CS Professional · Internal and Forensic Audit
Cyber Forensics: formula sheet
Key formulas
- Meaning of cyber forensics
- Identify → Preserve → Analyse → Document → Present digital evidence
- Use this chain as the definition skeleton. Preservation without alteration is the key point.
- Cyber crime role of computer
- Computer as tool + computer as target + computer as incidental store of evidence
- Classify any scenario by asking which role the computer plays.
- Cyber terrorism punishment (IT Act, Section 66F(2))
- Imprisonment which may extend to imprisonment for life
- Applies to whoever commits or conspires to commit cyber terrorism.
- Extra-territorial reach (IT Act, Section 75)
- Offence outside India by any person, any nationality + computer system or network located in India = Act applies
- Both conditions matter: the act must involve a computer, system or network located in India.
- CERT-In functions (IT Act, Section 70B(4))
- Collect, analyse and disseminate incident information; forecast and alert; emergency response; coordinate; issue guidelines
- Failure to give information or comply with CERT-In directions: up to one year, or fine up to one crore rupees, or both (Section 70B(7)).
- Meaning of electronic form evidence (IT Act, s 79A)
- Electronic form evidence = information of probative value, stored or transmitted in electronic form
- Includes computer evidence, digital audio, digital video, cell phones, digital fax machines. Central Government may notify an Examiner of Electronic Evidence to give expert opinion.
- Admissibility (BSA, s 61)
- Electronic or digital record = same legal effect, validity and enforceability as other documents, subject to s 63
- Cannot be rejected merely because it is electronic.
- Primary evidence (BSA, s 57, Explanations 4, 5 and 7)
- Each file of an electronic record stored in multiple files, or in multiple storage spaces including temporary files, is primary evidence; a record from proper custody is primary evidence unless disputed
- Explanation 5 makes the proper custody point important.
- Proper custody (BSA, s 81 Explanation)
- Proper custody = in the place and with the person where it is required to be kept; not improper if legitimate origin is proved or probable
- Also applies to s 93.
- Presumption for five-year-old records (BSA, s 93)
- Record purporting or proved to be 5 years old + proper custody → Court may presume electronic signature was affixed by the person or one authorised by him
- It is a discretionary presumption (may), not mandatory.
- Proving contents
- Contents of electronic records may be proved in accordance with s 63 (BSA, s 62)
- Section 63 text is not reproduced here; state only that its conditions must be met.
- Stages of investigation
- Identification → Preservation → Collection and imaging → Analysis → Documentation and reporting
- Some books merge or rename stages. Keep this order and explain each in a line.
- Integrity check
- Hash(original) = Hash(image) ⇒ image is an exact copy
- Record hash values at acquisition and again before analysis. Any mismatch means the data changed.
- Order of volatility
- Registers and cache → RAM and running processes → network state → disk → remote logs and backups
- Collect the most volatile data first because it is lost soonest when power is off.
- Chain of custody record
- Item + who + when + where + why + hash + signature
- Every transfer of an item must be written down.
- Section 43, IT Act 2000
- Act without permission of owner or person in charge ⇒ liable to pay damages by way of compensation
- Covers access, copying, contaminants, damage, disruption, denial of access, and deleting or altering information.
- Section 70B(7), IT Act 2000
- Failure to give information or follow CERT-In direction ⇒ imprisonment up to one year or fine up to ₹1 crore or both
- Cognizance only on a complaint by an officer authorised by CERT-In (section 70B(8)).
- Section 69B(4), IT Act 2000
- Intermediary intentionally or knowingly contravenes sub-section (2) ⇒ imprisonment up to one year or fine up to ₹1 crore or both
- Sub-section (2) is the duty to give technical assistance and facilities to the authorised agency.
- Section 66F(1)(A) test
- Intent (threaten unity, integrity, security or sovereignty of India, or strike terror) + Means (any one of: (i) denial of access to an authorised person / (ii) attempt to penetrate or access without authorisation or exceeding authorised access / (iii) introducing a computer contaminant) + Consequence (death or injuries, damage to or destruction of property, disruption of supplies or services essential to the life of the community, or knowing it is likely to cause such disruption, or adverse effect on critical information infrastructure specified under section 70)
- All three elements (intent, means, consequence) must be present. Within the means, the three items are alternatives, so any one of (i), (ii) or (iii) is enough. The consequence may be actual or likely.
- Section 66F(1)(B) test
- Knowing or intentional unauthorised access (or exceeding authorised access) + EITHER (1) information, data or database restricted for reasons of the security of the State or foreign relations, OR (2) any other restricted information, data or database, with reason to believe it may be used to cause or likely cause injury to India's sovereignty and integrity, State security, friendly relations with foreign States, public order, decency or morality, or in relation to contempt of court, defamation or incitement to an offence, or to the advantage of any foreign nation, group of individuals or otherwise
- No terror intent is needed in this limb. The 'reason to believe' qualifier applies only to category (2). For category (1), knowing or intentional unauthorised access to State-security or foreign-relations information is what matters.
- Punishment under Section 66F(2)
- Commits or conspires to commit cyber terrorism → imprisonment which may extend to life
- The text prescribes no fine. Do not add one.
- Abetment and attempt
- Section 84B: abetment punished as the offence, if the act is committed in consequence. Section 84C: attempt punished up to one-half of the longest term, or fine, or both
- Both apply only where no express provision is made. Section 66F(2) expressly covers conspiracy.
- Other law and compounding
- Section 77: IT Act penalties do not bar punishment under other laws. Section 77A: no compounding of offences punishable with life or imprisonment over three years
- Cyber terrorism, punishable with life, cannot be compounded.
- Who acts and how
- Central Government → notification in Official Gazette → authorises any agency of the Government
- Section 69B(1). The authority is the Central Government only, not a State Government.
- Purpose
- Enhance cyber security + identify, analyse and prevent intrusion or spread of computer contaminant
- Section 69B(1). This is the only stated ground, unlike section 69.
- What can be monitored and collected
- Traffic data or information generated, transmitted, received or stored in any computer resource
- Traffic data includes origin, destination, route, time, data, size, duration or type of underlying service and any other information.
- Duty of intermediary
- On being called upon: provide technical assistance + extend all facilities to enable online access
- Section 69B(2). Applies to the intermediary or any person in charge of the computer resource.
- Procedure and safeguards
- As may be prescribed
- Section 69B(3).
- Penalty
- Intentional or knowing contravention of s 69B(2) by an intermediary: imprisonment up to 1 year, or fine up to ₹1 crore, or both
- Section 69B(4), as substituted by Act 18 of 2023 w.e.f. 30-11-2023.
- Section 69 vs 69B
- 69: interception, monitoring, decryption of information, up to 7 years + fine. 69B: traffic data for cyber security, up to 1 year or fine or both
- Section 69 covers content and several grounds. Section 69B covers traffic data and one purpose.
- CERT-In functions (Section 70B(4))
- Collect and analyse incident information; forecast and alerts; emergency measures; coordinate response; issue guidelines, advisories, vulnerability notes and white papers
- Remember it as the national agency for incident response in cyber security.
- CERT-In powers and penalty (Section 70B(6), (7), (8))
- May call for information and give directions; non-compliance: imprisonment up to 1 year or fine up to ₹1 crore or both
- Cognizance only on a complaint by an officer authorised by CERT-In. The fine was raised from one lakh to one crore from 30-11-2023.
- Compensation for failure to protect data (Section 43A)
- Body corporate + sensitive personal data in its computer resource + negligence in reasonable security practices + wrongful loss or gain = damages by way of compensation
- All elements must be present. 'Body corporate' includes a firm, sole proprietorship or other association engaged in commercial or professional activities.
- Offences by companies (Section 85)
- Company + persons in charge and responsible = guilty; defence: no knowledge or all due diligence
- Directors, managers, secretaries or other officers are also liable where consent, connivance or neglect is proved.
- Control layers
- Prevent → Detect → Respond → Recover → Review
- Use this order to structure any answer on a framework.
Quick revision
- Cyber forensics means preserving, analysing and presenting digital evidence in a way that can be used before a court or authority.
- Evidence handling follows a sequence: identify, preserve, collect, document, analyse, report. Record every step.
- Section 66F needs intent to threaten the unity, integrity, security or sovereignty of India, or to strike terror, plus the stated conduct and consequence.
- The conduct in 66F(1)(A) is denying access, unauthorised access or exceeding authorised access, or introducing a computer contaminant.
- Section 66F(1)(B) covers unauthorised access to information restricted for State security or foreign relations reasons.
- Punishment for cyber terrorism, including conspiracy, may extend to imprisonment for life.
- Under Section 69B, the Central Government authorises a Government agency by notification to monitor and collect traffic data for cyber security.
- Traffic data identifies a person, system, network or location and includes origin, destination, route, time, size, duration and type of service.
- An intermediary that intentionally or knowingly fails to give technical assistance under 69B(2) faces up to one year imprisonment or a fine up to one crore rupees, or both.
- Section 69 deals with interception, monitoring or decryption of information, with orders made for reasons recorded in writing.
- Section 70B makes CERT-In the national agency for incident response. Section 79A allows notification of an Examiner of Electronic Evidence.
- Section 43A gives compensation where a body corporate is negligent in protecting sensitive personal data.
Common mistakes
- Treating cyber forensics and cyber crime as the same thing. Fix: Write cyber crime as the offence and cyber forensics as the investigative method used to prove it.
- Defining cyber forensics only as data recovery. Fix: Include preservation, analysis, documentation and presentation in court. Admissibility is part of the definition.
- Saying electronic records are inadmissible unless a paper printout is produced. Fix: State s 61: an electronic or digital record cannot be denied admissibility merely because it is electronic, subject to s 63.
- Working directly on the original device or data. Fix: Always acquire a forensic image, verify with a hash value and analyse the copy.
- Analysing the original device directly. Fix: Always state that a forensic image is made first and analysis is done only on the copy, with a write blocker on the original.
- Forgetting hash verification. Fix: Mention that hash values are calculated at acquisition and compared to prove the copy is exact.
- Calling every hacking incident cyber terrorism. Fix: Always state the special intent and the consequence. Without them the act falls under other sections, not 66F.
- Adding a fine or a minimum term to the punishment. Fix: Write exactly: imprisonment which may extend to imprisonment for life. No minimum term and no fine appear in section 66F(2).
- Saying section 69B allows interception or decryption of message content. Fix: Remember 69B covers traffic data for cyber security. Interception, monitoring and decryption of information is section 69.
- Writing that a State Government can authorise an agency under 69B. Fix: Section 69B(1) names only the Central Government.
Exam tips
- Always give a definition first, then scope, objectives and types. Examiners reward a clear structure.
- Attach an Indian example to each type of cyber crime. It shows application, not memory.
- Use section numbers only when sure. Section 66F, 70B, 69B and 75 of the IT Act are safe if you state their content correctly.
- In case questions, follow provision, analysis of facts, conclusion, and add practical steps such as preserving evidence and reporting.
- Link cyber forensics to forensic audit and evidence in a closing line. It ties the topic to the paper.
- Give a clear sequence (identify, acquire, preserve, document) in every process question; examiners reward structure.
- Quote section numbers only where you are sure: ss 57, 61, 62, 81, 93 of the BSA, 2023 and s 79A of the IT Act are safe.
- Apply the law to the facts given, such as company names and systems, and end with a conclusion.