CS Professional · Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice
Cyber Security: formula sheet
Key formulas
- CIA triad
- Cyber security objectives = Confidentiality + Integrity + Availability
- Learn each term with its meaning, a control, and a breach example.
- Confidentiality
- Only authorised persons can access information
- Breach example: a data leak. Controls: encryption, access control, passwords.
- Integrity
- Information is accurate and changed only by authorised persons
- Breach example: altering a bank record. Controls: hashing, digital signature, audit trail.
- Availability
- Authorised users get timely access to systems and data
- Breach example: denial-of-service or ransomware. Controls: backups, redundancy, recovery plans.
- Extended objectives
- Authentication, authorisation, non-repudiation, accountability
- Mention these as additions to the triad, not replacements.
- CIA triad
- Confidentiality + Integrity + Availability
- Name the property each attack hits: ransomware and DDoS hit availability, data theft hits confidentiality, tampering hits integrity.
- Threat–attack link
- Threat + Vulnerability → Attack
- Use this to separate the three terms in definition questions.
- Virus vs worm vs trojan
- Virus = needs host file and user action; Worm = self-spreading; Trojan = disguised, no self-replication
- The most asked comparison.
- Phishing vs spear phishing
- Phishing = bulk, generic; Spear phishing = targeted, personalised
- Mention research on the victim as the key difference.
- CIA triad
- Information security = Confidentiality + Integrity + Availability
- The three goals every framework and ISMS control aims to protect.
- NIST CSF functions
- Govern → Identify → Protect → Detect → Respond → Recover
- Five functions in version 1.1 (without Govern); six in version 2.0. Govern sits across all the others.
- ISO/IEC 27001 cycle
- Plan → Do → Check → Act (continual improvement)
- The ISMS is a continuing process, not a one-time project.
- Annex A structure (2022 edition)
- 93 controls = 4 themes: organisational, people, physical, technological
- Controls are selected on risk; exclusions must be justified in the Statement of Applicability.
- Certification rule
- ISO/IEC 27001: certifiable. NIST CSF: not certifiable.
- This is the sharpest point of difference in comparison questions.
- Risk
- Risk = Likelihood × Impact
- Used in risk assessment under both ISO 27001 and the NIST Identify function.
- Section 43 test
- Act listed in s.43 + without permission of owner/person in charge = civil liability to pay compensation
- No dishonest or fraudulent intention is needed. Compensation is claimed from the wrongdoer.
- Section 66 test
- Act in s.43 + dishonestly or fraudulently = criminal offence
- The mental element is what separates s.66 from s.43. Punishment is imprisonment, fine, or both; confirm the exact term and fine amount from the bare Act before quoting them.
- Section 66C
- Fraudulent or dishonest use of another's electronic signature, password or other unique identification feature = identity theft
- Think of misuse of someone's login credentials or digital signature.
- Section 66D
- Cheating by personation using a computer resource or communication device = offence
- Typical facts are fake emails, phishing and impersonating a bank official online.
- Section 79 safe harbour
- Intermediary protected if: passive role + no initiating, selecting receiver or modifying + due diligence + removal on actual knowledge or government notice
- Protection is lost on conspiracy, abetment or inducement, or failure to act after notice.
- Adjudication
- Section 46: adjudicating officer decides contraventions and compensation claims under Chapter IX
- Appeals go to the appellate tribunal under the Act. Check the current forum for appeals.
- CERT-In incident reporting window
- Report within 6 hours of noticing the incident or being notified of it
- From the CERT-In directions of 28 April 2022 under Section 70B(6). Applies to service providers, intermediaries, data centres, body corporates and Government organisations. Only incidents of the types listed in the directions must be reported.
- Log retention
- Keep logs of all ICT systems for a rolling 180 days, within Indian jurisdiction
- Logs must be produced to CERT-In when asked. The directions also require clocks to be synchronised to the NTP servers of NIC or NPL, or to sources traceable to them.
- Subscriber and KYC records
- Data centres, VPS, cloud and VPN providers: keep subscriber information for 5 years. Virtual asset service providers: keep KYC and transaction records for 5 years
- Retention runs for 5 years after the registration or relationship is cancelled or ends, as the directions provide.
- Point of contact
- Entity must designate a point of contact to interface with CERT-In
- Share the name and contact details with CERT-In. Keep them updated.
- CERT-In power and penalty
- Section 70B(6): call for information, give directions. Section 70B(7): non-compliance, up to 1 year, or fine up to ₹1,00,000, or both
- Quote the section when you answer a compliance question.
- NCIIPC and protected systems
- Section 70A: nodal agency for CII protection. Section 70: protected system declared by Gazette notification
- Unauthorised access to a protected system can attract imprisonment up to 10 years and a fine.
- SEBI CSCRF structure
- Govern, Identify, Protect, Detect, Respond, Recover
- CSCRF follows these cyber resilience goals for regulated entities. Check the circular for the exact timelines and category-wise applicability.
- Risk relationship
- Risk = Threat × Vulnerability × Impact
- A conceptual model, not an exact calculation. Reducing any factor reduces risk.
- Quantitative risk rating
- Risk score = Likelihood × Impact
- Used in risk matrices, for example 4 × 5 = 20 on a 5-point scale.
- Residual risk
- Residual risk = Inherent risk − Risk reduced by controls
- Conceptual. Residual risk must fall within the board's risk appetite.
- Risk treatment options
- Mitigate | Transfer | Avoid | Accept
- Name the option and give a reason for each risk.
- Incident response phases
- Preparation → Detection and analysis → Containment → Eradication → Recovery → Post-incident review
- Some models merge containment, eradication and recovery into one phase.
- Recovery targets
- RTO = maximum acceptable downtime; RPO = maximum acceptable data loss (measured in time)
- They drive BCP and DR design and backup frequency.
- Forensic process sequence
- Identification → Preservation → Collection → Analysis → Documentation/Reporting → Presentation
- Learn this order. Preservation always comes before analysis, and analysis is done on the image, not the original.
- Admissibility rule for electronic records
- Electronic record as secondary evidence = Section 63 BSA conditions + certificate
- Section 63 BSA corresponds to Section 65B of the Evidence Act, 1872. Original device produced in court needs no certificate.
- Integrity check
- Hash(original) = Hash(image) ⇒ copy is unaltered
- A mismatch means the data changed and its reliability can be challenged.
- Chain of custody
- Seizure → Sealing → Labelling → Transfer log → Storage → Court
- Every handover is recorded with date, time, name and purpose.
- Certificate signatories
- Certificate signed by person in charge of the device/management and by an expert
- The BSA gives a prescribed format in its Schedule. Check the format when drafting.
- Electronic record as document
- Electronic record = document for purposes of evidence
- This lets electronic records be proved like documents, under BSA conditions.
Quick revision
- Cyber security protects confidentiality, integrity and availability of information.
- Know the main attack types: phishing, malware, ransomware, denial of service and social engineering.
- Frameworks and standards give a structured way to manage security; know the purpose of each one you studied.
- The Information Technology Act, 2000 is the main Indian law on cyber offences and electronic records.
- Match each offence to the conduct it punishes before you write the section.
- CERT-In is the national agency for responding to cyber security incidents; know its reporting expectations.
- Risk management runs in order: identify, assess, treat and monitor.
- Incident response runs in order: detect, contain, eradicate, recover and review.
- Digital evidence must be preserved in its original state and its handling recorded.
- In a case answer, always write provision, analysis of the facts and conclusion.
- Always end with practical steps the company should take.
Common mistakes
- Confusing integrity with confidentiality Fix: Confidentiality is about who can see data. Integrity is about whether data is correct and unchanged.
- Treating availability as only a backup issue Fix: Availability means timely access. It covers uptime, redundancy, attack protection and recovery plans.
- Treating virus, worm and trojan as the same thing. Fix: Remember: virus needs a host and user action, worm spreads alone, trojan disguises itself and does not self-replicate.
- Saying phishing and spear phishing differ only in the medium. Fix: The difference is targeting. Spear phishing is personalised after research on the victim.
- Writing only five NIST functions and leaving out Govern, or writing six without mentioning version 1.1. Fix: Write: five core functions in version 1.1, and Govern added in version 2.0. This covers both.
- Saying a company is 'NIST certified'. Fix: State that NIST CSF is voluntary guidance and cannot be certified. Only ISO/IEC 27001 offers certification by an accredited body.
- Treating sections 43 and 66 as the same thing. Fix: Write one line: s.43 is civil compensation with no intent needed; s.66 is a crime needing dishonesty or fraud.
- Using section 66C for any online cheating. Fix: Use 66C when the accused uses another person's password, electronic signature or unique identification feature. Use 66D when cheating is by pretending to be someone.
- Saying the 6 hours run from the time the incident occurred. Fix: Write that the clock runs from noticing the incident or being notified of it. Always mark the time of noticing in your answer.
- Mixing up CERT-In and NCIIPC. Fix: CERT-In is the national agency for incident response and advisories (Section 70B). NCIIPC protects critical information infrastructure (Section 70A). Keep this one-line split in mind.
Exam tips
- Always write the full terms (confidentiality, integrity, availability) before using CIA, and give a one-line meaning of each.
- In case questions, name the element breached before suggesting remedies. It shows analysis.
- Add authentication, authorisation and non-repudiation when a question asks for objectives, to show wider coverage.
- Keep controls practical: access control, encryption, backups, training, policy. Examiners reward usable advice.
- Link your closing line to the board's or company secretary's role in oversight and compliance.
- Comparison questions are common. Use bullet points with clear parameters such as spread, host, purpose and example.
- In case-based questions, name the attack first, then give facts, impact and advice. Do not just list theory.
- Always tie the attack to the CIA triad. It shows analysis.