Skip to content

Internal and Forensic Audit · Cyber Forensics

Cyber Security Framework and Preventive Controls for Organisations

Updated 11 October 2026 · Fact-checked

A cyber security framework is a planned set of policies, controls and response steps that protect an organisation's data and systems. Preventive controls stop an attack, detective controls spot it, and incident response contains it. In India, CERT-In under Section 70B of the IT Act is the national agency for incident response.

Understand Cyber Security Framework and Preventive Controls

Cyber fraud happens when someone misuses a computer resource to cheat, steal data or disrupt business. You cannot remove the risk fully. So an organisation builds layers of protection, called a cyber security framework.

The framework has three groups of measures. Preventive controls stop an incident before it occurs, for example access rights, strong authentication, patching, encryption, firewalls and staff training. Detective controls find an incident that has started, for example log monitoring, intrusion alerts and exception reports. Corrective and response measures limit the damage and restore normal working.

Incident response is the planned handling of a cyber incident. A usual cycle is: preparation, detection and analysis, containment, eradication, recovery and review. For a forensic auditor, one point matters most: preserve evidence while you contain the incident. Do not wipe or reboot affected systems without recording their state.

The law supports this in several ways. Under Section 70B, the Indian Computer Emergency Response Team (CERT-In) is the national agency for cyber security incidents. It collects, analyses and circulates information on incidents, issues forecasts and alerts, takes emergency measures, coordinates response, and issues guidelines and advisories. It may call for information and give directions to service providers, intermediaries, data centres, body corporates and any other person. Failure to comply is punishable with imprisonment up to one year, or fine up to ₹1 crore, or both. No court takes cognizance except on a complaint by an officer authorised by CERT-In.

Section 43A makes a body corporate liable to pay compensation if it is negligent in implementing and maintaining reasonable security practices and thereby causes wrongful loss or gain, while handling sensitive personal data in a computer resource it owns, controls or operates. Section 85 extends liability for a company's contravention to the persons in charge, unless they prove lack of knowledge or due diligence. So preventive controls are also a legal defence.

Key rules to remember

CERT-In functions (Section 70B(4))
Collect and analyse incident information; forecast and alerts; emergency measures; coordinate response; issue guidelines, advisories, vulnerability notes and white papers
Remember it as the national agency for incident response in cyber security.
CERT-In powers and penalty (Section 70B(6), (7), (8))
May call for information and give directions; non-compliance: imprisonment up to 1 year or fine up to ₹1 crore or both
Cognizance only on a complaint by an officer authorised by CERT-In. The fine was raised from one lakh to one crore from 30-11-2023.
Compensation for failure to protect data (Section 43A)
Body corporate + sensitive personal data in its computer resource + negligence in reasonable security practices + wrongful loss or gain = damages by way of compensation
All elements must be present. 'Body corporate' includes a firm, sole proprietorship or other association engaged in commercial or professional activities.
Offences by companies (Section 85)
Company + persons in charge and responsible = guilty; defence: no knowledge or all due diligence
Directors, managers, secretaries or other officers are also liable where consent, connivance or neglect is proved.
Control layers
Prevent → Detect → Respond → Recover → Review
Use this order to structure any answer on a framework.

How to solve Cyber Security Framework and Preventive Controls questions

Use this method for a case question on cyber security measures, incident response or CERT-In.

  1. 1Read the facts and list what happened: the incident, the data or systems hit, and who was involved.
  2. 2Identify the weakness. Was it a missing preventive control, a failed detective control or a poor response?
  3. 3State the relevant provision: Section 70B for CERT-In duties and directions, Section 43A for negligence in data protection, Section 85 for company officers.
  4. 4Apply the provision to the facts, checking each condition (for example, was the data sensitive and was there wrongful loss or gain?).
  5. 5Recommend controls in layers: preventive, detective, response and recovery, with evidence preservation.
  6. 6Add practical compliance points: incident log, reporting to the board or audit committee, documentation and staff training.
  7. 7Conclude clearly: who is liable or what the company must do.

Quickest way: Prevent-Detect-Respond-Law checklist

When to use it: When time is short and the question asks you to advise on measures or liability.

  1. Write three headings: Prevent, Detect, Respond.
  2. Under each, give two or three controls tied to the facts.
  3. Add one line each on Section 70B, Section 43A and Section 85 if they fit.
  4. Close with the conclusion and one line on preserving evidence.

Common mistakes in Cyber Security Framework and Preventive Controls

  • Saying CERT-In investigates and prosecutes every cyber crime.

    Students treat a national agency as a police body.

    Fix: State its role: incident response, alerts, advisories and directions. Prosecution under Section 70B(7) needs a complaint by its authorised officer.

  • Quoting the old fine of ₹1 lakh for non-compliance with CERT-In directions.

    Older notes were not updated.

    Fix: Write fine up to ₹1 crore, or imprisonment up to one year, or both.

  • Applying Section 43A to any data loss.

    Students skip the conditions.

    Fix: Check for a body corporate, sensitive personal data, negligence in reasonable security practices, and wrongful loss or gain.

  • Listing only technical tools and ignoring people and process controls.

    Cyber security is seen as an IT topic only.

    Fix: Include policies, access governance, training, vendor controls and board oversight.

  • Recommending immediate system wipe or restore during an incident.

    Restoring business quickly feels like the priority.

    Fix: Contain first, preserve logs and images, then eradicate and recover.

  • Forgetting that company officers can be personally liable.

    Students stop at the company's liability.

    Fix: Add Section 85 and the due diligence defence.

Worked examples

Example 1

Arka Textiles Ltd, a company, suffers a ransomware attack that encrypts its servers. It does not inform CERT-In when CERT-In calls for information on the incident and issues a direction. Advise on the legal position and the response steps.

Show the solution
  1. Under Section 70B(6), CERT-In may call for information and give directions to a body corporate.
  2. Under Section 70B(7), failure to provide information or comply with a direction is punishable with imprisonment up to one year, or fine up to ₹1 crore, or both.
  3. Under Section 70B(8), a court takes cognizance only on a complaint by an officer authorised by CERT-In.
  4. Under Section 85, persons in charge of the company's business are also liable unless they prove lack of knowledge or due diligence.
  5. Response steps: isolate affected systems, preserve logs and disk images, cooperate with CERT-In, restore from clean backups, and report to the board.

Answer: Arka Textiles has contravened Section 70B(7). The company and the responsible officers face punishment on a complaint by CERT-In's authorised officer. It should comply at once, preserve evidence and follow the containment and recovery plan.

Example 2

Dhruv Finserv Pvt Ltd stores customers' financial details. A weak password policy lets an outsider access the database. Customers suffer wrongful loss. Is the company liable, and what preventive controls would you suggest?

Show the solution
  1. Dhruv Finserv is a body corporate and holds sensitive personal data in a computer resource it owns or controls.
  2. Weak access controls point to negligence in implementing and maintaining reasonable security practices.
  3. Customers have suffered wrongful loss, so the conditions of Section 43A are met.
  4. Liability is to pay damages by way of compensation to the affected persons.
  5. Preventive controls: strong and multi-factor authentication, least-privilege access, encryption, patching, monitoring of logs, staff training and periodic security audits.

Answer: Yes. Under Section 43A the company is liable to pay compensation to the affected customers. Section 85 may also reach responsible officers. Stronger layered controls would reduce the risk.

Exam tips

  • Structure every answer as provision, facts, conclusion, then add practical compliance points.
  • Quote the exact Section 70B sub-section for CERT-In's functions, powers and penalty.
  • Always give controls in layers: prevent, detect, respond, recover.
  • Mention evidence preservation in any incident response answer, as this is a forensic paper.
  • Link Sections 43A and 85 when the facts involve a company and personal data.

Practice questions from Cyber Forensics

Cyber Security Framework and Preventive Controls: frequently asked questions

What is the role of CERT-In in India?

Under Section 70B, CERT-In is the national agency for incident response in cyber security. It collects and analyses incident information, issues alerts, coordinates response and issues guidelines and advisories. It can also direct service providers, intermediaries, data centres and body corporates.

What is the penalty for not following CERT-In directions?

Imprisonment up to one year, or fine up to ₹1 crore, or both. Courts take cognizance only on a complaint by an officer authorised by CERT-In.

What are preventive controls in cyber security?

They are measures that stop an incident from occurring, such as access controls, authentication, encryption, patching, firewalls and staff awareness. They differ from detective controls, which find an incident already under way.

What are the stages of incident response?

A common cycle is preparation, detection and analysis, containment, eradication, recovery and review. In forensic work, evidence is preserved throughout.