Q. What are the different elements of cyber security ? Keeping in view the challenges in cyber security, examine the extent to which India has successfully developed a comprehensive National Cyber Security Strategy.
Question from UPSC Mains 2022 GS3 Paper
Model Answer:
Cyber security protects internet-connected systems—hardware, software, and data—from malicious attacks. It is foundational for safeguarding India’s rapidly expanding digital economy and national sovereignty.
1. Elements of Cyber Security

- Network Security: Preventing unauthorized access and intrusions into internal networks.
- Application Security: Shielding software and devices against inherent vulnerabilities.
- Data/Information Security: Ensuring privacy, integrity, and availability of digital data.
- Critical Infrastructure Security: Protecting vital national assets (power grids, nuclear plants).
- Operational Security: Managing user permissions and data handling procedures.
2. Contemporary Cyber Security Challenges
- State-Sponsored Warfare: Advanced Persistent Threats (APTs) targeting strategic assets (Kudankulam malware incident).
- Ransomware & Extortion: Crippling critical public health and administrative services (AIIMS Delhi attack, 2022).
- Emerging Technologies: Unprecedented vulnerabilities in IoT devices, AI, and Quantum computing.
- Hardware Dependency: Severe supply-chain risks due to heavy reliance on imported telecom/IT equipment.
3. Examination of India’s Cyber Security Strategy
India’s strategy, rooted in the National Cyber Security Policy (NCSP) 2013, shows both significant institutional progress and distinct policy gaps.
A. Strategic Successes & Institutional Growth

- Robust Nodal Agencies: Established CERT-In (incident response) and NCIIPC (critical infrastructure protection under Section 70, IT Act).
- Law Enforcement Coordination: Launched the Indian Cyber Crime Coordination Centre (I4C) for unified action.
- Military Readiness: Created the Defence Cyber Agency (DCyA) for joint armed forces cyber operations.
- Proactive Mitigation: Operationalized initiatives like the Cyber Swachhta Kendra for botnet and malware cleaning.
B. Gaps and Limitations
- Policy Vacuum: The modernized National Cyber Security Strategy (NCSS 2020) remains unreleased; NCSP 2013 is outdated.
- Skill Deficit: Acute shortage of trained cybersecurity professionals, ethical hackers, and forensic experts.
- Compliance Hurdles: Weak private sector compliance and reporting delays despite stringent CERT-In guidelines (2022).
- Siloed Governance: Lack of a unified, apex command structure leading to fragmented responses across multiple ministries.
Finalizing and implementing the updated National Cyber Security Strategy alongside a mandatory “zero-trust” architecture is imperative to secure India’s trillion-dollar digital economy against rapidly evolving asymmetric threats.




