0% found this document useful (0 votes)
6 views11 pages

Unit 5 Complete

The document discusses the concept of cyberspace and its legal implications, particularly focusing on cyber law, which encompasses regulations related to information technology, cyber crimes, and digital transactions. It highlights the importance of cyber law in protecting individuals and businesses from online fraud, copyright violations, defamation, and harassment, while also addressing the need for a robust cybersecurity framework. Additionally, it outlines India's cyber laws under the Information Technology Act, 2000, and the objectives of the National Cyber Security Policy aimed at enhancing the security and resilience of cyberspace.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
6 views11 pages

Unit 5 Complete

The document discusses the concept of cyberspace and its legal implications, particularly focusing on cyber law, which encompasses regulations related to information technology, cyber crimes, and digital transactions. It highlights the importance of cyber law in protecting individuals and businesses from online fraud, copyright violations, defamation, and harassment, while also addressing the need for a robust cybersecurity framework. Additionally, it outlines India's cyber laws under the Information Technology Act, 2000, and the objectives of the National Cyber Security Policy aimed at enhancing the security and resilience of cyberspace.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

UNIT-V: CYBERSPACE AND THE LAW, CYBER FORENSICS:

Cyberspace and the Law:


Introduction: Cyberspace is a concept describing a widespread interconnected digital
technology. The word became popular in the 1990s when the use of the Internet, networking, and digital
communication were all growing dramatically; the term cyberspace was able to represent the many new
ideas and phenomena that were emerging.
As a social experience, individuals can interact, exchange ideas, share information, provide social
support, conduct business, direct actions, create artistic media, play games, engage in political discussion,
and so on, using this global network. They are sometimes referred to as cybernauts(an expert or habitual
user of the internet). The term cyberspace has become a conventional means to describe anything
associated with the Internet and the diverse Internet culture.
The United States government recognizes the interconnected information technology and the
interdependent network of information technology infrastructures operating across this medium as part of
the US national critical infrastructure. Amongst individuals on cyberspace, there is believed to be a code
of shared rules and ethics mutually beneficial for all to follow, referred to as cyber ethics. Many view the
right to privacy as most important to a functional code of cyber ethics. Such moral responsibilities go
hand in hand when working online with global networks, specifically, when opinions are involved with
online social experiences.
Cyber Law also called IT Law is the law regarding Information-technology including
computers and internet. It is related to legal informatics and supervises the digital circulation of
information, software, information security and e-commerce.
IT law does not consists a separate area of law rather it encloses aspects of contract,
intellectual property, privacy and data protection laws. Intellectual property is a key element of
IT law. The area of software license is controversial and still evolving in Europe and elsewhere.
Cyber Laws yields legal recognition to electronic documents and a structure to support e-filing
and e-commerce transactions and also provides a legal structure to reduce, check cyber crimes.
Importance of Cyber Law:
1. It covers all transaction over internet.
2. It keeps eyes on all activities over internet.
3. It touches every action and every reaction in cyberspace.
Area of Cyber Law:
Cyber laws contain different types of purposes. Some laws create rules for how individuals and
companies may use computers and the internet while some laws protect people from becoming
the victims of crime through unscrupulous activities on the internet. The major areas of cyber
law include:
1. Fraud: Consumers depend on cyber laws to protect them from online fraud. Laws are
made to prevent identity theft, credit card theft and other financial crimes that happen
online. A person who commits identity theft may face confederate or state criminal
charges. They might also encounter a civil action brought by a victim. Cyber lawyers
work to both defend and prosecute against allegations of fraud using the internet.
2. Copyright: The internet has made copyright violations easier. In early days of online
communication, copyright violations was too easy. Both companies and individuals need
lawyers to bring actions to impose copyright protections. Copyright violation is an area of
cyber law that protects the rights of individuals and companies to profit from their own
creative works.
3. Defamation: Several personnel use the internet to speak their mind. When people use the
internet to say things that are not true, it can cross the line into defamation. Defamation
laws are civil laws that save individuals from fake public statements that can harm a
business or someone’s personal reputation. When people use the internet to make
statements that violate civil laws, that is called Defamation law.
4. Harassment and Stalking: Sometimes online statements can violate criminal laws that
forbid harassment and stalking. When a person makes threatening statements again and
again about someone else online, there is violation of both civil and criminal laws. Cyber
lawyers both prosecute and defend people when stalking occurs using the internet and
other forms of electronic communication.
5. Freedom of Speech: Freedom of speech is an important area of cyber law. Even though
cyber laws forbid certain behaviors online, freedom of speech laws also allow people to
speak their minds. Cyber lawyers must advise their clients on the limits of free speech
including laws that prohibit obscenity. Cyber lawyers may also defend their clients when
there is a debate about whether their actions consist of permissible free speech.
6. Trade Secrets: Companies doing businesses online often depend on cyber laws to
protect their trade secrets. For example, Google and other online search engines spend
lots of time developing the algorithms that produce search results. They also spend a
great deal of time developing other features like maps, intelligent assistance and flight
search services to name a few. Cyber laws help these companies to take legal action as
necessary in order to protect their trade secrets.
7. Contracts and Employment Law: Every time you click a button that says you agree to
the terms and conditions of using a website, you have used cyber law. There are terms
and conditions for every website that are somehow related to privacy concerns.

Advantages of Cyber Law:


 Organizations are now able to carry out e-commerce using the legal infrastructure
provided by the Act.
 Digital signatures have been given legal validity and sanction in the Act.
 It has opened the doors for the entry of corporate companies for issuing Digital
Signatures Certificates in the business of being Certifying Authorities.
 It allows Government to issue notification on the web thus heralding e-governance.
 It gives authority to the companies or organizations to file any form, application or any
other document with any office, authority, body or agency owned or controlled by the
suitable Government in e-form by means of such e-form as may be prescribed by the
suitable Government.
 The IT Act also addresses the important issues of security, which are so critical to the
success of electronic transactions.
Cyber Security Regulations: Cyber security regulations are laws that govern the types of
measures an organization must take to protect itself, its data, and its customers from cyber
threats and data breaches.

Cyber law encompasses laws relating to –


 Cyber crimes
 Electronic and digital signatures
 Intellectual property
 Data protection and privacy
CYBER LAW IN INDIA:In India, cyber laws are contained in the Information Technology Act, 2000
("IT Act") which came into force on October 17, 2000. The main purpose of the Act
is to provide legal recognition to electronic commerce and to facilitate filing of
electronic records with the Government.
The following Act, Rules and Regulations are covered under cyber laws:
1. Information Technology Act, 2000
2. Information Technology (Certifying Authorities) Rules, 2000
3. Information Technology (Security Procedure) Rules, 2004
4. Information Technology (Certifying Authority) Regulations, 2001
Need for Cyber law: In today’s techno-savvy environment, the world is becoming more and more
digitally sophisticated and so are the crimes. Internet was initially developed as a research and
information sharing tool and was in an unregulated manner. As the time passed by it became more
transactional with e-business, e-commerce, e-governance and e-procurement etc. All legal issues related
to internet crime are dealt with through cyber laws. As the number of internet users is on the rise, the need
for cyber laws and their application has also gathered great momentum.

Cyber crime on the rise: As per the cyber crime data maintained by the National Crime Records
Bureau (NCRB), a total of 217, 288, 420 and 966 Cyber Crime cases were registered under the
Information Technology Act, 2000 during 2007, 2008, 2009 and 2010 respectively. Also, a total of 328,
176, 276 and 356 cases were registered under Cyber Crime related Sections of Indian Penal Code (IPC)
during 2007, 2008, 2009 and 2010 respectively. A total of 154, 178, 288 and 799 persons were arrested
under Information Technology Act 2000 during 2007-2010. A total number of 429, 195, 263 and 294
persons were arrested under Cyber Crime related Sections of Indian Penal Code (IPC) during 2007-2010.
Important terms related to cyber law:
“Access" with its grammatical variations and cognate expressions means gaining entry into, instructing
or communicating with the logical, arithmetical, or memory function resources of a computer, computer
system or computer network. (Sec.2(1)(a) of IT Act, 2000).
"Addressee" means a person who is intended by the originator to receive the electronic record but does
not include any intermediary. (Sec.2(1)(b) of IT Act, 2000).

"Affixing Electronic Signature" with its grammatical variations and cognate expressions means
adoption of any methodology or procedure by a person for the purpose of authenticating an electronic
record by means of Electronic Signature. (Sec.2(1)(d) of IT Act, 2000).
"Asymmetric Crypto System" means a system of a secure key pair consisting of a private key for
creating a digital signature and a public key to verify the digital signature. (Sec.2(1)(f) of IT Act, 2000)

"Certifying Authority" means a person who has been granted a license to issue a Electronic Signature
Certificate under section 24. (Sec.2(1)(g) of IT Act, 2000).

"Communication Device" :means Cell Phones, Personal Digital Assistance (Sic), or combination of
both or any other device used to communicate, send or transmit any text, video, audio, or image.
(Sec.2(1)(ha) of IT Act, 2000).
"Computer" means any electronic, magnetic, optical or other high-speed data processing device or
system which performs logical, arithmetic, and memory functions by manipulations of electronic,
magnetic or optical impulses, and includes all input, output, processing, storage, computer software, or
communication facilities which are connected or related to the computer in a computer system or
computer network (Sec.2(1)(i) of IT Act, 2000)
Roles of International Law: International law structures relations among states and other
international stakeholders (most notably international organizations) through various prohibitions,
requirements, and permissions. As such, it has provided a path for regulating global governance
issues from arms control to trade to the environment. As states give increased attention to the
governance of cyberspace (the technical architecture that allows the global internet to function) and
governance in cyberspace (how states, industry, and users may use this technology), the role of
international law in the cyber context has gained increasing prominence.
Issues surrounding international law’s application to cyberspace may be broken into five
discrete categories:
(i) Silence;
(ii) Existential disagreements;
(iii) Interpretative challenges;
(iv) Attribution; and
(v) Accountability.
Above issues are properly addressed in International law related to cyber security.
The state and Private Sector in Cyberspace: It is extremely important to build a robust
information structure to preserve the integrity, confidentiality, and availability of information
in cyberspace. However, many times India has become the victim of cyber attacks. Since then,
there have been consistent efforts to build strong and durable cyberspace. The National
Security Council (NSC), National Security Advisor (NSA), plays a key role in shaping India’s
cyber policy ecosystem. Although another National cyber security policy was formulated in
2020, however, the rapidly increasing digitalization requires an extensive resilient Cyber
security infrastructure.

The un-definable scope of online activities and access to electronic spaces creates a huge
problem for government circles as there are no clear rules to govern them. It is vital, at the
same time, to maintain freedom of speech prevailing over the Net, yet some boundaries should
be set up with no excessive limitation. Policymakers and digital platforms have a great
challenge to fight against the negative content that goes beyond the liberality principle and
proscribed acts.

Cyber Security Standards: To make cyber security measures explicit, the written norms are required.
These norms are known as cyber security standards: the generic sets of prescriptions for an ideal
execution of certain measures. The standards may involve methods, guidelines, reference frameworks,
etc. It ensures efficiency of security, facilitates integration and interoperability, enables meaningful
comparison of measures, reduces complexity, and provide the structure for new developments.
A security standard is "a published specification that establishes a common language, and
contains a technical specification or other precise criteria and is designed to be used
consistently, as a rule, a guideline, or a definition." The goal of security standards is to improve
the security of information technology (IT) systems, networks, and critical infrastructures. The
Well-Written cyber security standards enable consistency among product developers and serve
as a reliable standard for purchasing security products.
Security standards are generally provided for all organizations regardless of their size or the industry
and sector in which they operate. This section includes information about each standard that is usually
recognized as an essential component of any cyber security strategy.
ISO(International Standards Organization) provides security standards in the following components
o Rights of copyright owners
o Works eligible for protection
o Duration of copyright
o Who can claim copyright
The INDIAN Cyberspace: Cyberspace is an interconnected digital environment. It is a type
of virtual world popularized with the rise of the Internet. The term entered popular culture from
science fiction and the arts but is now used by technology strategists, security professionals,
governments, military and industry leaders and entrepreneurs to describe the domain of the
global technology environment, commonly defined as standing for the global network of
interdependent informationtechnology infrastructures, telecommunications networks and
computer processing systems.
Others consider cyberspace to be just a notional environment in which communication
over computer networks occurs.
National Cyber Security Policy 2013: Cyber space is a complex environment consisting of
interactions between people, software and services, supported by worldwide distribution of information
and communication technology (ICT) devices and networks.
Owing to the numerous benefits brought about by technological advancements, the cyberspace today is
a common pool used by citizens, businesses, critical information infrastructure, military and governments
in a manner that makes it difficult to draw clear boundaries among these different groups. The cyberspace
is expected to be more complex in the foreseeable future, with many fold increase in networks and
devices connected to it.
There are various ongoing activities and programs of the Government to address the cyber security
challenges which have significantly contributed to the creation of a platform that is now capable of
supporting and sustaining the efforts in securing the cyber space. Due to the dynamic nature of
cyberspace, there is now a need for these actions to be unified under a National Cyber Security Policy,
with an integrated vision and a set of sustained & coordinated strategies for implementation.
Objectives
1) To create a secure cyber ecosystem in the country, generate adequate trust & confidence in IT systems
and transactions in cyberspace and thereby enhance adoption of IT in all sectors of the economy.
2) To create an assurance framework for design of security policies and for promotion and enabling
actions for compliance to global security standards and best practices by way of conformity assessment
(product, process, technology & people).
3) To strengthen the Regulatory framework for ensuring a Secure Cyberspace ecosystem.
4) To enhance and create National and Sectoral level 24 x 7 mechanisms for obtaining strategic
information regarding threats to ICT infrastructure, creating scenarios for response, resolution and crisis
management through effective predictive, preventive, protective, response and recovery actions.
5) To enhance the protection and resilience of Nation’s critical information infrastructure by operating a
24x7 National Critical Information Infrastructure Protection Centre (NCIIPC) and mandating security
practices related to the design, acquisition, development, use and operation of information resources.
6) To develop suitable indigenous security technologies through frontier technology research, solution
oriented research, proof of concept, pilot development, transition, diffusion and commercialisation
leading to widespread deployment of secure ICT products / processes in general and specifically for
addressing National Security requirements.
7) To improve visibility of the integrity of ICT products and services by establishing infrastructure for
testing & validation of security of such products.
8) To create a workforce of 500,000 professionals skilled in cyber security in the next 5 years through
capacity building, skill development and training.
9) To provide fiscal benefits to businesses for adoption of standard security practices and processes.
10) To enable protection of information while in process, handling, storage & transit so as to safeguard
privacy of citizen's data and for reducing economic losses due to cyber crime or data theft.
11) To enable effective prevention, investigation and prosecution of cyber crime and enhancement of law
enforcement capabilities through appropriate legislative intervention.
12) To create a culture of cyber security and privacy enabling responsible user behaviour & actions
through an effective communication and promotion strategy.
13) To develop effective public private partnerships and collaborative engagements through technical and
operational cooperation and contribution for enhancing the security of cyberspace.
14) To enhance global cooperation by promoting shared understanding and leveraging relationships for
furthering the cause of security of cyberspace
Cyber Forensics: Introduction to Cyber Forensics, Handling Preliminary Investigations, Controlling an
Investigation, Conducting disk-based analysis, Investigating Information-hiding, Scrutinizing E-mail,
Validating E-mail header information, Tracing Internet access, Tracing memory in real-time.
Cyber forensics is a process of extracting data as proof for a crime (that involves electronic devices)
while following proper investigation rules to nab the culprit by presenting the evidence to the court.
Cyber forensics is also known as computer forensics. The main aim of cyber forensics is to maintain
the thread of evidence and documentation to find out who did the crime digitally. Cyber forensics can
do the following:
It can recover deleted files, chat logs, emails, etc
It can also get deleted SMS, Phone calls.
It can get recorded audio of phone conversations.
It can determine which user used which system and for how much time.
It can identify which user ran which program.
Why is cyber forensics important?
In today’s technology driven generation, the importance of cyber forensics is immense. Technology
combined with forensic forensics paves the way for quicker investigations and accurate results. Below
are the points depicting the importance of cyber forensics:
Cyber forensics helps in collecting important digital evidence to trace the criminal.
Electronic equipment stores massive amounts of data that a normal person fails to see. For example: in
a smart house, for every word we speak, actions performed by smart devices, collect huge data which is
crucial in cyber forensics.
It is also helpful for innocent people to prove their innocence via the evidence collected online.
It is not only used to solve digital crimes but also used to solve real-world crimes like theft cases,
murder, etc.
Businesses are equally benefitted from cyber forensics in tracking system breaches and finding the
attackers.
The Process Involved in Cyber Forensics:
 Obtaining a digital copy of the system that is being or is required to be inspected.
 Authenticating and verifying the reproduction.
 Recovering deleted files (using Autopsy Tool).
 Using keywords to find the information you need.
 Establishing a technical report.
Identification: The first step of cyber forensics experts are to identify what evidence is
present, where it is stored, and in which format it is stored.
Preservation: After identifying the data the next step is to safely preserve the data and not
allow other people to use that device so that no one can tamper data.
Analysis: After getting the data, the next step is to analyze the data or system. Here the expert
recovers the deleted files and verifies the recovered data and finds the evidence that the
criminal tried to erase by deleting secret files. This process might take several iterations to
reach the final conclusion.
Documentation: Now after analyzing data a record is created. This record contains all the
recovered and available(not deleted) data which helps in recreating the crime scene and
reviewing it.
Presentation: This is the final step in which the analyzed data is presented in front of the court
to solve cases.
Types of computer forensics
There are multiple types of computer forensics depending on the field in which digital investigation is
needed. The fields are:
Network forensics: This involves monitoring and analyzing the network traffic to and from the
criminal’s network. The tools used here are network intrusion detection systems and other automated
tools.
Email forensics: In this type of forensics, the experts check the email of the criminal and recover
deleted email threads to extract out crucial information related to the case.
Malware forensics: This branch of forensics involves hacking related crimes. Here, the forensics
expert examines the malware, trojans to identify the hacker involved behind this.
Memory forensics: This branch of forensics deals with collecting data from the memory(like cache,
RAM, etc.) in raw and then retrieve information from that data.
Mobile Phone forensics: This branch of forensics generally deals with mobile phones. They examine
and analyze data from the mobile phone.
Database forensics: This branch of forensics examines and analyzes the data from databases and their
related metadata.
Disk forensics: This branch of forensics extracts data from storage media by searching modified,
active, or deleted files.
Techniques that cyber forensic investigators use
Cyber forensic investigators use various techniques and tools to examine the data and some of the
commonly used techniques are:
Reverse steganography: Steganography is a method of hiding important data inside the digital file,
image, etc. So, cyber forensic experts do reverse steganography to analyze the data and find a relation
with the case.
Stochastic forensics: In Stochastic forensics, the experts analyze and reconstruct digital activity
without using digital artifacts. Here, artifacts mean unintended alterations of data that occur from
digital processes.
Cross-drive analysis: In this process, the information found on multiple computer drives is correlated
and cross-references to analyze and preserve information that is relevant to the investigation.
Live analysis: In this technique, the computer of criminals is analyzed from within the OS in running
mode. It aims at the volatile data of RAM to get some valuable information.
Deleted file recovery: This includes searching for memory to find fragments of a partially deleted file
in order to recover it for evidence purposes.
Advantages
 Cyber forensics ensures the integrity of the computer.
 Through cyber forensics, many people, companies, etc get to know about such crimes, thus
taking proper measures to avoid them.
 Cyber forensics find evidence from digital devices and then present them in court, which can
lead to the punishment of the culprit.
 They efficiently track down the culprit anywhere in the world.
 They help people or organizations to protect their money and time.
 The relevant data can be made trending and be used in making the public aware of it.
What are the required set of skills needed to be a cyber forensic expert?
The following skills are required to be a cyber forensic expert:
 Cyber forensic based on technology. So, knowledge of various technologies, computers,
mobile phones, network hacks, security breaches, etc. is required.
 The expert should be very attentive while examining a large amount of data to identify
proof/evidence.
 The expert must be aware of criminal laws, a criminal investigation, etc.
 As we know, over time technology always changes, so the experts must be updated with the
latest technology.
 Cyber forensic experts must be able to analyze the data, derive conclusions from it and make
proper interpretations.
 The communication skill of the expert must be good so that while presenting evidence in front
of the court, everyone understands each detail with clarity.
 The expert must have strong knowledge of basic cyber security.

You might also like