0% found this document useful (0 votes)
30 views65 pages

Cyber Security Overview and Challenges

The document is a comprehensive overview of Cyber Security, detailing the architecture of cyberspace, communication technologies, and the evolution of the internet. It covers topics such as cybercrime, social media, e-commerce, and security best practices. The content is structured into chapters that address various aspects of cybersecurity, including legal perspectives and mitigation measures.

Uploaded by

storeweb555
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
30 views65 pages

Cyber Security Overview and Challenges

The document is a comprehensive overview of Cyber Security, detailing the architecture of cyberspace, communication technologies, and the evolution of the internet. It covers topics such as cybercrime, social media, e-commerce, and security best practices. The content is structured into chapters that address various aspects of cybersecurity, including legal perspectives and mitigation measures.

Uploaded by

storeweb555
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

.

CYBER SECURITY
CS -- 27

BCA SEM – 5

SAURASHTRA UNIVERSITY

-: PREPARED BY:-
WELLKNOWN COLLEGE OF COMPUTER SCIENCE
1 INDRAPRASTH NAGAR MAIN ROAD B/H HEMU GADHAVI HALL
PATHAK SCHOOL CAMPUS – RAJKOT – 360 001
MO :- 89808 03156 / 9601632630
INDEX
1.1 Defining Cyberspace ......................................................................................................................... 1
1.2 Overview of Computer and Web-technology ................................................................................... 1
1.3 Architecture of Cyberspace............................................................................................................... 2
1.4 Communication and Web Technology.............................................................................................. 3
1.5 Internet .............................................................................................................................................. 3
1.6 World Wide Web (www) .................................................................................................................. 4
1.7 Advent of internet ............................................................................................................................. 4
1.8 Internet infrastructure for data transfer and governance ................................................................... 5
A. Network Infrastructure ................................................................................................................... 5
B. Protocols and Standards ................................................................................................................. 5
C. Data Centres and Cloud Services ................................................................................................... 6
D. Data Governance and Regulation .................................................................................................. 6
E. Cybersecurity ................................................................................................................................. 6
F. Internet Governance Bodies ........................................................................................................... 6
G. Content Delivery Networks (CDNs).............................................................................................. 6
H. Quality of Service (QoS) ............................................................................................................... 6
I. International Collaboration.............................................................................................................. 6
J. Data Transfer Agreements .............................................................................................................. 6
1.9 Internet society .................................................................................................................................. 6
1.10 Regulation (Rule) of cyberspace ..................................................................................................... 7
1.11 Concept of cyber security ............................................................................................................... 7
1.12 Issues and challenges of cyber security .......................................................................................... 9
2.1 Cyber Crime .................................................................................................................................... 10
2.2 Classification of cyber crimes ......................................................................................................... 10
2.3 Common Cyber Crimes .................................................................................................................. 14
A. Cyber Crime targeting computers and mobiles ........................................................................... 14
B. Cyber Crime against women and children: .................................................................................. 16
C. Cyber Financial Frauds ................................................................................................................ 17
D. Social Engineering Attacks:......................................................................................................... 17
E. Malware Attacks and Ransom ware Attacks:............................................................................... 18
F. Zero-Day and Zero-Click Attacks: ............................................................................................... 18
2.4 Modus operandi of cyber criminals ................................................................................................ 19
2.5 Reporting of Cyber Crimes ............................................................................................................. 20
2.6Remedial & Mitigation Measures .................................................................................................... 20
2.7 Legal perspective of cybercrime in India ........................................................................................ 21
2.8 IT Act 2000 and its amendments .................................................................................................... 23
2.9 Cyber Crime and offences .............................................................................................................. 25
2.10 Organizations dealing with Cyber Crime and Cyber Security in India ......................................... 26
3.1 Introduction to Social Media........................................................................................................... 28
3.2 Social Media Types and Platforms: ................................................................................................ 28
3.3 Social media monitoring ................................................................................................................. 29
3.4 Hashtag ........................................................................................................................................... 29
3.5 Viral content.................................................................................................................................... 30
3.6 Social Media Marketing .................................................................................................................. 30
3.7 Social Media Privacy ...................................................................................................................... 30
3.8 Challenges of social media ............................................................................................................. 30
3.9 Opportunities and pitfalls in Online Social Network ...................................................................... 31
3.10 Security issues related to social media .......................................................................................... 32
3.11 Flagging and reporting of inappropriate content ........................................................................... 34
3.12 Laws regarding posting of inappropriate content .......................................................................... 34
3.12 Best practices for the use of social media security........................................................................ 35
4.1 Definition of E-Commerce.............................................................................................................. 38
4.2 Main components of E-Commerce ................................................................................................. 38
4.3 Elements of E-Commerce security ................................................................................................. 38
4.4 E-Commerce threats........................................................................................................................ 40
4.5 E-Commerce security best practices ............................................................................................... 41
4.6 Introduction to Digital Payments .................................................................................................... 43
4.7 Components of Digital Payment and Stake holders ........................................................................ 43
4.8 Modes of digital payments .............................................................................................................. 44
A. Banking cards: ............................................................................................................................. 44
B. Unified Payment Interface (UPI) ................................................................................................. 44
C e-Wallets ....................................................................................................................................... 44
D. Unstructured Supplementary Service Data (USSD) .................................................................... 44
E. Aadhar enabled payments system (AEPS) ................................................................................... 45
4.9 Digital Payments Related Common Frauds and Preventive Measures ........................................... 45
4.11 Relevant provisions of Payment Settlement Act, 2007. ................................................................ 47
5.1 What is Endpoint Security?............................................................................................................. 49
5.2 Mobile Phone Security .................................................................................................................... 51
5.3 Password policy .............................................................................................................................. 53
5.4 Security patch management ............................................................................................................ 54
5.5 Data backup .................................................................................................................................... 54
5.6 Downloading and management of third-party software.................................................................. 55
5.7 Device security policy..................................................................................................................... 57
5.8 Cyber Security Best Practices ......................................................................................................... 59
5.11 Wi-Fi Security............................................................................................................................... 60
5.12 Configuration of Basic Security Policy And Permissions. .............................................. 60
CHAPTER – 1: INTRODUCTION TO CYBER SECURITY
1.1 Defining Cyberspace
 The term Cyberspace was first coined by William Gibson in the year 1984.
 Cyberspace is the environment in which communication over computer networks occurs.
 Cyberspace is the virtual and dynamic space created by the machine clones. Cyberspace
mainly refers to the computer which is a virtual network and is a medium electronically
designed to help online communications to occur.
 The primary purpose of creating cyberspace is to share information and communicate
across the world.
 Cyberspace is that space in which users share information, interact with each other;
engage in discussions or social media platforms, and many other activities.
 The whole Cyberspace is composed of large computer networks which have many sub-
networks. These follow the TCP or IP protocol.

1.2 Overview of Computer and Web-technology


Computer and web technology are integral parts of our modern world, shaping how we
communicate, work, learn, and entertain ourselves.
Computer Technology:
1. Hardware: Computers consist of physical components like the central processing unit
(CPU), memory (RAM), storage devices (HDD/SSD), input/output devices (keyboard,
mouse, monitor), and more. These components work together to process and store data.
2. Software: Software includes the operating system (e.g., Windows, macOS, Linux) and
various applications (e.g., Microsoft Office, web browsers, and video games) that run on a
computer. Operating systems manage hardware resources and provide a user interface.
3. Networking: Computers can connect to each other and the internet via wired (e.g.,
Ethernet) or wireless (e.g., Wi-Fi) networks. Networking enables data sharing,
communication, and remote access.
4. Security: Computer security is crucial to protect data and systems from threats like
viruses, malware, and hackers. Antivirus software, firewalls, and encryption are common
security measures.
5. Processing Power: Moore's Law predicts that the processing power of computers doubles
approximately every two years. This constant improvement drives innovations in various
fields, including artificial intelligence, scientific research, and data analysis.
Web Technology:
1. World Wide Web (WWW): The World Wide Web, commonly referred to as the web, is a
global system of interconnected documents and resources linked through hyperlinks. It is
accessed via web browsers.
2. Web Browsers: Web browsers like Google Chrome, Mozilla Firefox, and Microsoft Edge
allow users to access and interact with web content.
3. Web Development: Web development involves creating and maintaining websites and
web applications.
4. Web Servers: Web servers store and deliver web content to users' browsers upon request.
Popular web server software includes Apache, Microsoft IIS.

Page 1 of 65
CHAPTER – 1: INTRODUCTION TO CYBER SECURITY
5. Web Security: Ensuring web security is critical to protect data and user privacy. Measures
include SSL (Secure Sockets Layer)/TLS (Transport Layer Security) encryption, secure
authentication, and regular security audits.
6. Web Standards: Organizations like the World Wide Web Consortium (W3C) establish
web standards to ensure compatibility and accessibility across different devices and browsers.

1.3 Architecture of Cyberspace


There isn't a single, specific architecture for cyberspace, as it encompasses a wide range of
technologies, protocols, and platforms. Some key components and concepts related to the
architecture of cyberspace are:
1. Network Infrastructure: At the core of cyberspace is the global network
infrastructure, often referred to as the Internet. This infrastructure comprises a vast
array of inter connected physical and virtual components, including routers, switches,
data centres, and undersea cables. The Internet's architecture is based on the Internet
Protocol (IP), which allows data packets to be routed across the network.

2. Protocols: Various communication protocols define how data is transmitted and


received in cyberspace. The Transmission Control Protocol (TCP) and Internet
Protocol (IP) are fundamental to the functioning of the Internet. Other protocols like
HTTP (Hypertext Transfer Protocol), SMTP (Simple Mail Transfer Protocol), and
FTP (File Transfer Protocol) govern specific types of data exchange.

3. Domain Name System (DNS): DNS is a critical component of cyberspace that


translates Human-readable domain names (e.g., [Link]) into IP
addresses. This system enables users to access websites and resources by name rather
than needing to remember numeric IP addresses.

4. Data Centres: Data centres house the servers and storage infrastructure that store and
deliver digital content and services. They play a pivotal role in hosting websites,
applications, and cloud services.

5. Cybersecurity: The architecture of cyberspace includes various security measures to


protect data, networks, and users. Firewalls, encryption, intrusion detection systems,
and antivirus software are examples of cybersecurity components.

6. Web and Application Servers: These servers host websites, web applications, and
other online services. They respond to user requests, retrieve data from databases, and
deliver content to users' devices.

7. User Devices: These are the various devices through which user‘s access cyberspace,
including computers, smartphones, tablets, and IoT devices. Each device has its own
hardware and software components that enable connectivity and interaction with
cyberspace.

8. Cloud Computing: Cloud services and platforms are an important part of cyberspace
architecture. Cloud providers offer accessible computing resources, storage, and
services, allowing organizations to leverage the cloud for various purposes.

9. Social Media and Online Communities: Cyberspace also includes virtual


communities and social media platforms that enable users to connect, share

Page 2 of 65
CHAPTER – 1: INTRODUCTION TO CYBER SECURITY
information, and collaborate online. These platforms have their own architectures and
algorithms for content delivery and interaction.

10. Internet of Things (IoT): IoT devices are connected to cyberspace, enabling them to
collect and exchange data with other devices and systems. They play a role in creating
the "smart" aspect of cyberspace, connecting physical objects to the digital realm.

11. Regulations and Governance: Various laws and regulations govern cyberspace to
ensure security, privacy, and fair use. Organizations like ICANN (Internet
Corporation for Assigned Names and Numbers) oversee domain name management,
while governments have authority over aspects like data protection and cybersecurity.
Cyberspace is a dynamic and developing environment, with new technologies and
architectures continually emerging. Its architecture is shaped by the needs of users,
businesses, governments, and the larger digital ecosystem. As such, it remains a subject of
ongoing development, discussion, and edition.

1.4 Communication and Web Technology


Communication and web technology are integral components of the modern digital
landscape. They encompass a wide range of technologies and tools that facilitate
communication and the dissemination of information over the internet. Some key features of
communication and web technology are:
1. Internet: The internet is the foundation of web technology. It is a global network of
interconnected computers and servers that allows for the transfer of data and information
across the world.
2. Web Browsers: Web browsers like Chrome, Firefox, Safari, and Edge are software
applications that enable users to access and interact with websites and web-based
applications.
3. Websites: Websites are collections of web pages that are hosted on web servers and can
be accessed through a web browser. They are created using various web technologies
such as HTML, CSS, and JavaScript.
4. Web Development: Web development involves designing, creating, and maintaining
websites. Web developers use various programming languages and frameworks to build
web applications and sites.
5. Web Standards and Protocols: Various standards and protocols govern web
technology, including HTTP/HTTPS (for data transfer), HTML5, CSS3, and more.
6. Mobile Web: Mobile web technology focuses on optimizing websites and applications
for mobile devices, ensuring a seamless user experience on smartphones and tablets.

1.5 Internet
 The word Internet is derived from the word internetwork, or the connecting together two
or more computer networks.
 The Internet started in the 1960s as a way for government researchers to share
information. Computers in the '60s were large and immobile and in order to make use of
information stored in any one computer, one had to either travel to the site of the
computer or have magnetic computer tapes sent through the conventional mail system.
 January 1, 1983 is considered the official birthday of the Internet. Earlier to this, the
various computer networks did not have a standard way to communicate with each other.

Page 3 of 65
CHAPTER – 1: INTRODUCTION TO CYBER SECURITY
 A new communications protocol was established called Transfer Control
Protocol/Internetwork Protocol (TCP/IP). This allowed different kinds of computers on
different networks to "talk" to each other.
Transmission Control Protocol/Internet Protocol (TCP/IP)
 TCP/IP is a suite of communication protocols used to interconnect network devices on
the Internet.
 TCP establishes the connections between sending and receiving computers, and makes
sure that packets sent by one computer are received in the same sequence by the other,
without any packets missing.
 IP provides the Internet's addressing scheme and is responsible for the actual delivery of
the packets.
 TCP/IP is divided into four separate layers, with each layer handling a different aspect of
the communication problem.

1.6 World Wide Web (www)


 The World Wide Web was invented by a British scientist, Tim Berners-Lee in 1989.
 World Wide Web, which is also known as a Web, is a collection of websites or web
pages stored in web servers and connected to local computers through the internet.
 These websites contain text pages, digital images, audios, videos, etc. Users can access
the content of these sites from any part of the world over the internet using their devices
such as computers, laptops, cell phones, etc.
 The WWW, along with the internet, enables the retrieval and display of text and media to
your device.
 The building blocks of the Web are web pages which are formatted in HTML and
connected by links called "hypertext" or hyperlinks and accessed by HTTP.

1.7 Advent of internet


 The Internet started off with research into what was then known as packet switching as
early as the 1960s.
 ARPANET is considered the first known group of interconnected computers aka the
internet. This system was used to transfer confidential data between the Military.
 This data-sharing technology was then opened to educational institutes in the United
States to allow them to access to government's supercomputer, first at 56 kbit/s, then at
1.5 Mbit/s, and then at 45 Mbit/s.
 Internet service providers began to arise in the late 1980s and the internet was fully
commercialized in the US by 1995.
 The history of the Internet can be segmented into three phases
1. Innovation Phase
2. Institutionalization Phase
3. Commercialization Phase

Page 4 of 65
CHAPTER – 1: INTRODUCTION TO CYBER SECURITY

Innovation Phase (1961 to 1974)


 The fundamental building blocks of the Internet-packet-switching hardware, a
communications protocol called TCP/IP, and client/server computing were
conceptualized and then implemented in actual hardware and software.
Institutionalization Phase (1975 to 1995)
 Large institutions such as the U.S. Department of Defence (DoD) and the National
Science Foundation (NSF) provided funding and legitimization for the fledging Internet.
Commercialization Phase (1995 to the present)
 The U.S. government encouraged private corporations to take over and expand the
Internet backbone as well as local service beyond military installations and college
campuses to the rest of the population around the world.

1.8 Internet infrastructure for data transfer and governance


 Internet infrastructure for data transfer and governance encompasses the physical and
virtual systems, protocols, and regulations that enable the secure, efficient, and reliable
exchange of data across the global network.
 This infrastructure plays a critical role in ensuring data privacy, security, and compliance
with regulations.
 Here are key components and considerations for internet infrastructure related to data
transfer and governance:
A. Network Infrastructure
- Backbone Networks: High-speed, long-distance networks that form the core of the
internet, connecting major data centres and internet exchange points (IXPs).
- Last-Mile Connectivity: The connection from service providers to end-users,
including wired (e.g., fiber-optic, DSL) and wireless (e.g., 5G, Wi-Fi) technologies.
- Data Centres: Facilities that house servers and storage devices, providing the
infrastructure for web hosting, cloud computing, and data storage.
B. Protocols and Standards
- Internet Protocol (IP): The foundation of internet communication, ensuring data
packets can be routed across networks.
- Transport Layer Security (TLS): Encryption protocol for securing data in transit.
- Hypertext Transfer Protocol (HTTP) and HTTPS: Protocols for web data transfer,
with HTTPS adding a security layer.
- DNSSEC: Enhances the Domain Name System (DNS) by adding a layer of security
through digital signatures.

Page 5 of 65
CHAPTER – 1: INTRODUCTION TO CYBER SECURITY
C. Data Centres and Cloud Services
- Major providers like Amazon Web Services (AWS), Microsoft Azure, and Google
Cloud offer robust infrastructure and tools for data storage and processing.
D. Data Governance and Regulation
- Data Privacy Regulations: Compliance with laws like GDPR (in Europe), CCPA (in
California), and HIPAA (for healthcare data).
- Data Retention Policies: Guidelines for storing and managing data for specific
periods.
- Data Access Controls: Systems to restrict and monitor who can access and modify
data.
- Data Encryption: Ensuring data at rest and in transit is properly encrypted to protect
against unauthorized access.
E. Cybersecurity
- Robust security measures, including firewalls, intrusion detection systems, and
regular security audits, are essential to protect data during transfer.
F. Internet Governance Bodies
- Organizations like ICANN (Internet Corporation for Assigned Names and Numbers)
oversee domain name system management and policy.
- Multi stakeholder governance models involve various stakeholders, including
governments, businesses, and civil society, in shaping internet governance.
G. Content Delivery Networks (CDNs)
- CDNs like Akamai and Cloud flare optimize data delivery by caching content at
various locations worldwide, reducing latency.
H. Quality of Service (QoS)
- Ensuring data transfer meets performance requirements, especially for applications
like video conferencing and online gaming.
I. International Collaboration
- Cooperation among nations is essential to establish international norms and
agreements related to data transfer and governance.
J. Data Transfer Agreements
- Agreements like Privacy Shield and Standard Contractual Clauses facilitate the lawful
transfer of data across borders.

1.9 Internet society


 Internet Society (ISOC) A professional membership society that promotes the use and
future development of the Internet. It has individual and organization members all over
the world and is governed by an elected board of trustees. ISOC coordinates various
groups responsible for Internet infrastructure.
 These include
1. The Internet Engineering Task Force (IETF),
2. The Internet Architecture Board (IAB), and
3. The Internet Engineering Steering Group (IESG).
 The IETF develops technical standards for the Internet.

Page 6 of 65
CHAPTER – 1: INTRODUCTION TO CYBER SECURITY
 The IAB has overall responsibility for the architecture and adjudicates on disputes about
standards.
 The IESG, along with the IAB, reviews standards proposed by the IETF

1.10 Regulation (Rule) of cyberspace


 Cyberspace spans worldwide, but it has no formal framework. The lack of formal
framework makes cyberspace nobody's domain
 No single individual, entity, or government owns or controls cyberspace.
 Regulation in cyberspace is a developing challenge.
 The default in cyberspace is privacy. Privacy encourages and improves the exercise of
freedom. A child too shy to express himself in physical space can fake to be somebody
else in virtual space, and express himself freely.
 Crimes of global effect are also committed with the use of the internet. Marketing of
persons, child pornography, kidnapping for payment, and terrorism are perpetrated with
the use of cyberspace. Freedom thus in cyberspace should not be exercised without the
associated responsibility of its users.
 Practical Problems In Extending The Traditional Laws To Cyberspace
1. Multiple Jurisdictions-Because of privacy of the Internet user, absence of
geographical boundaries in the cyberspace, and the cross border effect of Internet
transactions, all legal systems face legal uncertainty.
2. Problem of Policing-The lack of technical knowledge, non-co-operation among
different police organization etc., make the problem too difficult to be solved.
3. Expensive Process-Training of law enforcement (implementation) officers to solve
the issue of cybercrime is very expensive.
4. Obtaining Digital Evidence- Another instance where the controlling of cybercrime
becomes difficult is with regard to obtaining the digital evidence.

1.11 Concept of cyber security


Cyber security is the practice of protecting computer systems, networks, and data from theft,
damage, or unauthorized access.
It encompasses a wide range of technologies, processes, and practices designed to safeguard
digital information and ensure the confidentiality, integrity, and availability of data.
1. Confidentiality: This principle focuses on ensuring that sensitive information is only
accessible to authorized individuals or systems. It involves encryption, access
controls, and data classification to prevent unauthorized access or disclosure.
2. Integrity: Integrity in cybersecurity means that data and systems are accurate and
trustworthy. Any unauthorized modification or tampering with data or systems should
be detected and stopped. Techniques like checksums and digital signatures are used to
maintain data integrity.
3. Availability: Availability ensures that systems and data are accessible when needed.
Cyberattacks can disturb services or make them unavailable, so cyber security
measures aim to prevent or mitigate such troubles through redundancy, load
balancing, and tragedy recovery planning.
4. Authentication: Authentication is the process of verifying the identity of users,
devices, or systems trying to access resources. This can be achieved through
passwords, biometrics, two-factor authentication (2FA), and multi-factor
authentication (MFA).

Page 7 of 65
CHAPTER – 1: INTRODUCTION TO CYBER SECURITY
Cyber Attacks
 A cyber-attack is an exploitation of computer systems and networks. It uses malicious
code to alter computer code, logic or data and lead to cybercrimes, such as information
and identity theft.
 Cyber-attacks can be classified into the following categories:
1. Web-based attacks
2. System-based attacks

Web-based attacks
 These are the attacks which occur on a website or web applications. Some of the
important web-based attacks are as follows-
1. Injection attacks: It is the attack in which some data will be injected into a web
application to manipulate the application and fetch the required information.
2. Session Hijacking: It is a security attack on a user session over a protected network.
Web applications create cookies to store the state and user sessions. By stealing the
cookies, an attacker can have access to all of the user data.
3. Phishing: Phishing is a type of attack which attempts to steal sensitive information
like user login credentials and credit card number. It occurs when an attacker is
hidden as a trustworthy entity in electronic communication.
4. Denial of Service: It is an attack which meant to make a server or network resource
unavailable to the users. It accomplishes this by flooding the target with traffic or
sending it information that triggers a crash.
System-based attacks
 These are the attacks which are intended to compromise a computer or a computer
network. Some of the important system-based attacks are as follows-
1. Virus: It is a type of malicious software program that spread throughout the computer
files without the knowledge of a user. It is a self-replicating malicious computer
program that replicates by inserting copies of itself into other computer programs
when executed. It can also execute instructions that cause harm to the system.
2. Worm: It is a type of malware whose primary function is to replicate itself to spread
to uninfected computers. It works same as the computer virus. Worms often originate
from email attachments that appear to be from trusted senders.
3. Trojan horse: It is a malicious program that occurs unexpected changes to computer
setting and unusual activity, even when the computer should be idle. It misleads the
user of its true intent. It appears to be a normal application but when opened/executed
some malicious code will run in the background.
Cyber Threat
 A Cyber threat is any malicious act that attempts to gain access to a computer network
without authorization or permission from the owners.
 It refers to the wide range of malicious activities that can damage or disrupt a computer
system, a network or the information it contain.
Cyber Threat Cyber Attack
A Threat by definition is a condition / An Attack by definition is an intended
circumstance which can cause damage to action to cause damage to system/asset.
the system/asset.

Page 8 of 65
CHAPTER – 1: INTRODUCTION TO CYBER SECURITY
Threats can be intentional like human The attack is a deliberate action. An attacker
negligence or unintentional like natural has a motive and plan the attack
disasters. accordingly.
A Threat may or may not malicious. An Attack is always malicious.
Chance to damage or information alteration The chance to damage or information
varies from low to very high. alternation is very high.
1.12 Issues and challenges of cyber security
 Cybersecurity faces numerous issues and challenges due to the ever-evolving nature of
technology and the increasing sophistication of cyber threats.
 Some of the key issues and challenges in cybersecurity include:
1. Cyber Attacks: The constant threat of cyberattacks from various factors, including
hackers, cybercriminals, nation-states, and activists, is a significant challenge. These
attacks can take various forms, such as malware, ransom ware, phishing, and
distributed denial of service (DDoS) attacks.
2. Data Breaches: Data breaches can have severe consequences for organizations and
individuals. The theft or exposure of sensitive data, such as personal information,
financial records, or intellectual property, can lead to financial losses, reputational
damage, and legal liabilities.
3. Security Vulnerabilities: Software and hardware vulnerabilities are exploited by
attackers to gain unauthorized access or control over systems. Identifying and
patching these vulnerabilities in a timely manner is a constant challenge.

Page 9 of 65
CHAPTER – 2: CYBER CRIME AND CYBER LAW
2.1 Cyber Crime
 Any criminal activity carried out over the internet is referred to as cybercrime.
Cybercrimes are crimes that involve criminal activities done through cyberspace by
devices connected to the internet. At times, cybercrimes are also called 'computer crimes.
Most cybercriminals commit cybercrimes with mainly three motives- monetary,
personal, or political.
 The first incident of cybercrime was documented in 1973. A computer was used by a
teller at a New York bank to pilfer over two million dollars. The first email spam was
sent in 1978.
 Though cybercrimes do not physically affect anyone, they tend to seriously harm the
reputation, finances, and privacy of the targeted persons. Further, another crucial
characteristic of cybercrimes is the determination of jurisdiction. Since the identity of the
cybercriminal can be completely erased and mostly stays concealed in cyberspace, it is
very difficult to identify him/her.
 As far as India is concerned, the term cybercrime is not defined under any legal
provision. However, different types of cybercrimes are illustrated under the Information
Technology Act, 2000. Further, certain provisions of the Indian Penal Code, 1860
(hereinafter referred to as 'the IPC') are applicable to various cybercrimes also.
 These cybercrimes-related legal provisions under the IT Act and IPC apply to different
types of cybercrimes, though their specific names are not mentioned therewith.
Meaning of Cyber Crime
 Cybercrime refers to criminal conduct committed with the aid of a computer or other
electronic equipment connected to the internet. Individuals or small groups of people
with little technical knowledge and highly organized worldwide criminal groups with
relatively talented developers and specialists can engage in cybercrime.
 Cybercriminals or hackers who want to generate money, commit a majority of
cybercrimes. Individuals and organizations are both involved in cybercrime. Aside from
that, cybercriminals might utilize computers or networks to send viruses, malware,
pornographic material, and other unlawful data.
 To make money, cybercriminals engage in a range of profit-driven criminal acts,
including stealing and reselling identities, gaining access to financial accounts, and
fraudulently utilizing credit cards to obtain funds.

2.2 Classification of cyber crimes


 Cybercrimes can be classified under three heads, depending on the groups they are
targeted. They are:
A. Cybercrimes against individuals,
B. Cybercrimes against organizations, and
C. Cybercrimes against society at large.
A. Cybercrimes against individuals:
 Generally, ordinary individuals are the most weak targets of cybercriminals. This is due
to various reasons like lack of information, guidance, and cyber-security. The following
are some of the main cybercrimes committed targeting individuals.

Page 10 of 65
CHAPTER – 2: CYBER CRIME AND CYBER LAW
1. Cyber bullying:
Cyberbullying refers to bullying someone by threatening, harassing or embarrassing
the victim using technology digital device. Generally, cyberbullying includes the
following activities on the internet:
 Humiliating/embarrassing content posted online about the victim of online
bullying,
 Hacking social media accounts
 Posting vulgar messages on social media
 Threatening the victim to commit any violent activity
 Child pornography or threatening someone with child pornography
2. Cyberstalking
Browsing anyone's internet history or online activity, and sending obscene content
online with the help of any social media, software, application, etc. to know about
that particular person is called cyberstalking. Cybers talkers take advantage of the
inconspicuousness provided by the internet. They are generally not detectable by the
victim, as it is very easy for cybers talkers to open spam accounts just to stalk any
person; once the stalker deletes the account, his/her identity completely vanishes.
3. Cyber defamation
Cyber defamation means injuring the other person's reputation via the internet
through social media, Emails etc. There are two types of Cyber defamation: libel
and slander.
 Libel: It refers to any defamatory statement which is in written form. For
instance, writing defamatory comments on posts, forwarding defamatory
messages on social media groups, etc. are a part of cyber defamation in the form
of libel.
 Slander: It refers to any defamatory statement published in oral form. For
instance, uploading videos defaming someone on YouTube is a part of cyber
defamation in the form of slander.
4. Phishing
Phishing refers to the fraudulent practice of sending emails under the pretext of
reputable companies to induce individuals to reveal personal information, such as
passwords, credit card numbers, etc., online. Phishing refers to the impersonation of a
legitimate person and fraudulently stealing someone's data. Through phishing attacks,
cybercriminals not only exploit innocent individuals but also spoil the reputation of
well-known companies.
5. Cyber fraud
As the name suggests, cyber fraud refers to any act of fraud committed with the use of
a computer. Any person who dishonestly uses the internet to illegal deceive people
and gets personal data, communication, etc. with a motive to make money is called a
cyber fraud.
Examples of cyber fraud include sending emails containing fake invoices, sending
fake emails from email addresses similar to the official ones, etc.

Page 11 of 65
CHAPTER – 2: CYBER CRIME AND CYBER LAW
6. Cyber theft
Cyber theft is a type of cybercrime which involves the unauthorized access of
personal or other information of people by using the internet. The main motive of the
cyber criminals who commit cyber theft is to gather confidential data like passwords,
images, phone numbers, etc. and use it as leverage to demand a lump sum amount of
money. The unauthorized transmission of copyrighted materials, trademarks, etc. over
the internet is also a part of cyber theft. Cyber thefts are committed through various
means, like hacking, email/ SMS spoofing, etc.
Yahoo!, Inc. v. Akash Arora (1999), which was one of the initial cases related to
cyber theft in India. In this case, the defendant was accused of using the trademark or
domain name ‗[Link],'.
7. Spyware
Spyware is a type of malware or malicious software, when it is installed, it starts
accessing and computing the other person's device without the end user's knowledge.
The primary goal of this software is to steal credit card numbers, passwords, One-
Time Passwords (OTPs), etc.
B. Cybercrimes against organizations
 The cybercrimes mainly targeting individuals may help cybercriminals get only a meagre
amount of ransom, depending on the financial status of the targeted individuals. On the
other hand, cyber-attacking large companies or organisations can help them get their
hands on extremely confidential data of both private and public institutions and entities.
Cyber-attacks on organizations are generally launched on a large scale to get a lump sum
amount of ransom. Since such attacks drastically damage the companies' daily
operations, most companies try to resolve them as fast as possible. The following are the
kinds of cybercrimes launched targeting organizations.
1. Attacks by virus
A computer virus is a kind of malware which connects itself to another computer
program and can replicate and expand when any person attempts to run it on their
computer system. For example, the opening of unknown attachments received from
malicious emails may lead to the automatic installation of the virus on the system in
which it is opened. These viruses are extremely dangerous, as they can steal or
destroy computer data, crash computer systems, etc. The attackers program such
malicious viruses to get hold of organisations' official or confidential data. The
illegally retrieved data is then used as leverage to extort ransom from the
organisations.
2. Salami attack
It is one of the tactics to steal money, which means the hacker steals the money in
small amounts. The damage done is so minor that it is unnoticed. Generally, there are
two types of Salami attacks- Salami slicing and Penny shaving. In Salami slicing, the
attacker uses an online database to obtain customer information, such as bank/credit
card details. Over time, the attacker deducts insignificant amounts from each account.
These sums naturally add up to large sums of money taken from the joint accounts
invisibly.

Page 12 of 65
CHAPTER – 2: CYBER CRIME AND CYBER LAW
3. Web Jacking
Web Jacking refers to the illegal redirection of a user's browser from a trusted
domain's page to a fake domain without the user's consent. By using the method of
Web Jacking, people visiting any well-known or reliable website can be easily
redirected to bogus websites, which in turn lead to the installation of malware, leak of
personal data, etc. Web hackers intend to illegally collect confidential information of
users by enticing them to click on any link which may seem genuine at the first
glance.
4. Denial of Service Attack
Denial of Service Attack or DOS, is a cyber-attack on computer devices or systems,
preventing the legal users or accessors of the system from accessing them. The
attackers generally attack systems in such a manner by trafficking the targeted system
until it ultimately crashes. DoS attacks cost millions of dollars to the corporate world,
as it curbs them from using their own systems and carrying out their activities. The
attack may be also used to incorporate ransomware into corporate systems.
5. Data diddling
Data diddling is a cybercrime which involves the unauthorized alteration of data
entries on a computer. It may be done either before or during the entry of such data. It
is generally committed by way of computer virus attacks. At times, to conceal the
alteration, the altered data is changed to its original data after retrieving the required
information. Usually, the strategic or statistical data of large companies.
C. Cybercrimes against society at large
 Apart from the cybercrimes committed targeting individuals in society, various other
cyber-attacks are launched against the community at large. Such cybercrimes may be
aimed either against any particular section of society or the entire country. The following
are a few types of cybercrimes against the community at large.
1. Cyber pornography
 As per Merriam-Webster Dictionary, pornography is the depiction of erotic
behaviour (as in pictures or writing) intended to cause sexual excitement.
Accordingly, cyber pornography refers to using the internet to display, distribute,
import, or publish pornography or obscene materials.
 The following activities are punishable;
- Uploading pornographic content on any website, social media, etc. where third
parties may access it.
- Transmitting obscene photos to anyone through email, messaging, social media,
etc.
2. Cyber terrorism
Cyber terrorism means using cyberspace to hurt the general public and damage the
integrity and sovereignty of any country. Cyber terrorism is generally carried out in
the following ways:

Page 13 of 65
CHAPTER – 2: CYBER CRIME AND CYBER LAW
- Hacking government-owned systems of the target country and getting
confidential information. Destructing and destroying government databases and
backups by incorporating viruses or malware into the systems.
- Disrupting government networks of the target nation.
- Distracting the government authorities and preventing them from focusing on
matters of priority.
3. Cyber Espionage
 Cyber espionage refers to the unauthorized accessing of sensitive data or intellectual
property for economic, or political reasons. It is also called 'cyber spying'.
 In most cases of cyber espionage, spies in the form of hackers are deliberately
recruited to launch cyber-attacks on the government systems of enemy nations to
stealthily collect confidential information. The cross-border exposure of sensitive data
related to any country can continue as long as it stays undetected. The information
gathered through cyber espionage is then used by the gathering country to either
combat or launch military or political attacks on the enemy country. Generally, the
following data are gathered through cyber espionage:
- Military data
- Academic research-related data
- Intellectual property
- Politically strategic data, etc.

2.3 Common Cyber Crimes


A. Cyber Crime targeting computers and mobiles:
• In India, cyber-crime has become a major concern in recent years, with more and
more people using computers and mobiles for various purposes. Criminal activities
that are committed through the use of computers, networks, or other digital devices.
Some of the common types of cyber-crime in India include hacking, phishing,
identity theft, online fraud, cyberstalking, and cyberbullying.
• Cyber criminals often target computers and mobiles to gain access to sensitive
information such as passwords, bank account details, and personal data. Cyber-crime
can have serious consequences for individuals and businesses, including financial
losses, reputational damage, and even physical harm.
Example for Security threats:
a. Web-Based Threats: These types of threats happen when people visit sites that appear
to be fine on the front-end but in reality, automatically download malicious content
onto the mobile devices. Also, many mobile applications continue to sync their data in
the background which poses a threat. These threats usually go unnoticed by the users.
b. Phishing through Links: Some legitimate-looking links are sent through messages,
emails, or social media platforms. They extract personal information by tricking with
several schemes. It is not possible to categorize them as real or fake as they copy the
original website.
c. Forced Downloads: When you visit a page through anonymous links, it automatically
directs you to the download page. This method is called drive-by downloads.
d. Physical Threats: These threats happen when someone physically tries to access your
device. When you lose your mobile, or it is stolen there is a possibility for physical

Page 14 of 65
CHAPTER – 2: CYBER CRIME AND CYBER LAW
threats. Mobile devices carry your transactional data as well as has connected
applications to your bank accounts, which is a threat to your privacy breach.
e. No Password Protection: With keeping all measures to secure your data, it is
surprising to know that some people find it difficult to use a password on their devices,
or they rather use a password that is easy to crack by hackers. This leads to physical
threats.
f. Encryption: While using carrier networks they generally provide good encryption
while accessing servers. But while accessing some client and enterprise servers they are
explicitly managed. They are not end-to-end encrypted which can lead to physical
threats.
g. Network-Based Threats: Mobile network includes both Cellular and Local network
support such as Bluetooth and Wi-Fi. These are used to host network threats. These
threats are especially dangerous as the cyber-criminals can steal unencrypted data while
people use public Wi-Fi networks.
h. Public Wi-Fi: While we are using our devices for every task, at public places we are
provided with public open Wi-Fi which tends to be legitimate while they are controlled
by hackers which results in data leakage.
i. Network Exploits: Network exploits are due to the vulnerabilities in the operating
system in your mobile devices. Once this software is connected to the network they are
capable of installing malware onto the device without being known.
j. Application-Based Threats: Websites available for software downloads are home to
these threats. They tend to be genuine software but in fact are specially designed to
carry malicious activities.
k. Malware: Malware is designed to send unwanted messages to recipients and further
use your personal and business information by hacking your devices.
i. Spyware: They are the software that are used to collect specific information about an
organization or person which later can be used for fraud and identity threats.
Steps to prevent from Security Threats –
• Prefer using communication apps that encrypt data transfers.
• Update your device software regularly to ensure protection against spyware threats.
• Create unique passwords for different accounts created while using mobile devices.
• Delete the non-active apps to limit the threat to data access and privacy.
• Categories your applications under Blacklist and Whitelist.
• Check for apps accessing location and storage.
• Do not allow forced downloads from browser.
• Check on security that stops sharing of network unnecessary.
• Do not add your data to public servers.
To prevent cyber-crime, it is important to take measures such as using strong passwords,
keeping software up-to-date, avoiding suspicious emails and websites, and being cautious
about sharing personal information online. The Indian government has also taken steps to
combat cyber-crime by setting up specialized agencies such as the Cyber Crime Investigation
Cell (CCIC) and the National Cyber Security Coordination Centre (NCSC). However, there is
still a need for greater awareness and education about cyber security among the general
public, especially in rural areas where internet usage is increasing rapidly.

Page 15 of 65
CHAPTER – 2: CYBER CRIME AND CYBER LAW
B. Cyber Crime against women and children:
• Cyber-crime against women refers to any criminal activity that targets women using
digital technology or the internet.
• One common form of cyber-crime against women is online harassment or
cyberbullying. This can include sending threatening or abusive messages, spreading
rumours or false information, or posting explicit content without consent.
• Revenge porn is another prevalent form of cyber-crime targeting women. It involves
the non-consensual sharing of intimate images or videos online, often with the
intention to shame, blackmail, or harass the victim.
• Online stalking is also a significant concern for women. This involves someone
obsessively monitoring a person's online activities, gathering personal information,
and potentially using it to harm or intimidate them.
• Phishing scams targeting women are on the rise. These scams involve tricking
individuals into revealing sensitive information such as passwords, credit card
details, or social security numbers through deceptive emails, websites, or messages.
• Identity theft is another cyber-crime that can disproportionately affect women.
Criminals may steal personal information to commit fraud in the victim's name,
leading to financial loss and damage to their reputation.
• Online grooming is a serious concern for young girls and teenagers. Predators may
use social media platforms and other online spaces to build trust with their victims
and exploit them for sexual purposes.
• Women are also vulnerable to online fraud schemes such as romance scams.
Criminals create fake profiles on dating websites or social media platforms to
establish romantic relationships with unsuspecting victims and then manipulate them
into sending money.
• It is important for women to be aware of these risks and take precautions when using
digital technology. This includes regularly updating passwords, being cautious about
sharing personal information online, and reporting any instances of cyber-crime to
the appropriate authorities.
Cyber-crime against children refers to any criminal activity that targets or exploits children
using digital technology.
• One common form of cyber-crime against children is online child exploitation, which
includes child pornography, grooming, and sexual exploitation.
• Grooming is the process by which an adult builds an emotional connection with a child to
gain their trust for the purpose of sexual abuse or exploitation.
• Child pornography involves the production, distribution, or possession of sexually explicit
images or videos of children.
• Sextortion is another form of cyber-crime where perpetrators coerce children into
providing sexually explicit images or videos and then use those materials to blackmail and
exploit them further.
• Online bullying and harassment are also prevalent forms of cyber-crime against children.
This includes cyberbullying through social media platforms, online forums, or messaging
apps.
• Identity theft is another concern as criminals may steal a child's personal information to
commit fraud or other illegal activities.
It's important for parents and guardians to educate themselves and their children about online
safety measures such as privacy settings, safe internet browsing habits, and responsible social

Page 16 of 65
CHAPTER – 2: CYBER CRIME AND CYBER LAW
media usage. Reporting any suspicious activities or incidents to law enforcement authorities
is crucial in combating cyber-crime against children. Governments and organizations around
the world are working together to develop laws and regulations that protect children from
cybercrime.
Cyber Crime Prevention against Women and Children (CCPWC) Scheme is to have an
effective mechanism to handle cybercrimes against women and children in the country. The
main Components of the CCPWC Scheme,
• Online Cybercrime reporting Unit
• Forensic Unit
• Capacity Building Unit
• Research & development Unit
• Awareness Creation Unit
C. Cyber Financial Frauds:
• Cyber financial frauds involve unauthorized access, theft, or manipulation of
financial data or transactions using digital platforms.
• Types of financial fraud: Common types include phishing scams, identity theft,
credit card fraud, online banking fraud, and investment scams.
1. Phishing: This is a technique where fraudsters impersonate legitimate entities to trick
individuals into revealing sensitive information like passwords or credit card details.
2. Identity theft: It occurs when someone steals personal information to impersonate
another individual and carry out fraudulent activities.
3. Online banking fraud: Criminals may exploit vulnerabilities in online banking
systems to gain unauthorized access, transfer funds, or conduct fraudulent transactions.
4. Investment scams: These frauds involve false promises of high returns or fictitious
investment opportunities to deceive individuals into providing money.
Prevention: To protect against cyber financial frauds, individuals should be cautious
while sharing personal information online, use strong and unique passwords, regularly
monitor financial accounts, and be vigilant of suspicious emails or websites.
D. Social Engineering Attacks:
 Social engineering attacks manipulate human psychology to deceive individuals into
divulging sensitive information or performing actions that benefit the attacker.
 Social engineering attacks often involve impersonation, pretexting, baiting, phishing,
or tailgating to gain trust and exploit vulnerabilities.
1. Impersonation: Attackers may pretend to be someone trustworthy, like a colleague,
IT support, or a customer service representative, to trick individuals into revealing
information or granting access.
2. Pretexting: This technique involves creating a fabricated scenario or pretext to
manipulate victims into providing sensitive information or performing certain
actions.
3. Baiting: Attackers offer something enticing, like a free USB drive or a gift card, to
trick individuals into taking actions that compromise their security.
4. Phishing: Phishing is a social engineering technique where attackers use deceptive
emails or websites to trick individuals into revealing personal information.

Page 17 of 65
CHAPTER – 2: CYBER CRIME AND CYBER LAW
5. Prevention: Individuals can protect themselves from social engineering attacks by
being cautious of requests for sensitive information, verifying the identity of
individuals before sharing information, avoiding clicking on suspicious links or
downloading unknown files, and staying informed about common scam tactics.
E. Malware Attacks and Ransom ware Attacks:
i. Malware Attacks: Malware refers to malicious software designed to infiltrate and
damage computer systems, steal data, or gain unauthorized access.
Types of malware: Common types include viruses, worms, Trojans, spyware, and
adware.
1. Viruses: Viruses attach themselves to legitimate programs or files and spread by
replicating themselves. They can cause damage to files, slow down systems, or
even render them unusable.
2. Worms: Worms are self-replicating malware that spread over networks, exploiting
vulnerabilities in computer systems and causing disruption.
3. Trojans: Trojans appear as legitimate software but contain hidden malicious code.
They can give attackers unauthorized access to a system or steal sensitive data.
4. Spyware: Spyware secretly collects information about a user's activities, such as
browsing habits or keystrokes, and sends it to a third party without the user's
consent.
5. Adware: Adware displays unwanted advertisements, often in the form of pop-ups,
and can collect user information for targeted advertising purposes.
ii. Ransomware Attacks:
 Ransomware is a type of malware that encrypts a victim's files or locks them out of
their systems, demanding a ransom in exchange for restoring access.
 Encryption: Ransomware uses strong encryption algorithms to render files
inaccessible, making them useless until a decryption key is provided.
 Payment: Attackers typically demand payment in cryptocurrencies like Bit coin to
make it difficult to trace the transactions.
 Consequences: Ransomware attacks can lead to significant financial losses, data
breaches, operational disruptions, and reputational damage for individuals and
organizations.
 Prevention: Regularly updating software, using strong and unique passwords,
employing robust security solutions, and regularly backing up data are key
preventive measures against ransomware attacks.
F. Zero-Day and Zero-Click Attacks:
i. Zero-Day Attacks:
 Zero-day attacks are cyber-attacks that exploit software vulnerabilities that are
unknown to the software vendor or have not been patched yet.
 Vulnerabilities: Zero-day vulnerabilities can exist in operating systems, software
applications, web browsers, or other software components.
 Exploitation: Attackers discover and exploit these vulnerabilities before the software
developers become aware of them or release a patch to fix them.
 Damage Potential: Zero-day attacks can have severe consequences as there is no
known defence or protection against them at the time of their discovery.

Page 18 of 65
CHAPTER – 2: CYBER CRIME AND CYBER LAW
 Stealthy Nature: Zero-day attacks are often highly targeted and designed to stay
undetected by security measures and traditional security solutions.
 Prevention and Mitigation: Organizations and software vendors need to have strong
vulnerability management practices, including regular security updates, threat
intelligence, and proactive monitoring to detect and respond to zero-day attacks.
ii. Zero-Click Attacks:
 Zero-click attacks refer to cyber-attacks that exploit vulnerabilities in software or
devices without any interaction or action required from the user.
 Delivery Methods: Zero-click attacks can be delivered through various means, such as
malicious emails, instant messaging apps, or even through network traffic.
 Exploitation: Cybercriminals take advantage of security flaws in software or devices
to execute malicious code and compromise systems without the victim's knowledge.
• Targeted Exploitation: Zero-click attacks often target specific software versions or
device configurations, making them more challenging to defend against.
• Sophistication: Zero-click attacks are highly sophisticated, relying on techniques like
remote code execution, memory corruption, or privilege escalation to gain control
over the targeted system.
 Prevention and Mitigation: To protect against zero-click attacks, it is crucial to keep
software and devices up to date with the latest security patches, use robust security
solutions, and employ network segmentation to limit the potential impact of an attack.

2.4 Modus operandi of cyber criminals


 Identity Theft: Cyber criminals often engage in identity theft to impersonate individuals
for fraudulent activities. They may gather personal information through phishing emails,
data breaches, or social engineering techniques.
 Phishing: Phishing is a common tactic used by cyber criminals to trick individuals into
revealing sensitive information such as passwords, credit card numbers, or login
credentials. They often impersonate trusted entities via email, text messages, or fake
websites.
 Malware Distribution: Cyber criminals may distribute malware through various means,
including malicious email attachments, infected websites, or software downloads. Once
installed, the malware can gain unauthorized access, steal data, or cause other malicious
activities.
 Ransomware Attacks: Ransomware attacks involve encrypting victims' files or systems
and demanding a ransom for their release. Cyber criminals leverage social engineering,
email attachments, or exploit software vulnerabilities to deliver and execute ransomware.
 Data Breaches: Cyber criminals target organizations to gain unauthorized access to
sensitive data, including personal information, financial records, or intellectual property.
They may exploit vulnerabilities in networks, weak passwords, or use social engineering
techniques to infiltrate systems.
 Online Scams: Cyber criminals often engage in online scams to deceive individuals into
providing money or sensitive information. Common examples include romance scams,
lottery scams, investment scams, or fake tech support scams.
 Credential Stuffing: In credential stuffing attacks, cyber criminals use stolen usernames
and passwords from data breaches to gain unauthorized access to other online accounts
of victims who reuse their credentials.

Page 19 of 65
CHAPTER – 2: CYBER CRIME AND CYBER LAW
 Business Email Compromise (BEC): BEC attacks involve cyber criminals
impersonating a high-ranking executive or a trusted party within an organization to trick
employees into transferring funds or disclosing sensitive information.
 Crypto jacking: Cyber criminals may exploit victims' computing resources to mine
cryptocurrencies without their knowledge or consent. They achieve this by infecting
systems with malware that runs in the background.
 Dark Web Activities: Cyber criminals utilize the anonymity of the dark web to engage
in various illicit activities, including the sale of stolen data, hacking tools, drugs,
weapons, and more.

2.5 Reporting of Cyber Crimes


1. Reporting Channels: Cyber-crimes should be reported to the appropriate authorities,
such as local law enforcement agencies, national cybercrime units, or dedicated
cybercrime reporting portals established by governments or cybersecurity
organizations.
2. Evidence Preservation: It is crucial to preserve any evidence related to the cyber-
crime, including screenshots, emails, or system logs, as it can aid in the investigation
and prosecution of the offenders. 3. Provide Details: When reporting a cyber-crime,
provide as many details as possible, including the nature of the incident, any
suspicious emails or messages received, relevant IP addresses, and timestamps of the
events.

2.6 Remedial & Mitigation Measures


Remedial Measures
1. Incident Response: In the event of a cyber-crime, organizations should have an
incident response plan in place to quickly identify, contain, and mitigate the impact of
the attack. This includes isolating affected systems, restoring backups, and applying
patches or security updates.
2. Forensic Investigation: Engaging professional forensic investigators can help
identify the source and extent of the cyber-crime, gather evidence, and aid in legal
proceedings.
3. Data Recovery: If data is compromised or encrypted due to a cyber-attack,
organizations should have backups in place to restore affected systems and minimize
data loss.
Mitigation Measures
1. Strong Security Practices: Implement robust security measures, such as firewalls,
antivirus software, and intrusion detection and prevention systems, to protect against
cyber threats.
2. Regular Updates and Patching: Keep software, operating systems, and firmware up
to date with the latest security patches to mitigate vulnerabilities that cyber criminals
may exploit.
3. Employee Education: Provide cybersecurity awareness and training programs to
employees to educate them about common cyber threats, phishing techniques, and
safe online practices.
4. Multi-factor Authentication (MFA): Implement MFA wherever possible to add an
extra layer of security, making it harder for cyber criminals to gain unauthorized
access to accounts or systems.
Page 20 of 65
CHAPTER – 2: CYBER CRIME AND CYBER LAW
5. Data Encryption: Encrypt sensitive data, both in transit and at rest, to ensure that
even if it is intercepted or stolen, it remains unreadable and unusable for unauthorized
individuals.
6. Regular Security Audits: Conduct regular security audits and vulnerability
assessments to identify and address any weaknesses or potential entry points for cyber
criminals.

2.7 Legal perspective of cybercrime in India


1. Information Technology Act, 2000: In India, cybercrime is primarily governed by
the Information Technology Act, 2000 (IT Act). This law was established to address
various cyber offenses and provide a legal framework for electronic transactions,
digital signatures, and data protection.
2. Cyber Crimes: The IT Act defines several cyber offenses, including unauthorized
access to computer systems, data theft, identity theft, hacking, cyberstalking,
cyberbullying, phishing, spreading of malicious software, and more.
3. Penalties and Punishments: The IT Act prescribes penalties and punishments for
various cyber-crimes. Offenders can face imprisonment, fines, or both, depending on
the severity of the offense. The punishment can range from a few months to several
years, depending on the specific cybercrime committed.
4. Cyber Crime Investigation Cells: India has established cyber-crime investigation
cells at both national and state levels, such as the Cyber Crime Investigation Cell
(CCIC) and Cyber Crime Police Stations. These specialized units are responsible for
investigating and prosecuting cyber criminals.
5. Reporting Cyber Crimes: Individuals or organizations can report cyber-crimes to the
local police station or the nearest cyber-crime investigation cell. Additionally, the
Ministry of Home Affairs has established the Cyber Crime Reporting Portal
([Link]) for reporting cyber-crimes online.
6. Digital Evidence: The IT Act recognizes the admissibility of electronic records as
evidence in court proceedings. Digital evidence, such as emails, chat logs, or
computer forensic reports, can be submitted and considered during the investigation
and trial of cyber-crime cases.
7. International Cooperation: India participates in international efforts to combat
cybercrime. It has signed agreements and treaties with several countries to facilitate
cooperation in investigating and prosecuting cyber criminals across borders.
8. Amendments and Updates: The IT Act has undergone amendments over the years to
address emerging cyber threats and strengthen cybercrime provisions. For example,
the Information Technology (Amendment) Act, 2008 introduced additional provisions
to tackle cyber terrorism, data privacy, and intermediary liability. It is important to
consult with legal professionals or refer to official sources for comprehensive and up-
to- date information on the legal aspects of cybercrime in India.
Punishment for Cyber Crime
In order to control the rise in cybercrime cases, specific punishments are imposed under the
India Penal Code, 1860 and the Information Technology Act 2000. Below are the Sections
that identify the punishments imposed on an individual committing cybercrime.

Page 21 of 65
CHAPTER – 2: CYBER CRIME AND CYBER LAW
I. Under the Indian Penal Code
• Section 292: This Section deals with the sale of obscene materials either in the form of a
book, paper, drawing, writing, pamphlet, painting, etc., or sexually explicit acts harming
the surroundings. An individual or a group involved in such an offence is punished with
imprisonment and a fine. On a first conviction, the punishment is imprisonment for two
years and Rs.2000 fine whereas on a second or subsequent conviction, the punishment is
imprisonment for a term that may extend to five years and Rs. 5,000 fine.
• Section 354C: It deals with the offence of voyeurism, where an individual watches or
captures, or publicizes the image of a woman engaged in a private Act without her
consent. Under the provisions of this Section of IPC, such an offender or criminal is
punished with imprisonment of 1 to 3 years and 3 to 7 years for first-time and second-
time offenders respectively.
• Section 354D: This section deals with stalking both physical and cyberstalking. As per
this Section, ―Any man who follows a woman and contacts, or attempts to contact such
woman to foster personal interaction repeatedly despite a clear indication of disinterest
by such woman or monitors the use by a woman of the interest, email or any other form
of electronic communication, commits the offence of stalking." An offender will be
punished with imprisonment that may extend to three years for the first offender and five
years for the second offender.
• Section 379: If a person commits theft either electronically or physically, he or she will
be punished under the provisions of this Section. It states that "whoever commits theft
shall be punished with imprisonment of either description for a term which may extend
to three years or with fine, or with both.‖ • Section 411: If a person receives any stolen
property such as a computer, mobile phone, or data then he or she will be punished for
three years or fine or both.
• Section 419: This Section deals with fraud such as email phishing or committing the
crime of password theft for impersonating and collecting data for personal benefit.
According to this Section, "Whoever cheats by personation shall be punished with
imprisonment of either description for a term which may extend to three years, or with
fine, or with both."
• Section 420: It also deals with fraud cases especially cheating and dishonestly inducing
delivery of property'. Whoever dishonestly induces one's property, "the person deceived
to deliver any property to any person r to make or alter or destroy the whole or any part
of a valuable security... and which is capable of being converted into a valuable security,
shall be punished with imprisonment of either description for a term which may extend
to seven years, and shall also be liable to fine."
• Section 465: The punishment for forgery, email spoofing, preparation of false
documents, etc., are dealt with in Section 465 of the IPC. It states that anyone who
commits forgery should be punished with imprisonment extending to two years, a fine,
or both.
• Section 468: This Section deals with the forgery of documents or electronic records for
committing other serious crimes such as cheating. As per the provisions of this Section,
whoever commits such a crime shall be punished with imprisonment which may extend
to seven years with a fine. It is a non-boilable offence.
• Section 469: According to this Section, forgery for the purpose of harming reputation is
a punishable offence. Section 469 states that "Whoever commits forgery, 1[intending that
the document or electronic record forged] shall harm the reputation of any party, or
knowing that it is likely to be used for that purpose, shall be punished with imprisonment

Page 22 of 65
CHAPTER – 2: CYBER CRIME AND CYBER LAW
of either description for a term which may extend to three years, and shall also be liable
to fine."
• Section 500: It states that "Whoever defames another shall be punished with simple
imprisonment for a term which may extend to two years, or with fine, or with both." This
means that any individual who sends abusive messages or defamatory content via email
or any other electronic form is dealt with as per the provisions of Section 500 of the IPC.
• Section 504: If anyone insults, tries to provoke, or threatens another person with the
motive of affecting their peace via any electronic form of communication will be
attracted by Section 504 of the IPC. As per its provisions, an individual involved in such
an offence is punished with imprisonment which may extend to two years or a fine or
both.
• Section 506: This Section deals with the 'punishment for criminal intimidation'. If an
individual tries to intimidate another individual shall be punished with imprisonment
which may extend to two years or a fine or both. This criminal intimidation can either be
physical or through electronic means.
• Section 509: It states that ―Whoever intending to insult the modesty of any woman,
utters any word, makes any sound or gesture, or exhibits any object, intending that such
word or sound shall be heard, or that such gesture or object shall be seen, by such
woman, or intrudes upon the privacy of such woman, shall be punished with simple
imprisonment for a term which may extend to one year, or with fine, or with both."
II. Under the Information Technology Act
• Section 43 (a-h): It covers 8 instances (a-h) where "If any person without the permission
of the owner or any other person who is in charge of a computer, computer system or
computer network,"
• Section 65: 'Tampering with computer source documents' is an offence that is punishable
under Section 65 of the Information Technology Act. It states that "Whoever knowingly
or intentionally conceals, destroys or alters or intentionally or knowingly causes another
to conceal, destroy, or alter any computer source code used for a computer, computer
programme, computer system, or computer network when the computer source code is
required to be kept or maintained by law for the time being in force, shall be punishable
with imprisonment up to three years, or with fine which may extend up to two lakh
rupees, or with both".
• Section 66 (A-F): This Section deals with punishments for computer-related offences
such as sending offensive messages, receiving stolen computer resources, identity theft,
cheating by impersonation, violation of privacy, and cyber-terrorism, punishments may
extend to three years imprisonment or a fine of up to 5 lakhs, or both.
• Section 67 (A-B): This Section of the Information Technology Act deals with the
punishments related to the publishing or transmitting of obscene material containing
sexually explicit act, etc., in an electronic format. The punishment on the first conviction
is imprisonment which may extend to three years and with a fine extending to 5 lakh
rupees. The punishment on the second conviction is imprisonment which may extend to
five years and with a fine extending to 10 lakh rupees.

2.8 IT Act 2000 and its amendments


The Information Technology Act, 2000 (IT Act) is a landmark legislation in India that
governs cybercrime, electronic commerce, and data protection. It has been amended several
times to keep pace with the evolving landscape of technology and cybercrime.

Page 23 of 65
CHAPTER – 2: CYBER CRIME AND CYBER LAW
Key Features of the IT Act, 2000:
 Cybercrime: Defines various cyber offenses like hacking, data theft, phishing, and
cyberbullying.
 Electronic Governance: Facilitates the use of electronic records and digital signatures
for government transactions.
 E-commerce: Sets the legal framework for electronic commerce activities, including
contracts, payment systems, and dispute resolution.
 Data Protection: Provides provisions for data protection, including regulations on data
storage, disclosure, and consent.
Amendments to the IT Act:
 Information Technology (Amendment) Act, 2008: Introduced stricter penalties for
cybercrime, including increased jail terms and fines. Also, it defined new offenses like
cyberstalking and identity theft.
 Information Technology (Amendment) Act, 2009: Added provisions for the
establishment of the Cyber Appellate Tribunal to hear appeals against decisions of the
Cyber Regulations Appellate Tribunal.
 Information Technology (Amendment) Act, 2011: Introduced provisions for the
regulation of intermediaries like social media platforms and search engines, requiring
them to take down objectionable content.
 Information Technology (Amendment) Act, 2013: Enhanced the provisions for data
protection and privacy, including regulations on data breaches and the appointment of a
Data Protection Officer.
 Information Technology (Amendment) Act, 2019: Introduced provisions for the
establishment of the National Cyber Security Coordinator (NCSC) to oversee
cybersecurity strategy and coordination.
Current Status:
The IT Act, 2000, along with its amendments, continues to be the primary legislation
governing cybersecurity and digital transactions in India. It's being reviewed and
amended periodically to address new challenges and evolving technologies.
Challenges and Future Directions:
 Data Privacy and Protection: The IT Act lacks comprehensive data protection
regulations compared to the GDPR (General Data Protection Regulation) in Europe.
 Cybercrime and Digital Forensics: The increasing sophistication of cybercrime
necessitates continuous updates to the legislation and advancements in digital forensics
capabilities.
 Regulation of social media and Intermediaries: Striking a balance between free
speech and regulation of online content remains a critical challenge.
 Cross-border Cybercrime: International cooperation is essential to address
cybercrime that transcends national boundaries.
Key Provisions:
 Section 43: Deals with damages caused by cybercrime, including data breaches and
system disruptions.

Page 24 of 65
CHAPTER – 2: CYBER CRIME AND CYBER LAW
 Section 66A: Prohibited the sending of offensive messages through communication
services, but it was later deemed unconstitutional.
 Section 67: Outlaws the publication or transmission of sexually explicit content
involving children.
 Section 79: Provides safe harbour provisions for intermediaries who are not responsible
for the content hosted by their users.

2.9 Cyber Crime and offences


Cybercrime encompasses a wide range of illegal activities committed using computers and
the internet. It's a rapidly evolving field, with new forms of crime emerging constantly. Here's
a breakdown of common cybercrimes and offenses:
1. Financial Crimes:
 Phishing: Deceiving individuals into revealing sensitive information like login
credentials, credit card details, or personal data through fake emails, websites, or
messages.
 Malware Attacks: Deploying malicious software (viruses, ransomware, spyware) to
steal data, disrupt systems, or extort money.
 Credit Card Fraud: Unauthorized use of credit cards through stolen numbers, online
scams, or card skimmers.
 Money Laundering: Using cyber tools to conceal the origins of illegally obtained
funds.
 Cyber Extortion: Threatening to harm individuals or organizations unless a ransom is
paid.
2. Data Breaches and Theft:
 Hacking: Unauthorized access to computer systems and networks for various purposes,
including data theft, system disruption, or personal gain.
 Data Leakage: Accidental or intentional release of sensitive information, often due to
weak security measures or insider threats.
 Identity Theft: Stealing personal information (Social Security numbers, credit card
details, etc.) to assume someone else's identity and commit fraud.
3. Cyber Harassment and Bullying:
 Cyberstalking: Repeated online harassment, threats, or intimidation directed at an
individual.
 Cyberbullying: Bullying or harassment that takes place through digital devices like
smartphones, computers, or social media.
 Online Doxing: Publishing private information about someone online without their
consent, often with malicious intent.
4. Intellectual Property Crimes:
 Copyright Infringement: Unauthorized reproduction, distribution, or performance of
copyrighted works.
 Trademark Infringement: Using another company's trademark without permission.
 Patent Infringement: Manufacturing or selling products that violate a patent.

Page 25 of 65
CHAPTER – 2: CYBER CRIME AND CYBER LAW
5. Other Cyber Offenses:
 Child Pornography: Sharing or distributing explicit content involving minors.
 Cyberterrorism: Using computers or networks to disrupt critical infrastructure or incite
violence.
 Cyberwarfare: State-sponsored attacks on other countries' computer systems or
networks.
 Legal Implications:
 Cybercrimes carry significant legal consequences, often resulting in fines,
imprisonment, or both. The severity of the punishment depends on the nature and
impact of the crime.
Prevention and Protection:
 Strong Passwords: Use unique and complex passwords for all online accounts.
 Multi-Factor Authentication (MFA): Enable MFA wherever possible to add an extra
layer of security.
 Antivirus and Firewall: Install and keep these security software updated.
 Be Cautious Online: Avoid suspicious emails, websites, or messages.
 Regularly Back Up Data: Create backups of important files to mitigate the impact of
data loss.
 Keep Software Updated: Patch vulnerabilities by installing the latest software
updates.
 Educate yourself and others: Stay informed about cyber threats and educate others on
how to stay safe online.
Reporting Cybercrime:
 If you suspect you've been a victim of cybercrime, report it to law enforcement
authorities. Contact your local police department or the FBI's Internet Crime Complaint
Centre (IC3).

2.10 Organizations dealing with Cyber Crime and Cyber Security in India
 Several organizations in India play a crucial role in dealing with cybercrime and
cybersecurity. These organizations work towards preventing, investigating, and
mitigating cyber threats.
 Effective cybersecurity in India requires collaborative efforts from government
agencies, law enforcement, private sector firms, and research institutions. The
landscape is dynamic, and organizations at various levels work together to address
cyber threats and build a secure digital environment. Regular updates to policies,
international collaboration, and public-private partnerships are essential components of
India's cybersecurity strategy.
Ministry of Home Affairs (MHA):The Ministry of Home Affairs is responsible for
formulating policies related to internal security, including cybersecurity. It coordinates with
various agencies to address cyber threats and protect critical infrastructure.
Ministry of Electronics and Information Technology (MeitY):MeitY formulates policies
and programs to promote the growth of the information technology sector in India. It is
actively involved in initiatives related to cybersecurity, including the implementation of the
National Cyber Security Policy.

Page 26 of 65
CHAPTER – 2: CYBER CRIME AND CYBER LAW
National Cyber Security Coordinator (NCSC):The NCSC operates under the Prime
Minister's Office and is responsible for coordinating efforts related to cybersecurity. It works
towards enhancing the cybersecurity posture of the country and facilitating collaboration
among various stakeholders.
Computer Emergency Response Team-India (CERT-In):CERT-In is the national nodal
agency for responding to cybersecurity incidents. It provides incident response services,
alerts, and advisories to organizations and the public. CERT-In also collaborates with
international CERTS and industry partners.
National Critical Information Infrastructure Protection Centre (NCIIPC): NCIIPC
focuses on protecting critical information infrastructure from cyber threats. It identifies
critical sectors, conducts risk assessments, and develops strategies to enhance the
cybersecurity of critical infrastructure.
Cyber Crime Units in State Police: Many states in India have established dedicated
cybercrime investigation units within their police departments. These units handle the
investigation and prosecution of cybercrimes at the state level.
Cyber Appellate Tribunal (CAT): The Cyber Appellate Tribunal hears appeals against
adjudication orders issued by CERT-In and addresses disputes related to cybercrime and
cybersecurity.
National Investigation Agency (NIA): NIA is a specialized agency that handles terrorism-
related cases, including those involving cyber aspects. It investigates and prosecutes cases
with a national security dimension, which may include cyberterrorism.
State Cyber Crime Cells: Many states have established Cyber Crime Cells or Cyber Police
Stations to handle technology-related offenses. These cells investigate and prosecute
cybercrimes at the state level.
Data Security Council of India (DSCI): DSCI is a not-for-profit organization that focuses
on promoting data protection and cybersecurity best practices. It works closely with the
industry, government, and law enforcement to enhance the cybersecurity ecosystem.
International Cooperation: India collaborates with international organizations and law
enforcement agencies to address global cyber threats. Cooperation involves sharing threat
intelligence, conducting joint investigations, and participating in international cybersecurity
initiatives.
Private Sector Cybersecurity Firms: Several private cybersecurity firms in India specialize
in providing cybersecurity solutions, consulting, and incident response services to
organizations. These firms play a vital role in enhancing the overall cybersecurity posture of
businesses.
Cyber Research and Training Institutes: Institutes and organizations involved in
cybersecurity research and training contribute to building a skilled workforce and advancing
cybersecurity knowledge. These include academic institutions, research labs, and training
centres.

Page 27 of 65
CHAPTER – 3: SOCIAL MEDIA OVERVIEW AND SECURITY
3.1 Introduction to Social Media
Social media refers to the means of interactions among people in which they create, share,
and/or exchange information and ideas in virtual communities and networks.
Social Networking
 Social networking refers to use internet-based social media sites to stay connected with
friends, family, colleagues, or customers. Social networking can have a social purpose, a
business purpose, or both through sites like Facebook, X (formerly Twitter), Instagram,
and Pinterest.

3.2 Social Media Types and Platforms:


1. Social networks
 Social networking sites help people connect with each other and offer a multitude of
ways for different brands to attract individuals.
 Examples of social networking platforms:
- Facebook
- Twitter
- Instagram
- LinkedIn
- TikTok
2. Discussion forums
 Discussion forums encourage people to answer each other's questions and share ideas
and news. Many of these social media sites focus on posting questions to solicit the
best answer.
 Examples of discussion forums:
- Reddit
- Digg
- Quora
- Clubhouse
3. Image-sharing networks
 These social media sites let people share photos and related content. They offer a
platform to start conversations, inspire creativity, make products seem more appealing
and encourage customers to talk about your brand.
 Examples of image-sharing networks:
- Instagram
- Flickr
- Photobucket
4. Bookmarking networks
 Bookmarking networks are platforms where users save different ideas, articles, posts
and other content for later use.
 Examples of bookmarking networks:
- Feedly
- Flipboard
- Pocket
Page 28 of 65
CHAPTER – 3: SOCIAL MEDIA OVERVIEW AND SECURITY
- Stumble Upon
- Pinterest
5. Blogging and publishing networks
 These social media networks give you a place to publish your thoughts on your job,
current events, hobbies and more. You can enjoy many of the benefits of having your
own blog without having to host it on your own website.
6. Consumer review networks
 These sites display customers' reviews of businesses, giving users a full perspective of
the type of services and products offered and the overall satisfaction rate.
 Examples of consumer review networks:
- TripAdvisor
- Yelp
- Open Table
- Google My Business
7. Social shopping networks
 These networks help people spot trends, share great finds, make purchases and follow
their favourite brands. They focus on e-commerce, and the social element makes it
engaging and entertaining.
 Examples of social shopping networks:
- Instagram
- Poshmark
- Etsy
- Facebook
8. Video hosting platforms
 Video hosting platforms gives independent filmmakers, journalists and other creators
a way for their audiences to stream videos quickly and easily. Brands can use paid ads
to reach new customers, they can ask influencers to use and talk about their products
or they can film their own video content. Examples of video hosting platforms:
- YouTube
- Tik Tok
- Snapchat
- Vimeo
- Instagram

3.3 Social media monitoring


 It is the process of collecting social conversations and messages into a database of
useful information. Social media monitoring is the process of identifying and
determining what is being said about a brand, individual or product through different
social and online channels.

3.4 Hashtag
 When it comes to social media, the hashtag is used to draw attention, organize,
promote, and connect. Hashtags refers to the usage of the pound or number symbol,
"#," to mark a keyword or topic on social media. Hashtags originated on Twitter and
Page 29 of 65
CHAPTER – 3: SOCIAL MEDIA OVERVIEW AND SECURITY
have since become common on Instagram, Facebook and other social media
platforms. It's used within a post on social media to help those who may be interested
in your topic to be able to find it when they search for a keyword or particular
hashtag. It helps to draw attention to your posts and encourage interaction.

3.5 Viral content


 To be "viral" on social media means that a piece of content, such as a post, video, or
image, has become extremely popular and is being shared by a large number of
people on various social media platforms.
 Viral content is online content that achieves a high level of awareness due to shares
and exposure on social media networks, news websites, aggregators, email
newsletters and search engines.

3.6 Social Media Marketing


 Social media marketing is a form of digital marketing that leverages the power of
popular social media networks to achieve your marketing and branding goals.

3.7 Social Media Privacy


 Social media privacy includes personal and sensitive information that people can find
out from user accounts. Some of this information is shared voluntarily through posts
and profile information. Information also may be released unknowingly through
tracking cookies, which track the information of a user's online activity, including
webpage views, social media sharing and purchase history.
 Examples of categories may be fitness enthusiast, pet lover or parent. With these
categories, companies can personalize marketing campaigns to users on social media.

3.8 Challenges of social media


 Performance: Nowadays, project won't survive on the market if its performance is
poor. The user becomes more and more demandable. Mobile application should also

Page 30 of 65
CHAPTER – 3: SOCIAL MEDIA OVERVIEW AND SECURITY
load and work fast without any slowdowns. This can be achieved by using powerful
technologies and the right architecture.
 Security: Users expect that your platform is secure, and they can control their
privacy. People have to have the ability to hide their personal data, posts visibility,
etc. Moreover, messaging between people must be private and encrypted.
 Design and user experience: When a user gets into the web or mobile application, he
has to instantly understand how to use it and get what he was looking for.
 Marketing: Building a great product is half of the way. One of the biggest challenges
is to market it right and attract enough users to survive during the first stage. If you
have defined your target audience right and built the product that satisfies their needs,
it should go smoothly.

3.9 Opportunities and pitfalls in Online Social Network


 Content Creation: Whether it's writing, photography, videography, or graphic
design, creating engaging and high-quality content is at the core of social media
success. You can become a content creator or influencer in your niche.
 Social Media Marketing: Many businesses and organizations use social media to
promote their products and services. You can work as a social media marketer,
helping companies create and execute marketing strategies on platforms like
Facebook, Instagram, Twitter, and LinkedIn.
 Community Management: Brands often need individuals to manage their online
communities, respond to customer inquiries, and engage with followers. This role is
crucial for maintaining a positive online reputation.
 Analytics and Insights: Analysing data and social media metrics can help businesses
make informed decisions. If you have analytical skills, you can work as a social media
analyst to provide insights on audience behaviour and campaign performance.
 Social Media Advertising: Platforms like Facebook, Instagram, and YouTube offer
robust advertising options. Becoming proficient in running paid social media ad
campaigns can be a lucrative career.
 E-commerce and Influencer Marketing: Social media platforms are increasingly
used for e-commerce and influencer marketing. Anyone can start an own online store
or collaborate with brands to promote their products.
 Video Content: Video content is gaining popularity, especially on platforms like
YouTube, TikTok, and Instagram. If you're comfortable in front of the camera, you
can create vlogs, tutorials, or entertainment content.
 Podcasting: Podcasts have a dedicated following, and platforms like Spotify and
Apple Podcasts provide opportunities for creators to reach a global audience.
 Consulting and Training: As you gain expertise in social media, you can offer
consulting services to businesses looking to improve their social media presence. You
can also provide training and workshops on social media marketing.
 Freelance Work: Many freelance opportunities exist in social media, including
content writing, graphic design, and social media management. Freelancing allows for
flexibility in your work schedule.
 Non-profits and Causes: If you're passionate about a particular cause, you can use
social media to raise awareness and support for it. Many non-profit organizations also
hire social media specialists.

Page 31 of 65
CHAPTER – 3: SOCIAL MEDIA OVERVIEW AND SECURITY
 Live Streaming and Gaming: Platforms like Twitch have created opportunities for
gamers and streamers to build a following and monetize their content through
donations and sponsorships.
 Social Media Management Tools: Developing or working with social media
management tools and software can be a tech-focused career option.
 Personal Branding: Building a personal brand on social media can open doors to
various opportunities, including speaking engagements, collaborations, and book
deals.
 Data Privacy and Security: With the increasing concerns about data privacy, there's
a growing demand for experts in this field to help protect user data on social media
platforms.

3.10 Security issues related to social media


Some common security issues associated with social media:
1. Privacy Concerns:
 Unauthorized sharing of personal info.
 Location tracking.
 Potential for data breaches.
2. Data Breaches:
 Cybercriminals target user data.
 Email addresses, passwords exposed.
3. Phishing Attacks:
 Trick users into revealing credentials.
 Via direct messages or fake pages.
4. Account Takeovers:
 Unauthorized access to accounts.
 Through the password guessing or phishing.
5. Cyberbullying and Harassment:
 Abusive comments, threats, doxing.
6. Fake Profiles and Impersonation:
 Identity theft, misinformation.
7. Malware Distribution:
 Malicious links/files shared.
 Risk of infections (viruses, ransomware).
8. Misinformation and Fake News:
 Spread of false information.
 Real-world consequences.

Page 32 of 65
CHAPTER – 3: SOCIAL MEDIA OVERVIEW AND SECURITY
9. Third-Party App Risks:
 Apps may access user data.
 Security risks if not properly secured.
10. Geolocation Tracking:
 Location sharing exploited by malicious actors.
[Link] Targeting and Data Profiling:
 Concerns about user data use for targeted ads.
12. Security Flaws and Vulnerabilities:
 Software vulnerabilities exploited by hackers.
 Need for continuous updates and patches.
Best practices for the use of social media
1. Strong, Unique Passwords:
 Use complex passwords with letters, numbers, and symbols.
 Create different passwords for each social media account.
2. Enable Two-Factor Authentication (2FA):
 Activate 2FA to add an extra layer of security.
3. Review Privacy Settings:
 Regularly check and adjust privacy settings.
 Limit public visibility of personal information.
4. Protect Personal Information:
 Avoid sharing sensitive details like your address and phone number.
5. Beware of Phishing:
 Be cautious with links and attachments from unknown sources.
6. Verify User Identities:
 Check for authenticity before accepting friend requests.
7. Use Secure Wi-Fi:
 Avoid public Wi-Fi for sensitive social media activities.
 Consider using a VPN for added security.
8. Keep Software Updated:
 Update social media apps and devices to patch vulnerabilities.
9. Educate on Scams:
 Stay informed about common social media scams and hoaxes.

Page 33 of 65
CHAPTER – 3: SOCIAL MEDIA OVERVIEW AND SECURITY
10. Strong Security Questions:
 Choose non-guessable answers for security questions.
1. Limit Third-Party Apps:
 Review and restrict permissions for third-party apps.
12. Log Out Securely:
 Always log out from shared or public computers.
13. Monitor Accounts:
 Periodically check for suspicious activity.
 Review account settings regularly.
14. Report Suspicious Activity:
 Notify the platform of any suspicious or compromised accounts. By following these
practices, social media can be used securely and reduce the risk of online threats.

3.11 Flagging and reporting of inappropriate content


 The flag is now a common mechanism for reporting offensive content to an online
platform, and is used widely across most popular social media sites. A mechanism for
reporting harmful or offensive content to an online social media platform or company.
Content can be flagged by an algorithm, content moderator, or another user.

3.12 Laws regarding posting of inappropriate content


1. Defamation Laws: Posting false statements that harm someone's reputation can lead
to defamation charges.
2. Harassment and Cyberbullying Laws: Harassing or cyberbullying individuals
online can be subject to legal consequences.
3. Hate Speech and Incitement Laws: Many countries have laws against hate speech
and incitement to violence or discrimination.
4. Child Protection Laws: Posting inappropriate content involving minors can violate
child protection laws.
5. Privacy Laws: Violating someone's privacy by sharing personal information without
consent can lead to legal action.
6. Copyright Infringement: Posting copyrighted material without permission may lead
to copyright infringement claims.
7. Revenge Porn Laws: Sharing intimate images without consent (revenge porn) is
illegal in many jurisdictions.
8. Obscenity Laws: Posting explicit or obscene content may violate obscenity laws.
9. Cybersecurity Laws: Unauthorized hacking, data breaches, or sharing of confidential
information can lead to legal consequences.
10. Platform-Specific Rules: Social media platforms often have their own rules and
guidelines; violations may result in account suspension or legal action.
11. International Jurisdiction: Online content can be subject to laws of the country
where it's posted or the country where it's viewed.
12. Freedom of Speech Considerations: Laws regarding inappropriate content must be
balanced with freedom of speech rights, which can vary widely by jurisdiction.

Page 34 of 65
CHAPTER – 3: SOCIAL MEDIA OVERVIEW AND SECURITY
13. Legal Penalties: Consequences for violating these laws may include fines, probation,
or imprisonment, depending on the severity of the offense.

3.12 Best practices for the use of social media security


Here are the best practices to enhance your social media security and privacy.
1. Develop a strong password policy
 You should create a strong password policy and instruct employees to use it when
logging into their social media accounts.
 Passwords should include intricate combinations of uppercase, lowercase, digits and
special characters.
 They should also be updated regularly and the same passwords shouldn't be used on
different platforms.
 Avoid using common passwords or information that could be guessed, such as
birthdates or pet names.
 Interesting Read: Social Media Governance: What It Is and Associated Best Practices
2. Enable two-factor authentication
 Two-factor authentication amplifies security by requiring users to submit a second
form of verification, such as a special code sent to their mobile device, in addition to
their password. This approach substantially reduces the risk of unauthorized access,
even if the initial credentials have been compromised.
 Both X and Facebook have two-factor authentication solutions. Once activated, you'll
get a unique code on your phone that you'll need to input to complete the login
process whenever someone tries to log in to your account from a new device.
 Facebook-s two-factor authentication

3. Educate employees on security awareness


 Security breaches can be avoided with regular training and updates on new security
risks. Brands should regularly hold training sessions to inform employees of the
Page 35 of 65
CHAPTER – 3: SOCIAL MEDIA OVERVIEW AND SECURITY
potential hazards of social media and how to identify and react to potential threats.
Employees should be taught how to spot phishing efforts, suspicious sites and social
engineering tactics. Brands should also implement guidelines for using social media,
managing passwords and handling data.
 To learn about security enhancements and best practices, follow reliable cybersecurity
blogs and websites and the directions that official social media accounts of the
platforms you use provide.
 Take the example of how Sprinkler ensures its team is equipped and vigilant in
safeguarding against cyber threats:
 Employees receive ongoing training in secure coding practices and collaborate with
the security team, adhering to OWASP and other industry standards.
 Employees undergo annual training to stay current on best practices and threat
response, including practical response exercises.
 New hires receive privacy and security training during on boarding, with annual
refreshers and specialized training for teams to ensure data privacy law compliance.
 All employees complete the required security and privacy training annually,
supported by strict internal policies and a Code of Conduct.
4. Limit access privileges
 Brands should limit access rights by allowing only authorized staff access to social
media profiles. Ensure that only those employees who need access to certain accounts
and functionalities for their jobs are granted administrator rights. To retain control
over account security, access rights should be verified and updated regularly.
5. Monitor and evaluate account activity
 Social media accounts should be frequently monitored to identify any unauthorized
access or questionable behaviour. Brands should create a procedure for content
approval and review before the content is published. Keep a record of logins, social
media posting schedules and account configuration alterations. And make sure that
you respond immediately to any security or unauthorized access problems.
 If you are a global brand with distributed marketing teams, it becomes even more vital
– and challenging - to ensure all engagements are 100% brand and legal compliant.
AI-integrated marketing tools come to your rescue by:
 Flagging non-compliant messages
 Ensuring access control
 Training local teams in compliance best practices
 No hassle of tedious approval workflows and manual access controls!
6. Use third-party applications with caution
 Carefully examine the security procedures and reputation of third-party apps before
integrating them into your social media accounts. Pay attention to the permissions
given to these applications because they could give access to private information that
they shouldn‘t be privy to. Regularly check permissions and revoke them for
unnecessary applications.

Page 36 of 65
CHAPTER – 3: SOCIAL MEDIA OVERVIEW AND SECURITY
7. Protect mobile devices
 With the increasing usage of mobile devices for social media management, it‘s
necessary to take precautions for the safe usage of these devices. Ensure that these
devices have activated biometric or secure password authentication. The data that‘s
saved your devices should be encrypted and operating systems and software should be
updated often to fix security flaws.
8. Update and patch software regularly
 Attackers may take advantage of outdated software, jeopardizing the security of your
social media accounts. All social media management applications and platforms
should be updated with the most recent security patches and upgrades. Brands should
perform frequent scans for vulnerabilities and promptly implement any pending
patches.
9. Keep an eye out for free Wi-Fi
 Social media security precaution on free Wi-Fi
 Brand employees should avoid using public Wi-Fi networks to access their social
media accounts. This is because public Wi-Fi hotspots are usually insecure and it‘s
easier for hackers to intercept data on these networks. Instead, a trustworthy,
dedicated Wi-Fi network or a private and secure internet connection with a strong
password would be ideal.
10. Update privacy settings frequently
 Social media platforms often change their privacy settings and available security
alternatives. Brands should stay mindful and updated about these changes and use the
available tools to manage who can view their posts, reach them and access their
personal information. Privacy settings should be reviewed and modified regularly so
your brand can retain control over its online visibility.

Page 37 of 65
CHAPTER – 4: E-COMMERCE AND DIGITAL PAYMENTS
Introduction to digital payments, Components of digital payment and stake holders, Modes of
digital payments- Banking Cards, Unified Payment Interface (UPI), e-Wallets, Unstructured
Supplementary Service Data (USSD), Aadhar enabled payments, Digital payments related
common frauds and preventive measures. RBI guidelines on digital payments and customer
protection in unauthorized banking transactions. Relevant provisions of Payment Settlement
Act, 2007.

4.1 Definition of E-Commerce


 E-Commerce or Electronic Commerce means buying and selling of goods, products,
or services over the internet.
 E-commerce is also known as electronic commerce or internet commerce.
 Transaction of money, funds, and data are also considered as E-commerce.
 These business transactions can be done in four ways: Business to Business (B2B),
Business to Customer (B2C), Customer to Customer (C2C), and Customer to
Business (C2B).

4.2 Main components of E-Commerce


The components of E-Commerce are as follows:
1. User: This may be individual / organization or anybody using the e-commerce platforms.
2. E-commerce vendors: This is the organization/entity providing the user, goods/services.
E.g.: [Link].E-commerce Vendors further needs to ensure following for better,
effective and efficient transaction.

 Suppliers and Supply Chain Management


 Warehouse operations
 Shipping and returns
 E-Commerce catalogue and product display
 Marketing and loyalty programs
3. Technology Infrastructure: This includes Server computers, apps etc. These are the
backbone for the success of the venture. They store the data/program used to run the whole
operation of the organization.
4. Internet/ Network: This is the key to success of e-commerce transactions. Internet
connectivity is important for any e-commerce transaction to go through. The faster net
connectivity leads to better e-commerce.
5. Web Portal: This shall provide the interface through which an individual/organization
shall perform e-commerce transactions. These web portals can be accessed through desktops/
laptops/PDA/hand-held computing devices/ mobiles and now through smart TVs.
6. Payment Gateway: The payment mode through which customers shall make payments.
Payment gateway represents the way e-commerce vendors collect their payments. Examples
are Credit/Debit Card Payments, Online bank payments, Vendors own payment wallet, Third
Party Payment wallets, like PAYTM and Unified Payments Interface (UPI).

4.3 Elements of E-Commerce security


E-commerce security involves safeguarding online transactions and protecting sensitive
information during online purchases. Here are some key elements:

Page 38 of 65
CHAPTER – 4: E-COMMERCE AND DIGITAL PAYMENTS
1. Encryption: Encrypting data ensures that sensitive information like credit card details,
personal information, and transaction data is encoded during transmission. Secure Sockets
Layer (SSL) or Transport Layer Security (TLS) protocols are commonly used to encrypt data.
2. Secure Payment Gateways: Using trusted and secure payment gateways ensures that
financial information is transmitted securely between the customer, merchant, and financial
institutions.
3. Firewalls and Security Software: Implementing firewalls and up-to-date security
software helps prevent unauthorized access to the e-commerce website's network. This
includes protection against malware, viruses, and other cyber threats.
4. Authentication and Authorization: Employing strong user authentication methods, such
as two-factor authentication (2FA), helps verify the identity of users, reducing the risk of
unauthorized access.
5. Regular Updates and Patch Management: Ensuring that the e-commerce platform and
all associated software are regularly updated with the latest security patches helps mitigate
vulnerabilities that could be exploited by attackers.
6. Data Privacy and Compliance: Adhering to data privacy regulations (such as GDPR,
CCPA) and implementing privacy policies that protect customer data is crucial. This includes
proper handling and storage of personal information.
7. Risk Assessment and Monitoring: Conducting regular security audits and risk
assessments helps identify potential vulnerabilities and threats. Continuous monitoring of
systems for suspicious activities is vital to detect and respond to any security breaches
promptly.
8. Customer Education: Educating customers about safe online practices, such as creating
strong passwords, avoiding public Wi-Fi for sensitive transactions, and being cautious of
phishing attempts, can significantly enhance overall e-commerce security.
9. Physical Security Measures: Ensuring physical security of servers and data centres where
customer information is stored is essential to prevent unauthorized access to hardware and
infrastructure.
10. Backup and Disaster Recovery: Implementing robust backup and disaster recovery
plans ensures that in case of a security breach or system failure, data can be recovered
without significant loss.

Page 39 of 65
CHAPTER – 4: E-COMMERCE AND DIGITAL PAYMENTS
4.4 E-Commerce threats

E-commerce platforms face various threats that can compromise security and disrupt
operations. Here are some common threats:
1. Data Breaches: These occur when sensitive customer information, such as credit card
details or personal data, is accessed or stolen by unauthorized individuals or
cybercriminals. Breaches can happen through hacking, phishing, or exploiting
vulnerabilities in the system.
2. Phishing Attacks: Cybercriminals use deceptive emails, messages, or websites that
mimic legitimate sources to trick users into revealing sensitive information like login
credentials, credit card numbers, or personal details.
3. Malware and Viruses: Malicious software can infect e-commerce websites,
compromising user data, stealing information, or disrupting operations. Malware can be
introduced through infected files, links, or vulnerable software.
4. DDoS Attacks: Distributed Denial of Service attacks aim to overwhelm a website's
servers with excessive traffic, causing it to become slow or unavailable, disrupting
business operations and potentially leading to financial losses.
5. SQL Injection: Attackers exploit vulnerabilities in the website's code to insert malicious
SQL queries, allowing them to access or manipulate the database, compromising
sensitive information.
6. Man-in-the-Middle (MITM) Attacks: Hackers intercept communication between a
user and an e-commerce website to eavesdrop, steal information, or manipulate data
during the transmission.
7. Identity Theft: Cybercriminals may steal user identities from e-commerce platforms to
make fraudulent purchases, access financial accounts, or commit other forms of fraud.

Page 40 of 65
CHAPTER – 4: E-COMMERCE AND DIGITAL PAYMENTS
8. Supply Chain Attacks: Hackers target weaknesses in the supply chain to access the e-
commerce platform, compromising the security of transactions, customer data, or the
overall system.
9. Payment Frauds: Fraudulent activities during payment transactions, such as stolen
credit card information or unauthorized transactions, pose a significant threat to e-
commerce platforms and customers.

4.5 E-Commerce security best practices


Ensuring security in e-commerce is crucial to protect both your business and your customers'
sensitive information. Here are some best practices:
1. Use Secure Sockets Layer (SSL) Encryption: Encrypt data transmitted between your
website and users' browsers. This prevents interception of sensitive information like
credit card details.
2. Implement Strong Password Policies: Encourage users to create strong passwords and
use multi-factor authentication (MFA) wherever possible to add an extra layer of
security.
3. Regularly Update Software and Security Patches: Keep your e-commerce platform,
plugins, and software updated to patch vulnerabilities that attackers could exploit.
4. Secure Payment Gateways: Use reputable payment gateways that comply with
Payment Card Industry Data Security Standard (PCI DSS). Avoid storing payment
information on your servers.
5. Data Encryption: Encrypt sensitive data, including customer information and payment
details, when stored in databases or during transmission.
6. Regular Security Audits and Testing: Conduct security audits and penetration testing
to identify vulnerabilities and weaknesses in your system before attackers do.
7. Implement Firewalls and DDoS Protection: Install firewalls to monitor and control
incoming and outgoing traffic. Use DDoS (Distributed Denial of Service) protection to
prevent service disruption due to attacks.
8. Train Employees: Educate your staff about security best practices, phishing attacks, and
how to handle sensitive information to prevent internal security breaches.
9. Privacy Policies and Compliance: Comply with data protection regulations (like
GDPR, CCPA) and clearly communicate your privacy policies to customers.
10. Monitor and Respond to Suspicious Activity: Implement monitoring systems to detect
unusual activity and respond promptly to security incidents.
11. Backup Data Regularly: Keep regular backups of your e-commerce data to ensure you
can recover in case of a security breach or data loss.
12. Limit Access to Data: Restrict access to sensitive data. Only grant access to those who
need it for their specific roles.
Advantage of e-commerce
1. Reduced overhead costs: Running an e-commerce store is a lot more cost-effective
than running a physical store. You don't have to rent commercial real estate — instead,
you can pay an affordable fee for web hosting.
2. No need for a physical storefront: There are so many difficult aspects to running a
physical storefront and using e-commerce means you don't have to face most of those
obstacles. Renting a commercial property can be expensive. You also have to pay for
electricity, water, and internet to ensure your space is up to code and can handle your
business. There's also security to consider; if you want your physical storefront to be

Page 41 of 65
CHAPTER – 4: E-COMMERCE AND DIGITAL PAYMENTS
secure, you'll need to invest in cameras and other surveillance equipment. With an e-
commerce store, you can simply build your website and start selling your products
online without worrying about setting up a physical storefront and spending as much
money.
3. Ability to reach a broader audience: Perhaps the biggest advantage of e-commerce is
the fact that it allows you to reach a massive audience. Your physical storefront can only
get so many visitors in a day, especially if you live in a smaller town or a rural area.
With an e-commerce store, you can reach potential customers all throughout the world
and show them your products.
4. Scalability: If you have a physical storefront, your business can only grow so much
before you have to move to a larger storefront. You also have to move inventory and
equipment from one location to another, which makes it even harder to scale your store
with the growth of your business. With e-commerce, your website and store can grow as
your business does, and you don't have to spend a fortune moving to a new physical
space.
5. Track logistics: Keeping track of logistics is an essential part of e-commerce and retail
marketing, and it's significantly easier with e-commerce than it is with a physical
storefront. You can outsource fulfilment logistics so your customers can enjoy benefits
like 2-day shipping and easy returns processing.
Survey of popular e-commerce sites
There are several popular e-commerce sites that cater to different markets and needs. Some of
the well-known ones globally include:
1. Amazon: One of the largest online retailers, offering a wide range of products from
electronics to books to household items.
2. eBay: Known for its auction-style selling and a vast array of products, including both
new and used items.
3. Alibaba: A Chinese e-commerce company specializing in wholesale trading between
businesses and consumers.
4. Walmart: A major retailer with a strong online presence, selling a variety of products
similar to its physical stores.
5. Etsy: Focused on handmade, vintage, and unique goods, often catering to niche markets
and creative products.
6. Target: Similar to Walmart, Target offers a diverse range of products and has a
significant online presence.
7. Best Buy: Specializes in electronics, offering a wide selection of tech-related products.
8. Zappos: A popular online shoe and clothing retailer known for its customer service and
wide selection.
9. ASOS: Primarily focused on fashion and beauty products, targeting a younger audience
with trendy items.
10. Rakuten: A diverse marketplace offering various products and services, often
providing cashback rewards for purchases.
Each of these platforms has its own strengths, unique selling points, and target demographics,
making them popular choices for different types of consumers.

Page 42 of 65
CHAPTER – 4: E-COMMERCE AND DIGITAL PAYMENTS
4.6 Introduction to Digital Payments
 Digital payments are payments done through digital or online modes, with no
exchange of hard cash being involved. Such a payment, sometimes also called an
electronic payment (e-payment), is the transfer of value from one payment account to
another where both the payer and the payee use a digital device such as a mobile
phone, computer, or a credit, debit, or prepaid card. The payer and payee could be
either a business or an individual. This means that for digital payments to take place,
the payer and payee both must have a bank account, an online banking method, a
device from which they can make the payment, and a medium of transmission,
meaning that either they should have signed up to a payment provider or an
intermediary such as a bank or a service provider.

4.7 Components of Digital Payment and Stake holders


Digital payments involve several components and stakeholders that collectively facilitate the
transfer of money or transactions through electronic means.
Here are the key components and stakeholders:
Components:
1. Payment Gateway: It's the technology that authorizes and facilitates transactions by
connecting merchants, banks, and customers. It encrypts sensitive information and
ensures secure transfer.
2. Payment Processor: Responsible for managing the transaction process by transmitting
data between the merchant's bank and the customer's bank. It verifies transaction details
and ensures funds are transferred.
3. Mobile Wallets: Apps or platforms that store payment information, allowing users to
make transactions through their smartphones. Examples include Apple Pay, Google Pay,
and PayPal.
4. Digital Currencies/Cryptocurrencies: These decentralized forms of currency (like
Bitcoin or Ethereal) facilitate peer-to-peer transactions through block chain technology.
5. Near Field Communication (NFC): Technology that enables contactless payments by
allowing devices to communicate when in close proximity.
6. QR Codes: Scannable codes that store payment information, enabling easy transactions
by simply scanning the code.
Stakeholders:
1. Customers/Users: Individuals or entities making payments or transactions using digital
payment methods.
2. Merchants/Retailers: Businesses or individuals selling goods or services and accepting
digital payments from customers.
3. Financial Institutions: Banks, credit unions, and other financial entities that provide the
infrastructure and accounts necessary for digital transactions.
4. Payment Service Providers (PSPs): Companies that offer services facilitating digital
payments for merchants, such as Stripe, Square, or Adyen.
5. Regulatory Bodies/Government Agencies: Entities responsible for creating and
enforcing rules, regulations, and standards for digital payments to ensure security and
fairness.

Page 43 of 65
CHAPTER – 4: E-COMMERCE AND DIGITAL PAYMENTS
6. Technology Providers: Companies developing and maintaining the technology and
software necessary for secure digital payment systems, including hardware
manufacturers and software developers.
7. Security Firms: Organizations specializing in ensuring the security of digital payment
systems by providing encryption, fraud detection, and cybersecurity services.
These components and stakeholders collectively form the ecosystem that enables the
seamless execution of digital payments across various platforms and devices.

4.8 Modes of digital payments


There are various modes of digital payments that have become increasingly popular due to
their convenience and accessibility.
Here's a brief overview of each:
A. Banking cards:
 Cards are among the most widely used payment methods and come with various
features and benefits such as security of payments, convenience, etc. The main
advantage of debit/credit or prepaid banking cards is that they can be used to make
other types of digital payments. For example, customers can store card information in
digital payment apps or mobile wallets to make a cashless payment. Some of the most
reputed and well-known card payment systems are Visa, Rupay and MasterCard,
among others. Banking cards can be used for online purchases, in digital payment
apps, POS machines, online transactions, etc.
B. Unified Payment Interface (UPI)
 UPI is a payment system that culminates numerous bank accounts into a single
application, allowing the transfer of money easily between any two parties. As
compared to NEFT, RTGS, and IMPS, UPI is far more well-defined and standardized
across banks. You can use UPI to initiate a bank transfer from anywhere in just a few
clicks.
 The benefit of using UPI is that it allows you to pay directly from your bank account,
without the need to type in the card or bank details. This method has become one of
the most popular digital payment modes in 2020, with October witnessing over 2
billion transactions.
C e-Wallets
 Electronic wallets or e-wallets store financial information and allow users to make
online transactions quickly. E-wallet is a type of pre-paid account in which a user can
store his/her money for any future online transaction. An E-wallet is protected with a
password. With the help of an E-wallet, one can make payments for groceries, online
purchases, and flight tickets, among others. E-wallet has mainly two components,
software and information. The software component stores personal information and
provides security and encryption of the data. The information component is a database
of details provided by the user which includes their name, shipping address, payment
method, amount to be paid, credit or debit card details, etc. Services like PayPal,
Google Pay, Apple Pay, and Paytm fall under this category.
D. Unstructured Supplementary Service Data (USSD)
 USSD technology enables mobile banking services through basic phones, allowing
users to access banking services by dialing a short code. This method doesn't require

Page 44 of 65
CHAPTER – 4: E-COMMERCE AND DIGITAL PAYMENTS
internet connectivity and is particularly beneficial in regions with limited internet
access. USSD was launched for those sections of India's population which don't have
access to proper banking and internet facilities. Under USSD, mobile banking
transactions are possible without an internet connection by simply dialing *99# on
any essential feature phone.
 This number is operational across all Telecom Service Providers (TSPs) and allows
customers to avail of services including interbank account to account fund transfer,
balance inquiry, and availing mini statements. Around 51 leading banks offer USSD
service in 12 different languages, including Hindi & English.
E. Aadhar enabled payments system (AEPS)
 AEPS is a bank-led model for digital payments that was initiated to leverage the
presence and reach of Aadhar. Under this system, customers can use their Aadhaar-
linked accounts to transfer money between two Aadhaar linked Bank Accounts. As of
February 2020, AEPS had crossed more than 205 million as per NPCI (National
Payments Corporation of India) data.
 AEPS doesn't require any physical activity like visiting a branch, using debit or credit
cards or making a signature on a document. This bank-led model allows digital
payments at PoS (Point of Sale/Micro ATM) via a Business Correspondent (also
known as Bank Mitra) using Aadhar authentication.
• Each mode of digital payment offers its own set of advantages in terms of
accessibility, ease of use, security, and suitability for different scenarios. The choice
of which to use often depends on factors like convenience, accessibility to technology,
internet connectivity, and personal preferences.

4.9 Digital Payments Related Common Frauds and Preventive Measures


With the increasing trend of digital payment systems, the number of fraud attempts is also
increasing at an alarming rate. Cybercriminals are always looking for ways to exploit the
loopholes in the digital payment process to steal money from unsuspecting individuals.
1. Phishing:
 Phishing scams are fake messages, emails, or websites that trick people into providing
their personal information, such as login credentials, credit card details, or social
security numbers. These scammers then use this information to access victims'
accounts and steal their funds.
 Preventive Measures:
- Verify website URLs before entering any personal information.
- Never share personal or financial details via email or unsecured websites.
- Enable two-factor authentication for added security.
2. Identity Theft:
 Identity theft occurs when a fraudster steals someone's personal information, such as
their name, address, or social security number, and uses it for fraudulent activities,
such as opening a new credit card or mobile payment account.
 Preventive Measures:
- Use strong, unique passwords for each financial account.
- Regularly monitor your credit report for any suspicious activities.
- Be cautious while sharing personal information online.

Page 45 of 65
CHAPTER – 4: E-COMMERCE AND DIGITAL PAYMENTS
3. Account Takeover
 In an account takeover, a fraudster gains access to a user's digital payment account by
stealing their login credentials or obtaining their personal information using phishing
scams. The attacker then uses the account to make unauthorized transactions and
transfer funds.
 Preventive Measures:
- Use strong, unique passwords and change them regularly.
- Enable account alerts for any unusual activity.
- Consider using biometric authentication if available.
4. Card Skimming
 Card skimming involves the illegal copying of a user's credit or debit card information
using a skimming device when the card is swiped for payment. The scammers then
use the copied information to make fraudulent transactions.
 Preventive Measures:
- Check for tampering on card readers before using them.
- Use contactless payment methods where possible.
- Regularly monitor your account statements for any unauthorized charges.
5. Malware and Spyware:
 Malicious software designed to steal financial information from devices.
 Preventive Measures:
- Install and regularly update antivirus and anti-malware software.
- Avoid clicking on suspicious links or downloading unknown attachments.
- Keep your device's operating system and apps up to date.
6. Unauthorized Transactions:
 Transactions made without the account holder's knowledge or consent.
 Preventive Measures:
- Regularly check account statements for any unfamiliar transactions.
- Enable transaction notifications or alerts for your accounts.
- Report any unauthorized transactions to your bank or payment provider
immediately.
7. Social Engineering Attacks:
 Manipulating individuals to reveal confidential information.
 Preventive Measures:
- Be cautious of unsolicited calls or messages asking for personal information.
- Verify the identity of the person or organization before sharing any details.
- Educate yourself and your family about common social engineering tactics.

4.10 RBI guidelines on digital payments and customer protection in


unauthorized banking transactions
The Reserve Bank of India (RBI) has put forth various guidelines regarding digital payments
and customer protection, particularly concerning unauthorized banking transactions.
Here are some key aspects:

Page 46 of 65
CHAPTER – 4: E-COMMERCE AND DIGITAL PAYMENTS
Digital Payments:
1. Security Measures: RBI mandates that banks and financial institutions implement
robust security measures to safeguard digital transactions. This includes two-factor
authentication, encryption, and other security protocols.
2. Customer Awareness: Banks are required to educate customers about safe digital
practices, potential risks, and methods to secure their transactions. This could be
through notifications, SMS alerts, or educational campaigns.
3. Fraud Monitoring: Regular monitoring of transactions for any suspicious activity or
patterns to prevent fraudulent transactions is mandatory.
4. Prompt Redressal: There are provisions for customers to report unauthorized
transactions promptly. Upon receiving such reports, banks are obligated to investigate
and resolve complaints within a specific timeline.
Customer Protection in Unauthorized Transactions:
1. Limited Liability of Customers: In cases of unauthorized transactions, if the customer
reports the transaction within a stipulated time frame, the customer's liability is limited.
The liability shift is from the customer to the bank, subject to certain conditions and
documentation.
2. Timely Reporting: Customers are encouraged to report unauthorized transactions or
any suspicious activity as soon as possible to minimize their liability.
3. Dispute Resolution: There is a defined process for dispute resolution between the
customer and the bank regarding unauthorized transactions.
4. Reversal of Transactions: The RBI mandates that banks have to ensure prompt
reversal of any unauthorized transaction within a specified time frame once it is
reported by the customer.

4.11 Relevant provisions of Payment Settlement Act, 2007.


The Payment and Settlement Systems Act, 2007 is an Indian legislation that provides the
regulatory framework for payment systems in India. Here are some of the relevant provisions:
1. Regulation of Payment Systems: The Act establishes the Reserve Bank of India (RBI)
as the regulatory authority for payment systems in India. It aims to ensure the stability,
efficiency, and integrity of payment systems.
2. Designation of Payment Systems: The RBI has the authority to designate systems for
the purpose of the Act, allowing it to regulate and supervise various payment systems in
the country.
3. Licensing of Payment System Operators: The Act outlines provisions for the
licensing and regulation of payment system operators, ensuring that entities involved in
payment systems meet certain criteria and adhere to specified norms.
4. Oversight and Monitoring: The RBI is empowered to oversee and monitor payment
systems to ensure their smooth functioning, stability, and compliance with regulations.
5. Settlement Finality: The Act provides for settlement finality, meaning that once a
settlement in a payment system is deemed final, it cannot be revoked or reversed,
except in certain specified circumstances.
6. Establishment of Payment System Board: The Act establishes a Payment System
Board within the RBI to regulate and supervise payment systems more effectively.

Page 47 of 65
CHAPTER – 4: E-COMMERCE AND DIGITAL PAYMENTS
7. Penalties and Enforcement: Provisions for penalties and enforcement mechanisms are
outlined in the Act to ensure compliance with its provisions and regulations set by the
RBI.
These provisions and more are detailed in the Payment and Settlement Systems Act, 2007,
aimed at fostering a secure, efficient, and reliable payment system framework in India.

Page 48 of 65
CHAPTER – 5: DIGITAL DEVICES SECURITY, TOOLS & TECHNOLOGIES FOR CYBER SECURITY

5.1 What is Endpoint Security?


 Endpoint security involves the protection of end-user devices on your network, also
known as "endpoints." Most businesses have multiple endpoints in their networks,
including everything from computers and laptops to mobile phones, tablets and servers.
Small businesses might have only a few connected devices, whereas enterprise-level
operations could be dealing with thousands of devices all connecting to their network
and sharing data.
 With the Internet of Things (IoT) growing in leaps and bounds, it's all too easy for
hackers to exploit device vulnerabilities to break into business networks in search of
sensitive data. With the right endpoint security solutions in place, however, you can
protect your network from malicious attacks, stopping them before they truly start or
limiting their impact.
Examples of endpoints include:
- Mobile computers and smartphones
- Sensors/actuators
- Industrial / smart manufacturing controllers
- Smart lighting and heating controllers
- Smart cameras and computer vision systems
- Security systems
- Point-of-sale (POS) terminals
Objectives for targeting endpoints include, but are not limited to:
 Use an endpoint as an entry and exit point to access high-value assets and information
on an organization's network
 Access assets on the endpoint to exfiltration or hold hostage, either for ransom or
purely for disruption.
 Take control of the device and use it in a botnet to execute a DoS attack.

❖ Why Is an Endpoint Important?


 Endpoints are rapidly increasing, due in part by the proliferation of the internet of
things (IoT). In some instances, so much data is collected by an IoT endpoint device
that there can be challenges associated with transmitting to the data center for
processing. To address these issues and maximize data insights, endpoint devices are
increasingly empowered to "think" for themselves. Endpoint Al has emerged as a way
to make even the smallest endpoints intelligent and capable of performing some
degree of real-time analytics.
 By processing the data, they collect without moving it (or processing the data to the
degree to which only the relevant information need be transmitted), allows
organizations to save bandwidth and:
- Minimize latency by avoiding the need to wait for responses from the cloud.
- Improve overall system performance by processing data locally.
- Reduce the power budget and increase battery life.
- Reduce reliance on the cloud and increase autonomy.
- Increase privacy and security by avoiding the transmission of data between
systems.
- Reduce cost by using less network bandwidth.

Page 49 of 65
CHAPTER – 5: DIGITAL DEVICES SECURITY, TOOLS & TECHNOLOGIES FOR CYBER SECURITY

Endpoint Security Risks & Threats

 There are many endpoint security risks and threats to defend against, with
new threats evolving daily. As noted above, zero-day attacks are among the
most common reported when it comes to endpoint incursions. While insider
threats are a concern, the largest threat to businesses today comes from
external criminal activity.
Common Endpoint Threats
Here are some of the most common endpoint threats today:
 Phishing. Phishing attacks involve individuals (or bots) posing as legitimate parties in
an attempt to gain access to sensitive data. This can occur over email, phone, text, or
chat. Security awareness training alongside technical solutions like screening phishing
IP addresses and sandboxing inbound email addresses can help to prevent or limit the
impact of phishing.
 Ransomware. Ransomware blocks access to a device or files until the attacker gets
what they demand (often money or data). Anti-malware and antivirus solutions are
your best defense.
 Device Vulnerabilities. Unpatched vulnerabilities in devices and software provide
access points for attackers. Be sure that all of your systems, hardware and software are
up-to-date and running the most recent versions.
Endpoint Security Solutions
When it comes to endpoint security, there are three main categories to consider: endpoint
security software, hardware solutions and managed endpoint security service.
Endpoint Security Software
 Endpoint protection starts with finding the right software to protect devices and data
while limiting access to your network. This software could include firewalls, antivirus
programs, encryption software, application control and more.
 Endpoint security software is not usually a single program. Instead, you will likely
have several programs working together to protect your entire network and the
devices connected to it. You should plan to have software installed on a centralized
server as well as on individual endpoint devices.
 Endpoint control software is an essential component, ensuring the integrity and
authenticity of applications and their data. If applications have been infiltrated and
they're not behaving as they should, endpoint protections must recognize the threat
and stop these applications from executing, potentially compromising sensitive data
and putting the entire network at risk.
Endpoint Security Hardware
There are hardware solutions available that can help to improve your endpoint security as
well. Some of the most common hardware solutions include:
 Firewalls & UTM Devices. UTM stands for "unified threat management". These
appliances create a single point of defense that can make managing updates and
security maintenance much easier. Shop Now.

Page 50 of 65
CHAPTER – 5: DIGITAL DEVICES SECURITY, TOOLS & TECHNOLOGIES FOR CYBER SECURITY

 Security Tokens: Tokens are devices used to manage multi-factor authentication to


restrict access and help to keep your data and networks safe.
 Physical Security Systems: Physical security solutions like cameras and alarms can
help to detect intrusions or tampering with your physical devices.
 Network Access Control Systems: These systems can provide automatic device
discovery, monitoring, and management to help prevent unwanted endpoints from
accessing your network and/or limit activity to align with your policies.

5.2 Mobile Phone Security


Mobile phones are becoming ever more popular and are rapidly becoming attractive targets
for malicious attacks. Mobile phones face the same security challenges as traditional desktop
computers, but their mobility means they are also exposed to a set of risks quite different to
those of a computer in a fixed location. Mobile phones can be infected with worms, trojan
horses or other virus families, which can compromise your security and privacy or even gain
complete control over the device. This guide provides the necessary steps, do's, don'ts & tips
to secure your mobile devices.
Key aspects of mobile phone security:
1. Device Locks: Set a strong PIN, password, pattern, fingerprint, or face recognition to
lock your device. This adds an extra layer of protection in case your phone falls into the
wrong hands.
2. Software Updates: Keep your phone's operating system and applications up to date.
Manufacturers regularly release updates that often include security patches to address
vulnerabilities.
3. App Permissions: Review and understand the permissions requested by each app before
installation. Grant only the necessary permissions to apps, and be cautious about apps
that ask for excessive access to your device.
4. App Source: Download apps only from official app stores such as Google Play Store
(for Android) or the Apple App Store (for iOS). Avoid third-party app stores to minimize
the risk of downloading malicious apps.
5. Antivirus Software: Consider installing reputable antivirus or security software on your
device to protect against malware and other security threats. There are several well-
known options available for both Android and iOS.
6. Remote Tracking and Wiping: Enable features like "Find My iPhone" (iOS) or "Find
My Device" (Android) to remotely locate, lock, or erase your phone in case it's lost or
stolen.
7. Secure Wi-Fi Connections: Avoid connecting to unsecured Wi-Fi networks, especially
for sensitive activities like online banking. Use a virtual private network (VPN) when
connecting to public Wi-Fi.
8. Bluetooth and NFC: Turn off Bluetooth and NFC when not in use to prevent
unauthorized access or attacks.
9. Backup you’re Data: Regularly back up your important data to a secure cloud service or
an external device. This ensures that you can recover your information even if your
device is lost or damaged.
10. Phishing Awareness: Be cautious of phishing attempts through emails, messages, or
apps. Avoid clicking on suspicious links and only provide personal information on
trusted websites.

Page 51 of 65
CHAPTER – 5: DIGITAL DEVICES SECURITY, TOOLS & TECHNOLOGIES FOR CYBER SECURITY

11. Biometric Security: If your device supports biometric authentication, such as fingerprint
or facial recognition, consider using these methods for added convenience and security.
By implementing these practices, you can significantly enhance the security of your mobile
phone and protect your personal data from various threats.
How does Mobile Device Security work?
Securing mobile devices requires a multi-layered approach and investment in enterprise
solutions. While there are key elements to mobile device security, each organization needs to
find what best fits its network.
To get started, here are some mobile security best practices:
Establish, share, and enforce clear policies and processes
Mobile device rules are only as effective as a company's ability to properly communicate
those policies to employees. Mobile device security should include clear rules about:
1. What devices can be used
2. Allowed OS levels
3. What the company can and cannot access on a personal phone
4. Whether IT can remote wipe a device
5. Password requirements and frequency for updating passwords
1. Password Protection: One of the most basic ways to prevent unauthorized access to a
mobile device is to create a strong password, and yet weak passwords are still a persistent
problem that contributes to the majority of data hacks. Another common security problem
is workers using the same password for their mobile device, email, and every work-related
account. It is critical that employees create strong, unique passwords (of at least eight
characters) and create different passwords for different accounts.
2. Leverage biometrics: Instead of relying on traditional methods of mobile access security,
such as passwords, some companies are looking to biometrics as a safer alternative.
Biometric authentication is when a computer uses measurable biological characteristics,
such as face, fingerprint, voice, or iris recognition for identification and access. Multiple
biometric authentication methods are now available on smartphones and are easy for
workers to set up and use.
3. Avoid public Wi-Fi: A mobile device is only as secure as the network through which it
transmits data. Companies need to educate employees about the dangers of using public
Wi-Fi networks, which are vulnerable to attacks from hackers who can easily breach a
device, access the network, and steal data. The best defense is to encourage smart user
behavior and prohibit the use of open Wi-Fi networks, no matter the convenience.
4. Beware of apps: Malicious apps are some of the fastest growing threats to mobile
devices. When an employee unknowingly downloads one, either for work or personal
reasons, it provides unauthorized access to the company's network and data. To combat
this rising threat, companies have two options: instruct employees about the dangers of
downloading unapproved apps, or ban employees from downloading certain apps on their
phones altogether.
5. Mobile Device Encryption: Most mobile devices are bundled with a built-in encryption
feature. Users need to locate this feature on their device and enter a password to encrypt
their device. With this method, data is converted into a code that can only be accessed by
authorized users. This is important in case of theft, and it prevents unauthorized access.

Page 52 of 65
CHAPTER – 5: DIGITAL DEVICES SECURITY, TOOLS & TECHNOLOGIES FOR CYBER SECURITY

5.3 Password policy


A password policy is a set of rules designed to improve security by establishing strict
password requirements for your users. These rules are enforced on all users in your account.
A password policy is a set of rules and requirements designed to enhance the security of user
accounts by ensuring that passwords are strong, unique, and regularly updated. Implementing
a strong password policy is crucial for protecting sensitive information and preventing
unauthorized access.
Password policy settings
Password policy controls password settings for all users on your account. You can configure
the following password settings:
 Minimum password length
 Minimum uppercase characters
 Minimum numeric characters
 Minimum special characters Valid special characters: @ # $ % ^ & * ( ) - _ = + ' { } | ; :
<>, ./?!
 Password history restriction - Prevents users from entering previously used passwords
when updating their passwords.
 Password expiration - The number of days before a password expires and a new one must
be set.
 The following two password policies cannot be changed or disabled:
 Does not match the username
 Does not appear in compromised password database
Why we needed Password Policy & Compliance
Password policies and compliance are rules and methods that enforce the user for using a
secure and robust password. A billion credentials were stolen last year from multiple data
breaches
1. Use longer passwords: Hackers use methods like brute force attacks to gain access to
your accounts. In a brute force attack, hackers run a program and check all possible
combinations of letters, numbers, and symbols until the correct one is found.
2. Do not reuse passwords: When large-scale data breaches occur, email addresses and
passwords are often leaked online. If you reuse credentials across multiple accounts and
one of them gets compromised, hackers can easily access your other accounts as well.
3. Do not use personal information: Many people use names, birthdays, phone numbers,
and other personal details in their passwords. While these are easy to remember, such
data are readily available online and accessible to hackers.
4. Change passwords in the event of a compromise: These days, we witness massive
credential spills on a day-to-day basis. Whenever such an incident is reported, if you
have ever dealt with the victim organization, immediately change the password used.
5. Never text or email your passwords: When you share a username and password with
someone over email or text, even if that person may not share it with anyone else, your
credentials can get exposed if their email account or device gets compromised.
6. Avoid password recycling: Organizations should ensure that end-users do not recycle
old passwords. The policy should enforce a minimum password age. Otherwise, end-

Page 53 of 65
CHAPTER – 5: DIGITAL DEVICES SECURITY, TOOLS & TECHNOLOGIES FOR CYBER SECURITY

users could change their password multiple times within a few minutes and reuse their
previous password.
7. Start using a password manager: Maintaining an excel sheet or writing it down on a
sheet of paper are dangerous ways to store your passwords. The most effective solution
to maintaining overall password hygiene is to use a password manager. A password
manager helps you create strong passwords based on the best practices mentioned above
and securely store them.

5.4 Security patch management


What is Patch Management?
Patch management is the process of maintaining computer networks by performing regular
patch deployments. Patches are updates to existing software applications and packages. Each
patch to a system can varies greatly in severity of importance and difficulty of application.
Patch management encompasses four critical elements:
1. Identifying which devices are missing patches
2. Automatically gathering patches from vendors
3. Deploying patches to devices
4. Providing reports to help you make informed business decisions
The primary goal of security patch management is to enhance the security posture of an
organization's IT infrastructure by addressing known vulnerabilities and reducing the risk of
exploitation by malicious actors.
1. Vulnerability Assessment: Regularly assess your systems and software for
vulnerabilities. This can be done through automated tools, manual testing, or a
combination of both.
2. User Awareness: Educate users about the importance of system updates and patches.
Encourage them to promptly apply patches on their devices to enhance overall security
3. Automation: Utilize automation tools for patch management to streamline the process.
Automation helps ensure that patches are applied consistently and in a timely manner
4. Compliance: Adhere to regulatory requirements and industry best practices related to
patch management. This helps in demonstrating the organization's commitment to
security.
5. Documentation: Maintain detailed documentation of the patch management process,
including the timeline of patch deployment, any issues encountered, and actions taken.

5.5 Data backup


What Is a Data Backup?
Data backup is the practice of copying data from a primary to a secondary location, to protect
it in case of a disaster, accident or malicious action. Data is the lifeblood of modern
organizations, and losing data can cause massive damage and disrupt business operations.
This is why backing up your data is critical for all businesses, large and small.
What does backup data mean?
Typically, backup data means all necessary data for the workloads your server is running.
This can include documents, media files, configuration files, machine images, operating
systems, and registry files. Essentially, any data that you want to preserve can be stored as
backup data.
Page 54 of 65
CHAPTER – 5: DIGITAL DEVICES SECURITY, TOOLS & TECHNOLOGIES FOR CYBER SECURITY

1. Identify Critical Data: Determine what data is essential and needs regular backup.
Prioritize important documents, photos, videos, and any files crucial for your work.
2. Choose Backup Methods: Utilize a combination of methods like external hard drives,
cloud storage, or network-attached storage (NAS).
Cloud services such as Google Drive, Dropbox, or OneDrive offer convenient remote
backups.
3. Set Backup Schedule: Establish a regular backup schedule based on how frequently
your data changes. Automated backup tools can simplify this process, ensuring
consistency.
4. External Hard Drives: Connect an external hard drive and use built-in backup
features or dedicated backup software. Disconnect the drive after backup to protect
against malware or accidental data deletion.
5. Cloud Backup: Choose a reliable cloud service and configure automatic syncing of
important folders. Ensure the service encrypts your data for added security.
6. Network-Attached Storage (NAS): If applicable, set up a NAS device on your home
or office network for centralized data storage. Schedule regular backups to the NAS for
an additional layer of redundancy
7. Verify Backups: Periodically check your backups to ensure they are complete and
accessible. Simulate a data restoration process to confirm the integrity of your backup
files.
8. Multiple Locations: Store backups in different physical locations to guard against
disasters like fire or theft.

5.6 Downloading and management of third-party software


What is third-party software?
Third party software is any piece of software that is not a direct part of your DIS Business
System. Third-party software can be completely separate and easily identifiable from any
DIS product, or it can be used to perform functions related to your business system. Confused
yet? You most likely use a lot of third-party software every day. Examples include Microsoft
Office products like Word and Excel, email software like Outlook or Gmail, and antivirus
software like McAfee or Norton.
What is some popular third-party software?
Some third-party software is so closely integrated into your daily functions that you might not
even think of it as separate software. Some examples include internet browsers (Internet
Explorer, Firefox and Google Chrome), PDF readers like Adobe Reader, and Java, a
programming language and computing platform software that is used to interact with most
websites. Many third-party software applications are already installed when you purchase a
new PC, because they are necessary for normal computing.
This practice is crucial for individuals, businesses, and organizations to ensure the availability
and integrity of important information

Page 55 of 65
CHAPTER – 5: DIGITAL DEVICES SECURITY, TOOLS & TECHNOLOGIES FOR CYBER SECURITY

1. Source Reliability: Download software only from reputable sources, such as official
websites or trusted app stores. Avoid downloading from unfamiliar websites to
minimize the risk of malware.
2. Read Reviews: Check user reviews and ratings before downloading to gauge the
software's reputation and reliability. Look for feedback on security, performance, and
user experience.
3. Official Websites: Prefer downloading software directly from the official website or
authorized distribution channels. Be cautious with third-party download sites, as they
may bundle software with unwanted extras.
4. Check System Requirements: Verify that the software is compatible with your
operating system and hardware. Review system requirements on the official website
before downloading.
5. Use Trusted Antivirus Software: Keep your antivirus software up-to-date to scan and
detect any potential threats in downloaded files. Regularly perform full system scans for
added security.
6. Keep Software Updated: Enable automatic updates for third-party software whenever
possible. Updates often include security patches and improvements, reducing
vulnerabilities.
7. Uninstall Unused Software: Regularly review installed software and uninstall any
programs you no longer need. This reduces the potential attack surface and keeps your
system cleaner.
8. License Agreements: Read and understand the terms of use and license agreements
before installing any software. Be aware of any bundled software or additional tools
included in the installation.
9. Stay Informed: Stay informed about security vulnerabilities associated with the
software you use. Subscribe to notifications or newsletters from developers to receive
timely updates.
10. Backup before Installation: Create a backup of important data before installing new
software, especially major updates or system utilities. This precaution provides a safety
net in case of unexpected issues during installation.
Downloading Third-Party Software:
1. Official Sources: Download software only from official and reputable sources. Avoid
third-party websites, as they may host modified or malicious versions of the software.
2. Vendor's Website: Whenever possible, download software directly from the vendor's
official website. This ensures that you get the latest and legitimate version of the
software.
3. Check Reviews and Ratings: Before downloading, check reviews and ratings from
reliable sources or user communities to gauge the software's reputation and reliability.
4. Avoid "Cracked" Software: Refrain from downloading cracked or pirated versions of
software, as they often contain malware or other security risks. Use legitimate channels
to obtain software licenses.
5. Verify URLs: Double-check the URL to ensure that it matches the official website of
the software vendor. Be cautious of phishing attempts that mimic legitimate sites.

Page 56 of 65
CHAPTER – 5: DIGITAL DEVICES SECURITY, TOOLS & TECHNOLOGIES FOR CYBER SECURITY

Installing and Managing Third-Party Software:


1. Read Terms and Conditions: Take the time to read the terms and conditions of the
software installation. Be aware of any bundled software or additional tools that may
come with the installation.
2. Custom Installations: During the installation process, opt for custom installations
rather than "quick" or "default" installations. This allows you to control which
components are installed.
3. Uncheck Unnecessary Options: Uncheck any pre-selected options for additional
software or toolbars that are not necessary for the functionality of the main application.
4. Update Settings: Configure the software to update automatically or be notified of
updates. Keeping software up to date is crucial for security, as updates often include
patches for known vulnerabilities.
5. Check for Digital Signatures: Verify that the downloaded software has a valid digital
signature from the vendor. Digital signatures ensure that the software has not been
tampered with or altered.
6. Use a Standard User Account: Avoid installing software using an administrator
account unless necessary. Use a standard user account for everyday tasks to minimize
the impact of potential security vulnerabilities.
7. Regularly Review Installed Software: Periodically review the list of installed
software on your system and uninstall any applications that are no longer needed. This
helps reduce potential security risks.
8. Security Software: Maintain up-to-date antivirus and anti-malware software on your
system to provide an additional layer of protection against potential threats.
9. Backup before Installation: Before installing significant software updates or new
applications, consider backing up your system. This can help recover your data in case
of any issues during or after installation.
10. Secure Configuration: Configure the software securely, following best practices
provided by the vendor. This may include setting up firewalls, adjusting security
settings, and implementing strong passwords.

5.7 Device security policy


What is device security?
Device security is the defense of IT assets against harm and unauthorized use. Although the
term "device security" is not as widely used as "cybersecurity," it is a relevant concept that
denotes the full range of practices for securing desktop PCs, laptops, smartphones, tablets, or
Internet of Things (IoT) devices.
To reliably fend off modern security threats, a device security strategy must be multilayered,
with multiple security solutions working in tandem with one another and oriented around a
consistent set of processes. Moreover, both security personnel and end-users must be aligned
on best practices such as keeping software up to date and using the right access points or
gateways when accessing applications remotely.
What does device security include?
Device security has three fundamental components.
1. People: Security experts, whether in-house or at a cloud service provider, are the core
of device security. They decide what tools and controls are implemented and monitor

Page 57 of 65
CHAPTER – 5: DIGITAL DEVICES SECURITY, TOOLS & TECHNOLOGIES FOR CYBER SECURITY

environments for anomalies and threats. Security leaders are also important in
educating users about how to prevent sensitive data leakage and avoid risky behaviors,
especially when working remotely.
2. Processes: Effective device security requires a systematic approach to dealing with
each threat, with security policies and plans that follow best practices. For example, the
National Institute of Standards and Technology offers a framework with a continuous
cycle of Identify > Protect > Detect > Respond > Recover that can be followed when
confronted with malware or ransomware.
3. Technologies: Many technical solutions are available for securing environments
against threats. Web application firewalls (WAFs), analytics, bot identification and
management platforms, antimalware programs, email security, and more are among the
most commonly deployed for this purpose. The exact mix of tools changes over time.
For instance, secure internet access may replace a traditional virtual private network
(VPN).
For device security, keep software updated, use strong passwords, enable two-factor
authentication, install reputable antivirus software, and avoid suspicious links or apps.
1. Software Updates: Regularly update your device's operating system and applications to
patch vulnerabilities and ensure the latest security features.
2. Strong Passwords: Use complex passwords with a mix of uppercase and lowercase
letters, numbers, and symbols. Avoid easily guessable information like birthdays or
names.
3. Two-Factor Authentication (2FA): Enable 2FA whenever possible to add an extra
layer of security. This typically involves receiving a code on a secondary device or via
SMS.
4. Antivirus Software: Install reputable antivirus and anti-malware software to detect and
remove malicious programs that could compromise your device's security.
5. Secure Wi-Fi Connection: Use a strong, encrypted Wi-Fi password. Avoid public Wi-
Fi for sensitive transactions unless using a virtual private network (VPN).
6. App Permissions: Review and limit the permissions granted to each app. Only give
necessary access to features like camera, location, and contacts.
7. App Updates: Keep all installed apps updated to ensure they have the latest security
patches and bug fixes.
8. Biometric Security: If available, use biometric features like fingerprint or facial
recognition for added security
9. Backup Regularly: Back up your important data regularly to an external source or a
secure cloud service. This ensures you can recover your information in case of data loss.
10. Secure Browsing: Use secure, encrypted connections ([Link] when browsing the
internet. Be cautious of phishing websites and only download files from trusted sources.
11. Remote Tracking and Wiping: Enable remote tracking and wiping features in case
your device is lost or stolen. This allows you to locate your device and erase data if
necessary.
12. Awareness and Education: Stay informed about the latest security threats and best
practices. Educate yourself on common scams and phishing techniques to avoid falling
victim.
13. Physical Security: Keep your device physically secure. Avoid leaving it unattended
in public places, and consider using lock screens or passwords to prevent unauthorized
access.

Page 58 of 65
CHAPTER – 5: DIGITAL DEVICES SECURITY, TOOLS & TECHNOLOGIES FOR CYBER SECURITY

14. Regular Audits: Periodically review your device security settings and update them as
needed. Remove unused apps and accounts to minimize potential vulnerabilities.

5.8 Cyber Security Best Practices


1. Keep software up-to-date: Software companies typically provide software updates for
3 reasons: to add new features, fix known bugs, and upgrade security. Always update to
the latest version of your software to protect yourself from new or existing security
vulnerabilities.
2. Avoid opening suspicious emails: If an email looks suspicious, don't open it because it
might be a scam. Someone might be impersonating another individual or company to
gain access to your personal information. Sometimes the emails may also include
attachments or links that can infect your devices.
3. Keep hardware up-to-date: Outdated computer hardware may not support the most
recent software security upgrades. Additionally, old hardware makes it slower to
respond to cyber-attacks if they happen. Make sure to use computer hardware that's
more up-to-date.
4. Use a secure file-sharing solution to encrypt data: If you regularly share confidential
information, you absolutely need to start using a secure file- sharing solution. Regular
email is not meant for exchanging sensitive documents, because if the emails are
intercepted, unauthorized users will have access to your precious data.
On the other hand, using a secure file-sharing solution like Titan File will automatically
encrypt sensitive files so that you don't have to worry about a data breach. Remember,
your files are only as secure as the tools you chose to share them with.
5. Use anti-virus and anti-malware: As long as you're connected to the web, it's
impossible to have complete and total protection from malware. However, you can
significantly reduce your vulnerability by ensuring you have an anti-virus and at least
one anti-malware installed on your computers.
6. Use a VPN to privatize your connections: For a more secure and privatized network,
use a virtual private network (VPN). It'll encrypt your connection and protect your
private information, even from your internet service provider.
7. Check links before you click: Links can easily be disguised as something they're not
so it's best to double check before you click on a hyperlink. On most browsers, you can
see the target URL by hovering over the link. Do this to check links before you click on
them?
8. Don't be lazy with your passwords!: Put more effort into creating your passwords.
You can use a tool like [Link] to find out how secure your
passwords are.
9. Disable Bluetooth when you don't need it: Devices can be hacked via Bluetooth and
subsequently your private information can be stolen. If there's no reason to have your
Bluetooth on, turn it off!
10. Enable 2-Factor Authentication: Many platforms now allow you to enable 2-factor
authentication to keep your accounts more secure. It's another layer of protection that
helps verify that it's actually you who is accessing your account and not someone who's
unauthorized. Enable this security feature when you can.

Page 59 of 65
CHAPTER – 5: DIGITAL DEVICES SECURITY, TOOLS & TECHNOLOGIES FOR CYBER SECURITY

5.11 Wi-Fi Security


What Is Wi-Fi Security?
Wi-Fi security is the protection of devices and networks connected in a wireless environment.
Without Wi-Fi security, a networking device such as a wireless access point or a router can
be accessed by anyone using a computer or mobile device within range of the router's
wireless signal.
1. Encryption Protocols: Use WPA3 (Wi-Fi Protected Access 3) for the highest level of
security. WPA2 is still secure but consider upgrading, if possible, as it's vulnerable to
some attacks.
2. Password Strength: Choose a strong, unique password for your Wi-Fi network. Avoid
using easily guessable information like names, birthdays, or common words.
3. Router Security: Regularly update your router firmware to patch vulnerabilities.
Disable remote administration to prevent unauthorized access.
4. MAC Address Filtering: Enable MAC address filtering to specify which devices can
connect to your network.
5. Firewall Settings: Configure your router's firewall to block unauthorized access.
Consider using a hardware firewall for an additional layer of protection
6. Regular Monitoring: Keep an eye on connected devices and be aware of any
unfamiliar ones. Monitor router logs for suspicious activity.
7. Public Wi-Fi Caution: Avoid accessing sensitive information on public Wi-Fi
networks. Use a VPN (Virtual Private Network) for added security when on public
networks.
8. Two-Factor Authentication: If your router supports it, enable two-factor
authentication for an extra layer of protection.
9. Physical Security: Place your router in a secure location to prevent physical tampering.

5.12 Configuration of Basic Security Policy And Permissions.


The configuration of basic security policies and permissions is a fundamental aspect of
securing an IT environment. Below is a guide on how to set up basic security policies and
permissions for various components of your infrastructure:
1. User Authentication and Authorization:
a. Password Policies: Set up a strong password policy, including requirements for
length, complexity, and expiration. Enforce regular password changes.
b. Multi-Factor Authentication (MFA): Implement MFA to add an extra layer of
security beyond just passwords. Require users to authenticate using a second factor,
such as a mobile app or SMS code.
c. User Roles and Permissions: Define user roles based on job responsibilities. Assign
minimum necessary permissions to each role to follow the principle of least privilege.
2. Operating System Security:
a. Updates and Patch Management: Regularly update and patch operating systems to
address vulnerabilities. Implement a patch management system to ensure timely
updates.
b. Firewall Configuration: Enable and configure the host firewall on servers and
workstations. Define rules to allow only necessary inbound and outbound traffic.

Page 60 of 65
CHAPTER – 5: DIGITAL DEVICES SECURITY, TOOLS & TECHNOLOGIES FOR CYBER SECURITY

c. User Account Management: Set up policies for creating, modifying, and deleting
user accounts. Disable or remove inactive accounts promptly.
d. Account Lockout Policy: Implement an account lockout policy to prevent brute-
force attacks. Lock user accounts after a specified number of unsuccessful login
attempts.
3. Network Security:
a. Network Segmentation: Segment the network to limit the scope of potential security
breaches. Use VLANs and subnets to isolate different types of traffic.
b. VPN Configuration: If remote access is necessary, configure and secure VPN
connections. Ensure that data transmitted over VPNs is encrypted.
c. Intrusion Detection/Prevention Systems (IDS/IPS): Implement IDS/IPS systems to
monitor and respond to suspicious network activities. Configure rules to detect and
block known attack patterns.
4. Application Security:
a. Access Controls within Applications: Implement access controls within applications
to restrict user access to specific features or data. Apply the principle of least
privilege.
b. Data Encryption: Encrypt sensitive data within applications, especially when storing
or transmitting information. Follow best practices for securing sensitive data.
5. Email Security:
a. Spam Filtering: Enable spam filtering on email servers to reduce the likelihood of
phishing attacks and malicious attachments.
b. Email Encryption: Implement email encryption, especially for sensitive
communications. Use technologies like Transport Layer Security (TLS) for secure
email transmission.
6. Physical Security:
a. Access Controls to Physical Spaces: Control physical access to data centers, server
rooms, and other critical areas. Use access cards, biometric authentication, or other
secure methods.
b. Device Encryption: Enable device encryption on laptops and mobile devices to
protect data in case of device loss or theft.
7. Security Auditing and Monitoring:
a. Security Information and Event Management (SIEM): Implement a SIEM system
to collect, analyze, and respond to security events. Set up alerts for suspicious
activities.
b. Log Management: Configure systems to generate and retain logs. Regularly review
logs for security events, and establish processes for responding to anomalies.
8. Incident Response:
a. Incident Response Plan: Develop and document an incident response plan. Define
roles and responsibilities, and establish procedures for identifying, containing,
eradicating, recovering from, and analyzing security incidents.

Page 61 of 65
CHAPTER – 5: DIGITAL DEVICES SECURITY, TOOLS & TECHNOLOGIES FOR CYBER SECURITY

b. Communication Plan: Establish a communication plan to notify stakeholders and


users in the event of a security incident. Clearly define the chain of command for
incident response.
9. Security Training and Awareness:
a. Employee Training: Conduct regular security training for employees. Educate them on
security policies, social engineering threats, and best practices for maintaining security.
b. Phishing Awareness: Run simulated phishing exercises to train employees to
recognize and report phishing attempts.
10. Regular Security Assessments:
a. Vulnerability Assessments and Penetration Testing: Conduct regular vulnerability
assessments and penetration testing to identify and remediate security weaknesses.
Regularly update and adapt security policies based on assessment findings.

Remember that security policies and permissions should be regularly reviewed and
updated to adapt to changes in technology, threats, and organizational requirements.
Additionally, involve key stakeholders and departments in the development and
enforcement of security policies to ensure a comprehensive and collaborative approach
to security

Page 1 of 65

You might also like