Skip to content

Artificial Intelligence, Data Analytics and Cyber Security - Laws and Practice · Softwares and Software Security

Software Security Standards and Legal Framework

Updated 11 October 2026 · Fact-checked

Software security standards and laws set the rules for building and running secure software. ISO/IEC 27001 gives a management system for information security. OWASP lists common web application risks and fixes. The IT Act, 2000 adds legal duties, such as Section 43A, Section 43, Section 66 and Section 72A. In exams, state the rule, apply it to the facts, then conclude.

Understand Software Security Standards and Legal Framework

Software security means protecting programs and the data they handle from misuse, damage and unauthorised access. Three sources guide you: standards, community guidelines and law. They do different jobs, and exam answers score when you keep them apart.

ISO/IEC 27001 is an international standard for an Information Security Management System (ISMS). It is about managing security as an organisation-wide process: scope, risk assessment, risk treatment, controls, monitoring and continual improvement. It is a management standard, not a coding standard. An organisation can be certified against it by an independent certification body. Annex A lists a set of controls to choose from, and the organisation selects those that fit its risks and records the choice in a Statement of Applicability.

OWASP (Open Worldwide Application Security Project) is a non-profit community. Its OWASP Top 10 is an awareness list of the most critical web application security risks, such as broken access control, cryptographic failures, injection, insecure design, security misconfiguration, vulnerable and outdated components, identification and authentication failures, software and data integrity failures, logging and monitoring failures, and server-side request forgery. The ranking and names are revised from time to time, so learn the ideas, not only the order. OWASP guidance is voluntary. It is not law and it is not a certification.

The legal layer in India is the Information Technology Act, 2000. Section 43 gives compensation where a person, without permission of the owner, accesses a computer, introduces a virus, damages data or disrupts a system. Section 43A makes a body corporate that handles sensitive personal data liable to pay compensation if it is negligent in keeping reasonable security practices and procedures and causes wrongful loss or gain. The related Rules recognise ISO/IEC 27001 as one example of such a standard. Section 66 punishes the dishonest or fraudulent doing of the acts in Section 43. Section 72A punishes disclosure of personal information in breach of a lawful contract. Section 70B makes CERT-In the national agency for incident response.

Link them like this. The law says you must keep reasonable security. ISO 27001 shows how to run a system that meets that duty. OWASP shows what technical flaws to avoid in the code. A good answer ties all three to the facts given.

Key rules to remember

ISO/IEC 27001 core idea
ISMS = scope + risk assessment + risk treatment + controls + monitoring + continual improvement
A management system standard. Certification is voluntary and given by an independent certification body.
Three security goals (CIA)
Confidentiality + Integrity + Availability
Every control and every breach in a case can be mapped to one or more of these.
Section 43A test
Body corporate + sensitive personal data + negligence in reasonable security practices + wrongful loss or gain = compensation
All elements must be present. Compensation is claimed through the adjudication process under the Act.
Section 43 (civil liability)
Act without permission of owner (access, virus, damage, disruption) = compensation
Civil remedy. If done dishonestly or fraudulently, Section 66 applies as an offence.
Section 72A
Service provider or any person + lawful contract + disclosure of personal information + intent to cause or knowing likelihood of wrongful loss or gain = punishment
Applies to disclosure in breach of a lawful contract, which is different from negligence under Section 43A.
OWASP Top 10 status
OWASP Top 10 = awareness list, voluntary, revised periodically
Not a statute. Do not say it is mandatory.

How to solve Software Security Standards and Legal Framework questions

Use this order for any case-based or theory question on software security standards and law.

  1. 1Read the facts and list what happened: what software, what data, who was affected, what went wrong.
  2. 2Map the failure to confidentiality, integrity or availability.
  3. 3Name the technical weakness, using an OWASP category if it fits, such as injection or broken access control.
  4. 4Name the management gap, such as no risk assessment or no access policy, and link it to ISO/IEC 27001 controls.
  5. 5State the legal provision in plain words with its conditions, for example Section 43A needs a body corporate, sensitive personal data and negligence.
  6. 6Apply each condition to the facts, one by one.
  7. 7Conclude with the liability or remedy, then add practical compliance steps such as an ISMS, secure coding, testing, logging and incident reporting to CERT-In.

Quickest way: Standard, flaw, law in three lines

When to use it: Use when time is short, for example a 5 to 8 mark short note or a brief case.

  1. Line 1: define the standard or guideline asked, and say whether it is voluntary or mandatory.
  2. Line 2: give two or three points on how it works, or the key OWASP risks with a one-line fix each.
  3. Line 3: give the IT Act section that creates the duty or penalty, with its conditions.
  4. Close with one practical compliance step.

Common mistakes in Software Security Standards and Legal Framework

  • Calling ISO 27001 a law or saying it is compulsory for all companies.

    Students see it named in rules and assume it is binding.

    Fix: Say it is a voluntary international standard. It is only one example of reasonable security practices, not a legal requirement in itself.

  • Treating OWASP Top 10 as a certification or an Act.

    The word Top 10 sounds official.

    Fix: Describe it as a community awareness list of web application risks. Use it to name flaws, not to claim legal duty.

  • Applying Section 43A to any person or any data.

    Students remember only the idea of data protection.

    Fix: Check three things: body corporate, sensitive personal data, and negligence causing wrongful loss or gain.

  • Mixing Section 43 (civil compensation) with Section 66 (offence).

    Both list similar acts.

    Fix: Section 66 needs a dishonest or fraudulent intent on top of the acts in Section 43. Say which one the facts support.

  • Memorising the OWASP list by rank number.

    Students learn one year's version as fixed.

    Fix: Learn the risk names and what each means. The ranks and names change in later editions.

  • Giving only definitions with no application to the facts.

    Theory is easier than analysis.

    Fix: In every answer, write provision, analysis, conclusion, and add compliance steps.

Worked examples

Example 1

Rupee Pay Solutions Pvt Ltd runs a mobile app. A flaw in its login code let an attacker read the bank account details of customers. The company had no written security policy and never tested the code. A customer suffered a loss of ₹40,000. Advise on the legal position and the standards the company should have followed.

Show the solution
  1. Facts: a body corporate holds sensitive personal data (bank account details). The flaw let an outsider view it. This breaches confidentiality.
  2. Technical weakness: the login flaw fits broken access control or identification and authentication failures in the OWASP Top 10.
  3. Management gap: no policy and no testing show there was no ISMS or risk assessment, which ISO/IEC 27001 expects.
  4. Law: Section 43A makes a body corporate liable to pay compensation if it is negligent in keeping reasonable security practices and this causes wrongful loss or gain.
  5. Application: the company is a body corporate, the data is sensitive personal data, the lack of policy and testing shows negligence, and the customer suffered a ₹40,000 loss.
  6. Conclusion: the company is likely liable to pay compensation to the customer. The attacker may separately face action under Sections 43 and 66.
  7. Compliance: adopt an ISMS, secure coding and regular testing, access controls, logging, and report the incident to CERT-In.

Answer: Rupee Pay is likely liable under Section 43A for negligence in reasonable security practices. It should adopt ISO/IEC 27001 style controls and fix OWASP-type flaws such as broken access control. The attacker may be liable under Sections 43 and 66.

Example 2

Explain ISO/IEC 27001 and the OWASP Top 10, and state how they differ in nature and purpose.

Show the solution
  1. Define ISO/IEC 27001: an international standard for an Information Security Management System, based on risk assessment, risk treatment, controls and continual improvement.
  2. Note that an organisation can be certified by an independent body, and it records its chosen controls in a Statement of Applicability.
  3. Define OWASP Top 10: a community list of the most critical web application security risks, such as injection and broken access control, revised from time to time.
  4. Difference in nature: ISO 27001 is a certifiable management standard. OWASP Top 10 is an awareness guide with no certification.
  5. Difference in purpose: ISO 27001 manages security across the whole organisation. OWASP targets flaws in application code.
  6. Legal link: neither is a statute. Under the IT Act and its Rules, ISO/IEC 27001 is recognised as one example of reasonable security practices, which helps meet Section 43A duties.
  7. Conclude: use both together, the first for governance, the second for secure development.

Answer: ISO/IEC 27001 is a certifiable organisation-wide ISMS standard. OWASP Top 10 is a voluntary list of web application risks. Both are voluntary, and together they help an organisation show reasonable security practices under the IT Act.

Exam tips

  • Always say whether a standard is voluntary or mandatory. This one line is often missed.
  • In case questions, quote the conditions of Section 43A and tick each against the facts.
  • Name at least two OWASP risks with a one-line fix when a code flaw appears in the facts.
  • Finish every answer with practical compliance steps, since the paper values drafting and compliance points.
  • Do not quote section numbers you are unsure of. Describe the rule in plain words instead.

Practice questions from Softwares and Software Security

Software Security Standards and Legal Framework: frequently asked questions

Is ISO 27001 mandatory in India?

No. It is a voluntary standard. The IT Act Rules recognise it as one example of reasonable security practices, so following it helps a company show it met its duty under Section 43A.

What is the OWASP Top 10 in simple words?

It is a list of the most serious web application security risks, such as injection and broken access control. It is made by a non-profit community and updated from time to time. It guides developers but has no legal force.

Which IT Act sections matter most for software security?

Learn Sections 43, 43A, 66, 72A and 70B. They cover civil compensation for unauthorised acts, failure to protect sensitive data, the related offence, breach of confidentiality under contract, and CERT-In's role.

What is the difference between Section 43A and Section 72A?

Section 43A is about a body corporate's negligence in security practices, and the remedy is compensation. Section 72A is about disclosing personal information in breach of a lawful contract, with intent or knowledge of likely wrongful loss or gain, and it is punishable.