 test
Act listed in s.43 + without permission of owner/person in charge = civil liability to pay compensation
No dishonest or fraudulent intention is needed. Compensation is claimed from the wrongdoer.
Section 66 test
Act in s.43 + dishonestly or fraudulently = criminal offence
The mental element is what separates s.66 from s.43. Punishment is imprisonment, fine, or both; confirm the exact term and fine amount from the bare Act before quoting them.
Section 66C
Fraudulent or dishonest use of another's electronic signature, password or other unique identification feature = identity theft
Think of misuse of someone's login credentials or digital signature.
Section 66D
Cheating by personation using a computer resource or communication device = offence
Typical facts are fake emails, phishing and impersonating a bank official online.
Section 79 safe harbour
Intermediary protected if: passive role + no initiating, selecting receiver or modifying + due diligence + removal on actual knowledge or government notice
Protection is lost on conspiracy, abetment or inducement, or failure to act after notice.
Adjudication
Section 46: adjudicating officer decides contraventions and compensation claims under Chapter IX
Appeals go to the appellate tribunal under the Act. Check the current forum for appeals.
CERT-In incident reporting window
Report within 6 hours of noticing the incident or being notified of it
From the CERT-In directions of 28 April 2022 under Section 70B(6). Applies to service providers, intermediaries, data centres, body corporates and Government organisations. Only incidents of the types listed in the directions must be reported.
Log retention
Keep logs of all ICT systems for a rolling 180 days, within Indian jurisdiction
Logs must be produced to CERT-In when asked. The directions also require clocks to be synchronised to the NTP servers of NIC or NPL, or to sources traceable to them.
Subscriber and KYC records
Data centres, VPS, cloud and VPN providers: keep subscriber information for 5 years. Virtual asset service providers: keep KYC and transaction records for 5 years
Retention runs for 5 years after the registration or relationship is cancelled or ends, as the directions provide.
Point of contact
Entity must designate a point of contact to interface with CERT-In
Share the name and contact details with CERT-In. Keep them updated.
CERT-In power and penalty
Section 70B(6): call for information, give directions. Section 70B(7): non-compliance, up to 1 year, or fine up to ₹1,00,000, or both
Quote the section when you answer a compliance question.
NCIIPC and protected systems
Section 70A: nodal agency for CII protection. Section 70: protected system declared by Gazette notification
Unauthorised access to a protected system can attract imprisonment up to 10 years and a fine.
SEBI CSCRF structure
Govern, Identify, Protect, Detect, Respond, Recover
CSCRF follows these cyber resilience goals for regulated entities. Check the circular for the exact timelines and category-wise applicability.
Risk relationship
Risk = Threat × Vulnerability × Impact
A conceptual model, not an exact calculation. Reducing any factor reduces risk.
Quantitative risk rating
Risk score = Likelihood × Impact
Used in risk matrices, for example 4 × 5 = 20 on a 5-point scale.
Residual risk
Residual risk = Inherent risk − Risk reduced by controls
Conceptual. Residual risk must fall within the board's risk appetite.
Risk treatment options
Mitigate | Transfer | Avoid | Accept
Name the option and give a reason for each risk.
Incident response phases
Preparation → Detection and analysis → Containment → Eradication → Recovery → Post-incident review
Some models merge containment, eradication and recovery into one phase.
Recovery targets
RTO = maximum acceptable downtime; RPO = maximum acceptable data loss (measured in time)
They drive BCP and DR design and backup frequency.
Forensic process sequence
Identification → Preservation → Collection → Analysis → Documentation/Reporting → Presentation
Learn this order. Preservation always comes before analysis, and analysis is done on the image, not the original.
Admissibility rule for electronic records
Electronic record as secondary evidence = Section 63 BSA conditions + certificate
Section 63 BSA corresponds to Section 65B of the Evidence Act, 1872. Original device produced in court needs no certificate.
Integrity check
Hash(original) = Hash(image) ⇒ copy is unaltered
A mismatch means the data changed and its reliability can be challenged.
Chain of custody
Seizure → Sealing → Labelling → Transfer log → Storage → Court
Every handover is recorded with date, time, name and purpose.
Certificate signatories
Certificate signed by person in charge of the device/management and by an expert
The BSA gives a prescribed format in its Schedule. Check the format when drafting.
Electronic record as document
Electronic record = document for purposes of evidence
This lets electronic records be proved like documents, under BSA conditions.

Quick revision

  • Cyber security protects confidentiality, integrity and availability of information.
  • Know the main attack types: phishing, malware, ransomware, denial of service and social engineering.
  • Frameworks and standards give a structured way to manage security; know the purpose of each one you studied.
  • The Information Technology Act, 2000 is the main Indian law on cyber offences and electronic records.
  • Match each offence to the conduct it punishes before you write the section.
  • CERT-In is the national agency for responding to cyber security incidents; know its reporting expectations.
  • Risk management runs in order: identify, assess, treat and monitor.
  • Incident response runs in order: detect, contain, eradicate, recover and review.
  • Digital evidence must be preserved in its original state and its handling recorded.
  • In a case answer, always write provision, analysis of the facts and conclusion.
  • Always end with practical steps the company should take.

Common mistakes

  • Confusing integrity with confidentiality Fix: Confidentiality is about who can see data. Integrity is about whether data is correct and unchanged.
  • Treating availability as only a backup issue Fix: Availability means timely access. It covers uptime, redundancy, attack protection and recovery plans.
  • Treating virus, worm and trojan as the same thing. Fix: Remember: virus needs a host and user action, worm spreads alone, trojan disguises itself and does not self-replicate.
  • Saying phishing and spear phishing differ only in the medium. Fix: The difference is targeting. Spear phishing is personalised after research on the victim.
  • Writing only five NIST functions and leaving out Govern, or writing six without mentioning version 1.1. Fix: Write: five core functions in version 1.1, and Govern added in version 2.0. This covers both.
  • Saying a company is 'NIST certified'. Fix: State that NIST CSF is voluntary guidance and cannot be certified. Only ISO/IEC 27001 offers certification by an accredited body.
  • Treating sections 43 and 66 as the same thing. Fix: Write one line: s.43 is civil compensation with no intent needed; s.66 is a crime needing dishonesty or fraud.
  • Using section 66C for any online cheating. Fix: Use 66C when the accused uses another person's password, electronic signature or unique identification feature. Use 66D when cheating is by pretending to be someone.
  • Saying the 6 hours run from the time the incident occurred. Fix: Write that the clock runs from noticing the incident or being notified of it. Always mark the time of noticing in your answer.
  • Mixing up CERT-In and NCIIPC. Fix: CERT-In is the national agency for incident response and advisories (Section 70B). NCIIPC protects critical information infrastructure (Section 70A). Keep this one-line split in mind.

Exam tips

  • Always write the full terms (confidentiality, integrity, availability) before using CIA, and give a one-line meaning of each.
  • In case questions, name the element breached before suggesting remedies. It shows analysis.
  • Add authentication, authorisation and non-repudiation when a question asks for objectives, to show wider coverage.
  • Keep controls practical: access control, encryption, backups, training, policy. Examiners reward usable advice.
  • Link your closing line to the board's or company secretary's role in oversight and compliance.
  • Comparison questions are common. Use bullet points with clear parameters such as spread, host, purpose and example.
  • In case-based questions, name the attack first, then give facts, impact and advice. Do not just list theory.
  • Always tie the attack to the CIA triad. It shows analysis.