UPSC 2017 GS-III · 10 marks · 150 words

Discuss the potential threats of Cyber attack and the security framework to prevent it.

What “Discuss” demands

present several distinct facets of the issue and connect them into an argument, giving the competing views real weight rather than one line each.

The characteristic failure: a list of points with no argument running through them.

What a top answer must contain

These are the checkable specifics from the marking standard for this question — the actual case, committee, datum or thinker, not an instruction to “give examples”.

  • Threat classes: critical-infrastructure attack (power grid, ports), ransomware on hospitals (AIIMS 2022), financial fraud, espionage and APTs, data theft, disinformation
  • Named incidents: Stuxnet as the template, WannaCry (2017), the Kudankulam network breach (2019), the Mumbai grid episode
  • Institutional framework: CERT-In, NCIIPC under the NTRO, I4C and the cybercrime reporting portal, the Defence Cyber Agency, NCCC
  • Legal: IT Act 2000 sections 66F and 70, the CERT-In directions of 2022 on incident reporting, the DPDP Act 2023
  • Gaps to name: no dedicated cyber-security law, workforce shortage, attribution difficulty, cross-border evidence and MLAT delays

The band thresholds and the pre-scored sample answers behind this standard stay private — they are the calibration your copy is placed against.

Now write it, and find out what you actually scored

Attempt this question — typed or photographed — and it is marked against the standard above in under a minute: six parameter scores, a blunt verdict, and the points you missed. 50 free credits on signup, no card.

More from UPSC GS-III